Live data from Hacker News

cURL removes bug bounties

etn.se

181–190 of 271 posts

Re: cURL removes bug bounties

#181

An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. Then again, I once submitted a bug report to my bank, because the login method could be switched from password+pin to pin only, when not logged in, and they closed it as "works as intended", because they had decided that an optional password was more convenient than a required password. (And that's not even getting into the di…

> An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. I refer to this as the Notion-to-Confluence cost border. When Notion first came out, it was snappy and easy to use. Creating a page being essentially free of effort, you very quickly had thousands of them, mostly useless. Confluence, at least in west EU, is offensively slow. The thought of adding a page is sufficiently demor…

I suspect that applies specifically to their cloud rewrite which was apparently a bloat of JS libs and hundreds of requests even by Atlassian standards. The on-prem self-host Confluence I've used is still pretty snappy and pleasant to use and without throwing an absurd amount of resources at it. We do have quite a lot of actually-useful documentation in it.

That said, Atlassian is busy relentlessly raising the price for self-host to push people into their cloud roach motel, so we'll probably be on some alternative (either FOSS or commercial, but self-host) soon too.

Re: cURL removes bug bounties

#182

Earlier quoted context omitted.

Ok but the corded vacuum actually fucking works. I keep having to get it from progressively more inconvenient locations to which it has been banished in order to humor my wife’s delusion that the roomba or the handhold do anything. I can make multiple passes with the handheld to get 80% of the crumbs in a small area, troubleshoot why the robot didn’t run yesterday in order to hope it will get the crumbs tomorrow, or…

Maybe you just have a shit vacuum. Our cordless, on the highest suction setting, is bordering on unusable. The effort to move it across carpet becomes quite high. Trying to roll it on an area rug tends to cause it to drag the rug around, and if you pick it up while on it will pull the rug up off the floor. I have done some _very_ scientific testing here, vacuuming a section of carpet on the lowest section (doing line…

What model of cordless vacuum do you have?

Re: cURL removes bug bounties

#183
post #80

Earlier quoted context omitted.

Ok, run the same prompt on a legitimate bug report. The LLM will pretty much always agree with you

find me one

No. Learn about the burden of proof and get some basic reason - your AI sycophancy will simply disappear.

Re: cURL removes bug bounties

#184

Earlier quoted context omitted.

>“Free software” means software that respects users' freedom and community. Roughly, it means that the users have the freedom to run, copy, distribute, study, change and improve the software. https://www.gnu.org/philosophy/free-sw.html Being able to learn from the code is a core part of the ideology embedded into the GPL. Not only that, but LLMs learning from code is fair use.

That freedom for many free licenses comes with the caveat that you provide basic attribution and the same freedom to your users. LLMs don't (cannot, by design) provide attribution, nor do LLM users have the freedom to run most of these models themselves.

I think LLMs could provide attribution. Either running a second hidden prompt (like, who said this?) or by doing reverse query on the training dataset. Say if they do it with even 98% accuracy it would probably be good enough. Especially for bits of info where there's very few or even just one source.

Of course it would be more expensive to get them to do it.

But if it was required to provide attribution with some % accuracy, plus we identified and addressed other problems like GPL washing/piracy of our intellectual property/people going insane with chatbots/opinion manipulation and hidden advertisement, then at some point commercial LLMs could become actually not bad for us.

Re: cURL removes bug bounties

#185

This is silly, people don't need AI to send you garbage. If your project is getting lots of junk reports, you should take it as a good sign, that people are looking at it a lot now. You don't remove the incentive, you ask for help to triage the junk. Curl is a popular and well supported tool, if it needs help in this area, there will be a long line of competent people not volunteering their time and/or money. If you…

You don't need a car to kill someone in traffic, but it's certainly much easier with one.

Re: cURL removes bug bounties

#186
post #9

It seems open source loses the most from AI. Open source code trained the models, the models are being used to spam open source projects anywhere there's incentive, they can be used to chip away at open source business models by implementing paid features and providing the support, and eventually perhaps AI simply replaces most open source code

I couldn't possibly disagree more. AI has created an entirely new way to contribute to open source. You can not, in addition to donating to the maintainers, donate your _tokens_ to fix bugs.

Re: cURL removes bug bounties

#187
post #9

It seems open source loses the most from AI. Open source code trained the models, the models are being used to spam open source projects anywhere there's incentive, they can be used to chip away at open source business models by implementing paid features and providing the support, and eventually perhaps AI simply replaces most open source code

I feel AI will have the same effect degrading Internet as social media did. This flood of dumb PRs, issues is one symptom of it. Other is AI accelerating the trend which TikTok started—short, shallow, low-effort content. It's a shame since this technology is brilliant. But every tech company has drank the “AI is the future” Kool-aid, which means no one has incentive to seriously push back against the flood of low-eff…

I think "internet" needs a shared reputation & identity layer - i.e. if somebody offers a comment/review/contribution/etc, it should be easy to check - what else are their contributing, who can vouch for them, etc.

Most of innovation came from web startups who are just not interest in "shared" anything: they want to be a monopoly, "own" users, etc. So this area has been neglected, and then people got used to status quo.

PGP / GPG used to have web-of-trust but that sort of just died.

People either need to resurrect WoT updated for modern era, or just accept the fact that everything is spammed into smithereens. Blaming AI and social media does not help.

Re: cURL removes bug bounties

#188

Earlier quoted context omitted.

If something is not technically illegal that does not mean it cannot be bad. Like I said, there is a part that should be illegal, and then part where that's used to additionally harm one of the ways that OSS can be sustainable. The second part on its own is not illegal but adds to damages and is perfectly okay to condemn. Open source software can have business models, it's one of the ways it can be sustainable. It ca…

> If something is not technically illegal that does not mean it cannot be bad. Ok? I agree, but unsure what exactly that's relevant to here in our discussion. > Open source software can have business models I believe "businesses" are the ones who have "business models", and some of those chose to use open source as part of their business model. But "open source" the ecosystem has nothing to do with that, it's for-pro…

> unsure what exactly that's relevant to here in our discussion.

I'll remind then. Our discussion follows the top statement "It seems open source loses the most from AI". As far as I understand nobody narrowed the context to "what is currently legal". Something can be technically legal and still harmful to open source. Also, laws are never perfect and sometimes they need to be updated.

(For example, I know that a number of people would say US abducting and detaining citizens and brutally deporting immigrants is not illegal, but if it's technically legal does that make it OK?)

> what it's been doing since inception.

At inception open source was mostly personal side projects for funsies (like Linux) sponsored by maintainer having a dayjob. The big leap happened when copyleft licenses made it such that success of a big commercial company building products on open-source projects would directly improve these open-source projects. And it's nothing new, it happened long time ago. The desire for volunteer contributions to codebase to remain for public benefit in perpetuity is exactly the point of strong copyleft, and it's exactly what's being circumvented by LLM washing. The fact that these LLMs subsequently also harm open source communities adds insult to injury.

Re: cURL removes bug bounties

#189
post #20

Earlier quoted context omitted.

It’s strange how sensitive humans are to these sort of relative perceived efforts. Having a charged, cordless vacuum cleaner ready to go and take around the house has also changed our vacuuming game. Because carrying a big unwieldy vacuum cleaner and needing to find a power socket at every location just feels like much more effort. Even though it really isn't.

It is. The classical vacuum is heavier, you have to find the socket and plug it in (non-trivial if you have few of them, or have kids and sockets have kid blocks on them), and perhaps most importantly, you need two free hands to operate it (particularly when carrying, plugging in and repositioning). That alone is enough to turn it into a primary activity , i.e. the kind of thing that you explicitly decide to do and b…

Have you tried a handheld corded unit? I find most of the perceived effort with the larger unit is due to a combination of the bulk, the weight, and having to maneuver it around anything delicate without inadvertently bumping into it. Meanwhile the corded handheld never dies on me and I think isn't as bad for my hearing. All the cordless units I've tried seem to have an extremely high pitch whine to them.

Re: cURL removes bug bounties

#190
Hackerone (where cURL hosted their bounty program) tracks the reputation of bounty hunters. I don't understand why they are not taking advantage of this. Make a private program, invite only hackers who have proved themselves by submitting relevant reports.
Post reply on HN