Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

141–150 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#141
post #58
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…

Not to forget that you get a minimum of four weeks of vacation per year with 30 days being offered most of the time.

This year I used my vacation time well and I already had 3 weeks off while I still have almost 4 weeks left.

Re: Curl will not accept vulnerability reports during July 2026

#142
post #108
post #72

Earlier quoted context omitted.

> if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co No, that is the point, they are not going to accept your vuln report. They are taking a holiday.

There's a pretty big difference between a random report submitted via email, and, say, a close friend of the maintainers letting them know a serious vuln was found and they should login.

Not if it's a real vacation. If it was me then there would be no way I'd log in. Maybe this will increase the sales of support contracts.

Re: Curl will not accept vulnerability reports during July 2026

#143
post #87

Earlier quoted context omitted.

I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.

The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.

Even the concept that you need permission from your employer to take a sick day is crazy to me. After all, if you're sick, you're sick, not like a hard deadline of 15 days (or whatever) is going to make the sickness go away?

Re: Curl will not accept vulnerability reports during July 2026

#144
post #132

Earlier quoted context omitted.

> For whatever reason, real people seem to desperately want Openclaw regardless of it being AI generated slop. I can agree with it but I am unsure how much the desperation is out of FOMO or out of real use-cases. Surely curl has more use-cases and projects relying on it than OpenClaw. The demand seems to be generated out of hype rather than sustainability. Openclaw project isn't even an year old and from my time hear…

>I can agree with it but I am unsure how much the desperation is out of FOMO or out of real use-cases. I frequently run into people using it, they seem happy with it. I remain highly skeptical about this being a good idea, but I'm quite convinced that many people genuinely really like it and find it useful.

> I frequently run into people using it, they seem happy with it. I remain highly skeptical about this being a good idea, but I'm quite convinced that many people genuinely really like it and find it useful.

That can be the case and good for them, at the very least its open source software that they are using and it raises more awareness about them.

But I think that we have strayed a bit afar from my main premise that I think we both agree on that although the value of an project is always subjective and its up to the companies on how they direct the funds to. It's Okay for OpenAI to sponsor Openclaw if they absolutely want to.

But the question is if its entirely reasonable as to a project like Curl getting less funding overall, simply because everyone is using curl underneath but the tech is boring (as I think it should be), but this makes everyone think that curl is well-funded when it isn't.

I think that its a reasonable decision for a company to give a very small chunk if it has massive profits to curl to sponsor the project to be more sustainable, but I am not the one at the decision-making involved in that said company, so I don't know what is the rationale behind blocking or not sponsoring Curl.

Is the rationale that they can get away with not sponsoring curl in the first place and use it with its permissive licenses in its code so why invest/donate the money in first place, but this practise doesn't seem sustainable to me!?

Re: Curl will not accept vulnerability reports during July 2026

#145
post #112
post #54

Earlier quoted context omitted.

Ditto Australia: https://www.fairwork.gov.au/leave/annual-leave Full-time and part-time employees get 4 weeks of annual leave, based on their ordinary hours of work.

Sweden is fairly unique in allowing the employee to take a 4 week break. Is Australia the same? 2 weeks is the acceptable limit in the UK for example (where also has 20-35 holiday is common) though if you can convince your boss otherwise, you can take longer, but most people can't

Some employers "force" their employees to use a portion of their annual leave during the Christmas / New Year shutdown period (usually 24 December -> first full week after New Years Day, if not longer). So you might not be able to use the full 4 weeks continuously.

This can be an unwelcome feature for some people, for example, if you want to have a vacation in the northern hemisphere summer season instead and/or maybe you don't have substantial family in Australia (or at least, those you actually want to see).

The auscorp reddit has a yearly thread on this issue: https://www.reddit.com/r/auscorp/comments/1mw6pqt/end_of_yea...

Those with school aged children might also want to save some of their annual for the mid-term/mid-year breaks as well. (Our academic years are aligned to calendar years)

Re: Curl will not accept vulnerability reports during July 2026

#146
post #16

Earlier quoted context omitted.

As a manager, I will quite literally ding people for working when they are supposed to be off. Work during work time, don't work during not-work time. Good practices mean that everyone is important, but nobody is irreplaceable, the team and the work will move along a little slower, but that's fine.

Quote from my partner's manager before a vacation: "If I see you log on, I'll disable your account."

I had a colleague at my previous company where we had to log her out of everything and ask IT to keep her logged out until their vacation was done every single time. Her water broke during her pregnancy leave and she still replied to someone asking her a question in Slack near real-time, after which we made her uninstall Slack from her phone altogether lol

Some people are just workaholics and need interventions to actually take a proper holiday.

Re: Curl will not accept vulnerability reports during July 2026

#147
post #98

Earlier quoted context omitted.

I've been noticing an unusual number of spuriously dead comments from accounts in good standing for a while now. My suspicion is false positives due to holding back the AI wave yet some of the casualties really don't seem to make any sense.

Yeah, I have seen several people who are completely shadowbanned (all comments dead) without any visible reason. There seems to be no way to report this.

Just email hn@ycombinator.com and Dang will look into it. He responds quick and will always address any concerns.

Re: Curl will not accept vulnerability reports during July 2026

#148
post #90

Earlier quoted context omitted.

Why was this dead?

Hmm. Interesting. If it was [dead], probably a false positive from a naughty comment filter; if it was [flagged][dead], difficult to say, potentially even an accident, or maybe people didn't like the joke. Given the non-negative karma, I would guess the first. Regardless, I appreciate the vouch.

It was just [dead] before I vouched for it. Luckily we have vouching–HN is my favorite moderation system I've seen.

Re: Curl will not accept vulnerability reports during July 2026

#149
post #29
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

I worry that this will make the bad guys focus on finding zero days during the month they have free to exploit anything they find, but I don't doubt that they need a break.

Cool, then it's down to everyone using this library to figure out how they can minimize the impact of a zeroday in curl - security should never be down to a single part of a system.

Re: Curl will not accept vulnerability reports during July 2026

#150
post #58
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…

This is how it should be though - nobody should be irreplaceable. Look up bus factor etc.
Post reply on HN