Live data from Hacker News

Potential issues in curl found using AI assisted tools

mastodon.social

11–20 of 203 posts

Re: Potential issues in curl found using AI assisted tools

#12
post #9

I really didn't expect a story about curl and AI to be positive for once. Some history: https://hn.algolia.com/?q=curl+AI

Yeah this is really fair play to Daniel Stenberg that he still approached these AI generated bug reports with an open mind after all the problems he's had.

Re: Potential issues in curl found using AI assisted tools

#13
If something is found by Valgrind, we can reproduce it ourselves. Here we get private bug reports found by "his set of AI assisted tools".

The set seems to be:

https://joshua.hu/llm-engineer-review-sast-security-ai-tools...

So he likes ZeroPath. Does that get us any further? No, the regular subscription costs $200 and the free one-time version looks extremely limited and requires yet another login.

Also of course, all low hanging fruit that these tools detect will be found quickly in open source (provided that someone can afford a subscription), similar to the fact that oss-fuzz has diminishing returns.

Re: Potential issues in curl found using AI assisted tools

#14

Notice it was 'a set of tools' They're using it correctly. It's a system of tools, not an autopilot.

Well, that's how Mr. Stenberg described it, but he wasn't the one using them. I don't know how the contributor feels about his AI tool(s).

Re: Potential issues in curl found using AI assisted tools

#15
This should probably link to the original blog post by Joshua Rogers:

https://joshua.hu/llm-engineer-review-sast-security-ai-tools... ("Hacking with AI SASTs: An overview of 'AI Security Engineers' / 'LLM Security Scanners' for Penetration Testers and Security Teams")

Re: Potential issues in curl found using AI assisted tools

#16

Notice it was 'a set of tools' They're using it correctly. It's a system of tools, not an autopilot.

It's weird that the discussion has collapsed down to "autopilots" vs. "abstention". I'm thrilled to be converging on an understanding that it instead "people who understand what they're trying to do" vs. "vibe coders".

Re: Potential issues in curl found using AI assisted tools

#18
post #8
post #5

Earlier quoted context omitted.

The models used have improved quite well since then, I guess his change of opinion shows that.

I think it's more about how people are using it. An amateur who spams him with GPT-5-Codex produced bug reports is still a waste of his time. Here a professional ran the tools and then applied their own judgement before sending the results to the curl maintainers.

I keep irritating people with this observation but this was the status quo ante before AI, and at least an AI slop report shows clear intent; you can ban those submitters without even a glance at anything else they send.

Re: Potential issues in curl found using AI assisted tools

#20
post #12
post #9

I really didn't expect a story about curl and AI to be positive for once. Some history: https://hn.algolia.com/?q=curl+AI

Yeah this is really fair play to Daniel Stenberg that he still approached these AI generated bug reports with an open mind after all the problems he's had.

I think the big difference is that these aren't AI generated bug reports. They are bugs found with the assistance of AI tools that were then properly vetted and reported in a responsible way by a real person.
Post reply on HN