An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. Then again, I once submitted a bug report to my bank, because the login method could be switched from password+pin to pin only, when not logged in, and they closed it as "works as intended", because they had decided that an optional password was more convenient than a required password. (And that's not even getting into the di…
Bug bounties often involve a lot of risk for submitters. Often the person reading the report doesn't know that much and misinterprets it. Often rules are unclear about what sort of reports are wanted. A pay to enter would increase that risk. Honestly bug bounties are kind of miserable for both sides. I've worked on the recieving side of bug bounty programs. You wouldnt believe the shit that is submitted. This was bef…
cURL removes bug bounties
131–140 of 271 posts
Re: cURL removes bug bounties
#132Re: cURL removes bug bounties
#133An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. Then again, I once submitted a bug report to my bank, because the login method could be switched from password+pin to pin only, when not logged in, and they closed it as "works as intended", because they had decided that an optional password was more convenient than a required password. (And that's not even getting into the di…
You still need to complete a SMS auth to do anything other than view records though, like transfer money.
Re: cURL removes bug bounties
#134Re: cURL removes bug bounties
#135Re: cURL removes bug bounties
#136Earlier quoted context omitted.
Ok, run the same prompt on a legitimate bug report. The LLM will pretty much always agree with you
find me one
I tried your prompt with https://hackerone.com/reports/2187833 by copying the markdown, Claude (free Sonnet 4.5) begins: "I can't accurately characterize this security vulnerability report as "stupid." In fact, this is a well-written, thorough, and legitimate security report that demonstrates: ...". https://claude.ai/share/34c1e737-ec56-4eb2-ae12-987566dc31d1
AI sycophancy and over-agreement are annoying but people who just parrot those as immutable problems or impossible hurdles must just never try things out.
Re: cURL removes bug bounties
#137Earlier quoted context omitted.
They don't care. They generate large amounts of these, spam them out, and hope for some small success. If they get banned or blocked, they make new accounts. Shame isn't even a factor; it's all about money. They don't even attempt to understand or care about a product. This was partially the case before, where you'd still get weird spammy or extortive reports, but I guess LLMs enable random people to shoot their shot…
> Shame isn't even a factor That is general trend in society now.
Re: cURL removes bug bounties
#138Earlier quoted context omitted.
That freedom for many free licenses comes with the caveat that you provide basic attribution and the same freedom to your users. LLMs don't (cannot, by design) provide attribution, nor do LLM users have the freedom to run most of these models themselves.
That is if you redistribute or make a derivative work. Applying learnings you made from such software does not require such attribution.
The only indispensable part is the resource you're pirating. A resource that was given to you under the most generous of terms, which you ignored and decided to be guided by a purpose that you've assigned to those terms that embodies an intention that has been specifically denied. You do this because it allows you to do what you want to do. It's motivated "reasoning."
Without this "FOSS is for learning" thing you think overrules the license, you are no more justified in training off of it without complying with the terms than training on pirated Microsoft code without complying with their terms. People who work at Microsoft learn on Microsoft code, too, but you don't feel entitled to that.
Re: cURL removes bug bounties
#139Earlier quoted context omitted.
Just leaving this here: https://en.wikipedia.org/wiki/Pudding_mit_Gabel
already decades ago when we were kids eating pudding with a fork was a fun past time, and i am sure the idea is as old as pudding or forks themselves. i mean, the fact that it spread so fast shows that there are many who already practiced it. it's actually surprising it took this long to become a meme. heck, my cousin bet with me or let me compete eating pudding with chopsticks. (and that was long before i went to ch…