Live data from Hacker News

Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

aisle.com

21–30 of 32 posts

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#21
post #17

Earlier quoted context omitted.

Not to mention, it seems HN started to block login from user agents which are not based on a 'whatwg cartel' web engines... or their security provider loves gogol a bit too much... (How do I post this messase then, well, my browser is faking a real user agent from some browser using a 'whatwg cartel' web engine)

Blocking the curl useragent can obviously be worked around, but is probably a net good. This isn’t a conspiracy, HN would be getting spammed by crawlers but they won’t care about legitimate users.

Why are they blocking login on links, lynx, etc, user agents then? Those are not curl user agents.

And I did post this message because I am "techy" enough to know how to fake my user agent string, but normal people using noscritp/basic HTML will be bluntly blocked.

And AI BOTs are certainly using 'whatwg cartel' web engines now. So this fit more than anythiing else 'whatwg cartel' agenda perfectly... how f-ing convenient...

Hopefully HN security provider will stop making love with gogol.

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#22
post #18

It seems that just from the site's animations and UI layout alone, you can recognize whether they are highly skilled programmers.

As in inverse correlation? The best programmers I know have barebones text-based sites.

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#23

There's something unnerving about this blog post. Paraphrasing: "The world's top security researches and AI labs are pouring all their VC money into finding as many security issues in curl as possible". At the same time, we know that curl is run by volunteers that needs to handle all of this. I'm not saying that we shouldn't do security review of open source libraries, just saying that this situation puts a lot of pr…

Would be great if people would brag with quotes and feedback from the maintainers. I'd be more interested to see that. Instead our model found x, I want something that really helps the maintainers.

Your wish came true: https://news.ycombinator.com/item?id=48671717

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#24

There's something unnerving about this blog post. Paraphrasing: "The world's top security researches and AI labs are pouring all their VC money into finding as many security issues in curl as possible". At the same time, we know that curl is run by volunteers that needs to handle all of this. I'm not saying that we shouldn't do security review of open source libraries, just saying that this situation puts a lot of pr…

Would be great if people would brag with quotes and feedback from the maintainers. I'd be more interested to see that. Instead our model found x, I want something that really helps the maintainers.

Here: https://news.ycombinator.com/item?id=48671717

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#25
post #18

It seems that just from the site's animations and UI layout alone, you can recognize whether they are highly skilled programmers.

On some posts, HN hates scroll animations, on others they're the work of highly skilled programmers https://aisle.com/platform

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#26
post #18

It seems that just from the site's animations and UI layout alone, you can recognize whether they are highly skilled programmers.

As in inverse correlation? The best programmers I know have barebones text-based sites.

I like sites with lots of animations, but I've noticed that a lot of people dislike them.

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#27
post #18

It seems that just from the site's animations and UI layout alone, you can recognize whether they are highly skilled programmers.

On some posts, HN hates scroll animations, on others they're the work of highly skilled programmers https://aisle.com/platform

I grew up in the Flash game generation, so I feel that the more animations, the better. I remember putting a lot of animations on my homepage at first, but then I cut back on them after getting criticism that it had too much animation for a tech blog.

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#28
post #18

It seems that just from the site's animations and UI layout alone, you can recognize whether they are highly skilled programmers.

How? Looks like a bog standard corporate website to me, and it would surprise me if they would let their highly skilled programmers spend time on creating the website.

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#29
post #13

I already offered the following comments on Aisle "my experience from working with them on and off for many months now is nothing but good. Skilled, professional engineers without any bureaucracy. They know their stuff, and they've been very good at listening in and adjusting for our needs and wants." Who am I? I'm Daniel, curl lead developer. https://mastodon.social/@bagder/116807425534711479

Aren’t you supposed to be on vacation?? Don’t waste it all on HN! :) Hope your summer is going well.

[flagged]

Re: Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported

#30

There's something unnerving about this blog post. Paraphrasing: "The world's top security researches and AI labs are pouring all their VC money into finding as many security issues in curl as possible". At the same time, we know that curl is run by volunteers that needs to handle all of this. I'm not saying that we shouldn't do security review of open source libraries, just saying that this situation puts a lot of pr…

It's all things at once.

It's good that the world has thrown enormous resources into finding curl bugs, and found not very much. Most of the CVEs are low priority and in the more esoteric parts of curl. Some (like CVE-2026-9080) seem so obscure, I'm doubtful anyone other than the reporters have ever experienced it. That shows that curl was already pretty good to begin with.

This is ultimately a marketing piece for Aisle, but at least they did some public good to get their marketing.

The most important part is that these researchers were respectful of the maintainers, and spent their own time and money fully verifying their findings before raising them with the project. They have taken on board the message that the curl project won't even talk to slop flingers. The less diligent researchers, the Dunning-Krugerands who feel enabled by AI but actually just waste the maintainers time, are the real problem.

Post reply on HN