Live data from Hacker News

Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

aisle.com

11–20 of 32 posts

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#13
I already offered the following comments on Aisle

"my experience from working with them on and off for many months now is nothing but good. Skilled, professional engineers without any bureaucracy. They know their stuff, and they've been very good at listening in and adjusting for our needs and wants."

Who am I? I'm Daniel, curl lead developer.

https://mastodon.social/@bagder/116807425534711479

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#14
Really nice result, congrats to the Aisle team.

What stood out the most to me here was their pitch that harness currently matters most, over and above a specific model capacity. That’s one of my conclusions reading cloudflare’s Mythos debrief as well — the work right now that’s most valuable is in getting the models to loop effectively on tasks - so it’s super interesting to read the same perspective from a clearly effective org.

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#15
post #13

I already offered the following comments on Aisle "my experience from working with them on and off for many months now is nothing but good. Skilled, professional engineers without any bureaucracy. They know their stuff, and they've been very good at listening in and adjusting for our needs and wants." Who am I? I'm Daniel, curl lead developer. https://mastodon.social/@bagder/116807425534711479

Aren’t you supposed to be on vacation?? Don’t waste it all on HN! :) Hope your summer is going well.

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#16

There's something unnerving about this blog post. Paraphrasing: "The world's top security researches and AI labs are pouring all their VC money into finding as many security issues in curl as possible". At the same time, we know that curl is run by volunteers that needs to handle all of this. I'm not saying that we shouldn't do security review of open source libraries, just saying that this situation puts a lot of pr…

> The second unnerving thing is that many of the listed vulnerabilites target embedded libcurl; a library with a much slower update cycle.

I am guessing the slower update cycle is an issue where it is statically linked?

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#17
post #13

I already offered the following comments on Aisle "my experience from working with them on and off for many months now is nothing but good. Skilled, professional engineers without any bureaucracy. They know their stuff, and they've been very good at listening in and adjusting for our needs and wants." Who am I? I'm Daniel, curl lead developer. https://mastodon.social/@bagder/116807425534711479

Aren’t you supposed to be on vacation?? Don’t waste it all on HN! :) Hope your summer is going well.

Not to mention, it seems HN started to block login from user agents which are not based on a 'whatwg cartel' web engines... or their security provider loves gogol a bit too much...

(How do I post this messase then, well, my browser is faking a real user agent from some browser using a 'whatwg cartel' web engine)

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#19
post #17

Earlier quoted context omitted.

Aren’t you supposed to be on vacation?? Don’t waste it all on HN! :) Hope your summer is going well.

Not to mention, it seems HN started to block login from user agents which are not based on a 'whatwg cartel' web engines... or their security provider loves gogol a bit too much... (How do I post this messase then, well, my browser is faking a real user agent from some browser using a 'whatwg cartel' web engine)

Blocking the curl useragent can obviously be worked around, but is probably a net good. This isn’t a conspiracy, HN would be getting spammed by crawlers but they won’t care about legitimate users.
Post reply on HN