Live data from Hacker News

cURL removes bug bounties

etn.se

171–180 of 271 posts

Re: cURL removes bug bounties

#171
post #32

I just read one of the slop submissions and it's baffling how anyone could submit these with a straight face. https://hackerone.com/reports/3293884 Not even understanding the expected behaviour and then throwing as much slop as possible to see what sticks is the problem with generative AI.

It's a human problem, not a tool one.

It very much is also a tool problem.

LLMs have been marketed for years, with great meadia fanfare, as being almost magical, something that can do the job of software engineers. Every week, the hype is driven further.

This matters. When people get told everyday that XYZ is magic, some will believe so, and use it as if it is magic.

Re: cURL removes bug bounties

#172

Earlier quoted context omitted.

It is. The classical vacuum is heavier, you have to find the socket and plug it in (non-trivial if you have few of them, or have kids and sockets have kid blocks on them), and perhaps most importantly, you need two free hands to operate it (particularly when carrying, plugging in and repositioning). That alone is enough to turn it into a primary activity , i.e. the kind of thing that you explicitly decide to do and b…

Ok but the corded vacuum actually fucking works. I keep having to get it from progressively more inconvenient locations to which it has been banished in order to humor my wife’s delusion that the roomba or the handhold do anything. I can make multiple passes with the handheld to get 80% of the crumbs in a small area, troubleshoot why the robot didn’t run yesterday in order to hope it will get the crumbs tomorrow, or…

Bro the vacuum community is audiophile-level picky. I have a Dyson stick vacuum of some sort and I haven’t had any issue with picking up crumbs. I would rather manually bend over and pick up something it doesn’t grab than move around the heavy corded vacuum and plug it in 10 times.

Re: cURL removes bug bounties

#173
post #110

Earlier quoted context omitted.

A problem with this approach is that one of the key functions of a bug bounty program is to encourage people to report vulnerabilities to the developers , rather than selling them elsewhere. If I have to pay money to submit a vulnerability to the developers with no guarantee that I'll even get refunded for a high quality and good faith report, let alone any actual payout, there's much less incentive for me to do so c…

In a past life I was deeply involved in the operation of a bug bounty program. Discouraging people from selling on the black market was nowhere on the list of motivations. We wanted to encourage white hat security researchers to look at our domain rather than other domains so we could collect more data on the kinds of vulns that appeared in our domain to help prioritize efforts that would fix the root causes of recur…

There are plenty of places you can sell exploits other than OCGs. At the more legitimate end of that market is people like ZDI who will then collaborate with the vendors (after a time), or companies making exploit kits/tooling for pentesters/red teaming. More questionable ones are companies that make things like forensics tools or spyware who are legal, but perhaps ethically dubious. All completely legal, but not great for the wider community if they're getting the vulns rather than the developers.

If you're trying to protect your own website and servers, those markets won't be a concern for you. If you ship a widely used product that's an attractive target (like web browser, mobile device, network kit, etc) then they definitely are.

Re: cURL removes bug bounties

#174

Earlier quoted context omitted.

It is. The classical vacuum is heavier, you have to find the socket and plug it in (non-trivial if you have few of them, or have kids and sockets have kid blocks on them), and perhaps most importantly, you need two free hands to operate it (particularly when carrying, plugging in and repositioning). That alone is enough to turn it into a primary activity , i.e. the kind of thing that you explicitly decide to do and b…

Ok but the corded vacuum actually fucking works. I keep having to get it from progressively more inconvenient locations to which it has been banished in order to humor my wife’s delusion that the roomba or the handhold do anything. I can make multiple passes with the handheld to get 80% of the crumbs in a small area, troubleshoot why the robot didn’t run yesterday in order to hope it will get the crumbs tomorrow, or…

Maybe you just have a shit vacuum.

Our cordless, on the highest suction setting, is bordering on unusable. The effort to move it across carpet becomes quite high. Trying to roll it on an area rug tends to cause it to drag the rug around, and if you pick it up while on it will pull the rug up off the floor.

I have done some _very_ scientific testing here, vacuuming a section of carpet on the lowest section (doing lines where each pass half-overlapped the previous so each part of the carpet got touched once in each direction), emptying the vacuum, then going back over doing the same on high. Didn't see anything else come up. Shop vac didn't pull anything else out either that I could see.

I used to be in a similar boat of "these are a stupid class of product", but end of the day even if it takes eight passes my wife was going to use it anyway. The effort for her to set the time aside to drag around the heavier corded vacuum which is a substantial effort for her, etc, would be more than doing eight passes with a cordless. So got a good one and I'm sold on it now--it is quite convenient, and it does work.

Only thing I will say is the battery definitely can't do an entire carpeted house on a charge. We don't have that much carpet, so don't have any problem cleaning all the floors and a couple area and entry-way rugs on a charge.

Re: cURL removes bug bounties

#175

Earlier quoted context omitted.

Technically true but that argument also won't let you bring your gun on a plane.

The purpose of a tool is important. Guns have no other purpose than doing harm. E.g. We don't blame cars, the tool, for driving into a gathering of people that can kill a dozen of them, we blame the driver. The purpose is transport, the same way LLMs for coding are a tool for assisting coding tasks.

We do actually keep cars out of areas with lots of people here. And the media headlines always refer to a "car" driving into people without mentioning the person behind the steering wheel. Whether that's the better than addressing the root issue is another question though.

We also don't allow car use without a license.

In the end what matters if allowing something is a net positive or not. Of course you can have more precise rules than just a blanket ban but when deciding and enforcing those rules is not free that also needs to be considered in the cost benefit analysis. Unless you can propose how projects can allow "good" contributions without spending more time on weeding out bad ones, a blanket ban makes sense.

Re: cURL removes bug bounties

#176
post #2

A list of the slop if anyone is interested: https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d...

In the second report, Daniel greeted the slopper very kindly and tried to start a conversation with them. But the slopper calls him by the completely wrong name. And this was December 2023. It must have been extremely tiring.

This (manual?) addition in the second report [1] likely gives an idea as to the reporter's mastery of English and ability to proofread before spamming out slop:

> Sorry that I'm replying to other triager of other program, so it's mistake went in flow

I think it would be really interesting if someone at HackerOne did a dive into the demographic of many of the banned posters.

[1] https://hackerone.com/reports/2298307#activity-25314164

Re: cURL removes bug bounties

#177

An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. Then again, I once submitted a bug report to my bank, because the login method could be switched from password+pin to pin only, when not logged in, and they closed it as "works as intended", because they had decided that an optional password was more convenient than a required password. (And that's not even getting into the di…

> I've since learned that anything heavily regulated like hospitals and banks will have security procedures catering to compliance, not actual security.

This is the key insight. Nobody cares at all about actual security. It is all about checklists and compliance.

Re: cURL removes bug bounties

#178

Earlier quoted context omitted.

> the fact that they additionally ruin respective business models of open source The what now? Open source doesn't have a business model, it's all about the licensing. FOSS is about making code available to others, for any purpose, and that still works the same as 20 years ago when I got started. Some seem to wake up to what "for any purpose" actually mean, but for many of us that's quite the point, that we don't mak…

If something is not technically illegal that does not mean it cannot be bad. Like I said, there is a part that should be illegal, and then part where that's used to additionally harm one of the ways that OSS can be sustainable. The second part on its own is not illegal but adds to damages and is perfectly okay to condemn. Open source software can have business models, it's one of the ways it can be sustainable. It ca…

> If something is not technically illegal that does not mean it cannot be bad.

Ok? I agree, but unsure what exactly that's relevant to here in our discussion.

> Open source software can have business models

I believe "businesses" are the ones who have "business models", and some of those chose to use open source as part of their business model. But "open source" the ecosystem has nothing to do with that, it's for-profit companies trying to use and leverage open source, rather than the open source community suddenly wanting to do something completely different from what it's been doing since inception.

Re: cURL removes bug bounties

#179
post #110

Earlier quoted context omitted.

A problem with this approach is that one of the key functions of a bug bounty program is to encourage people to report vulnerabilities to the developers , rather than selling them elsewhere. If I have to pay money to submit a vulnerability to the developers with no guarantee that I'll even get refunded for a high quality and good faith report, let alone any actual payout, there's much less incentive for me to do so c…

In a past life I was deeply involved in the operation of a bug bounty program. Discouraging people from selling on the black market was nowhere on the list of motivations. We wanted to encourage white hat security researchers to look at our domain rather than other domains so we could collect more data on the kinds of vulns that appeared in our domain to help prioritize efforts that would fix the root causes of recur…

The reality is that most people's thoughts on bug bounties are from salacious headlines talking about those $1M vulnerabilities. In reality the average bug bounty submission is a machine translated report for a low severity issue in a web app that may or may not even exist (or be a vulnerability), sprayed at hundreds of companies (or the same company a hundred times) in the hopes of earning $500 to basically do currency manipulation.

Re: cURL removes bug bounties

#180
post #32

I just read one of the slop submissions and it's baffling how anyone could submit these with a straight face. https://hackerone.com/reports/3293884 Not even understanding the expected behaviour and then throwing as much slop as possible to see what sticks is the problem with generative AI.

It's a human problem, not a tool one.

I'm not sure I completely agree, I don't think it's that black and white, it's a similar analogy to Guns and gun violence.

Without the prevalence of guns there is simply less gun violence, but you could argue that it's also a human problem.

Giving people who have no business using an LLM to submit slop bug bounties is a problem of the tools accessibility. But also a human problem of course.

Edit: I should mention, I don't have a solution to the problem although I do like the other posters suggestion of a "deposit" scheme to submit a bug. I think that would incentives higher quality submissions.

Post reply on HN