Live data from Hacker News

Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

hackerone.com

11–20 of 78 posts

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#11
This type of thing is my biggest AI fear. It’s just too easy to produce bug reports, twitter posts, academic papers, entire books and audiobooks, using AI. While the results are almost entirely trash, we can’t force humans to take the time to categorize and reject them, as there isn’t enough time.

The only fix I can think of is going to be to introduce trust models, where you can vouch for people and their outputs, and people can trust their friends, or particular lists. PGP keys aren’t the technical answer (because it’s a mess), but I think something more modern in that area might be needed.

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#16
post #12

Does hovering over the reporter's username make the whole page go blank with a generic "An error occurred" for anyone else?

I would assume that this is evidence that the reporting account has been disabled.

Yes, you can still click through if you don't hover, and the account is gone.

Presumably, the code that shows the preview just doesn't handle deleted accounts gracefully.

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#17
Having contributed my small grain of sand to the curl project in the past, I can only say I have huge respect for badger. All the issues I worked on he was impressively active on and even though I was a newbie and his language came across a bit terse when making comments, he was never wrong or disrespectful. I can’t imagine how much strain is AI slop putting on curl maintainers so I hope there’s a solution to that in the near future.

Re: Buffer Overflow Risk in Curl_inet_ntop and Inet_ntop4

#20

This type of thing is my biggest AI fear. It’s just too easy to produce bug reports, twitter posts, academic papers, entire books and audiobooks, using AI. While the results are almost entirely trash, we can’t force humans to take the time to categorize and reject them, as there isn’t enough time. The only fix I can think of is going to be to introduce trust models, where you can vouch for people and their outputs, a…

With twitter posts, you have it easy because it was 95% trash before AI. You'll definitely have a lot of problem with other content though.
Post reply on HN