Live data from Hacker News

Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

hackerone.com

1–10 of 78 posts

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#2
I feel sorry for the maintainers having to spend their energy disproving the validity of these AI generated reports. Daniel Stenberg blogged about this issue earlier: https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-f...

Open source burnout is already real, I hope the volume of the AI slop security reports stays manageable.

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#3

I feel sorry for the maintainers having to spend their energy disproving the validity of these AI generated reports. Daniel Stenberg blogged about this issue earlier: https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-f... Open source burnout is already real, I hope the volume of the AI slop security reports stays manageable.

[deleted]

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#6

I feel sorry for the maintainers having to spend their energy disproving the validity of these AI generated reports. Daniel Stenberg blogged about this issue earlier: https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-f... Open source burnout is already real, I hope the volume of the AI slop security reports stays manageable.

[deleted]

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#7

I can kinda understand the motive for carpet bombing an issue tracker with AI slop hoping for a hit, but then to whine about unprofessional responses is really too much. Time to unplug the chatbot.

The complaint sounds AI-generated as well, like the rest of the comments from that user.

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#8

I can kinda understand the motive for carpet bombing an issue tracker with AI slop hoping for a hit, but then to whine about unprofessional responses is really too much. Time to unplug the chatbot.

Not to mention that the first couple of responses were very professional. At some point you just have to call a spade a spade, or not suffer fools, or whatever expression you prefer.

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#10
I wholeheartedly side with Bagder here. I felt his response in my soul. Even before AI, everyone wants to report a small problem that could be completely insufficient and with mountains of those reports piling on, it becomes increasingly difficult to find REAL issues being reported, by non-technical users who can't do proper PR's.
Post reply on HN