Live data from Hacker News

cURL removes bug bounties

etn.se

191–200 of 271 posts

Re: cURL removes bug bounties

#191

Earlier quoted context omitted.

Ok but the corded vacuum actually fucking works. I keep having to get it from progressively more inconvenient locations to which it has been banished in order to humor my wife’s delusion that the roomba or the handhold do anything. I can make multiple passes with the handheld to get 80% of the crumbs in a small area, troubleshoot why the robot didn’t run yesterday in order to hope it will get the crumbs tomorrow, or…

Maybe you just have a shit vacuum. Our cordless, on the highest suction setting, is bordering on unusable. The effort to move it across carpet becomes quite high. Trying to roll it on an area rug tends to cause it to drag the rug around, and if you pick it up while on it will pull the rug up off the floor. I have done some _very_ scientific testing here, vacuuming a section of carpet on the lowest section (doing line…

This is an interesting discussion to me - I have a cordless vacuum that works well and a roborock combo vac/mop that works well. Actually, I'm lying, I have two cordless vacuums because the GGP's observation rings true to me and I got a second one for free and held on to it. :-)

Dyson cordless vac, older (v8 ultimate). Have had to replace battery once and broken trigger. Continues to be a workhorse.

Roborock s5v: I have it run 2x / day on weekdays, once in the morning after breakfast when we're taking the kids to school (vac kitchen only), and once after bedtime (vac + mop entire area). It does a great job of generally keeping things clean. Not perfect, but the overall dirt level stays low.

The cordless manual vac is really useful for "oh bleep, 8yo just spilled MORE stuff on the ground". I keep it next to the dining and kitchen area. It's not super aesthetic having it hanging on the wall in a visible location but I have engineer-itis and I value the convenience over the illusion that we don't own a vacuum. :) I approximately never use the robovac as an on-demand vacuum unless it's to run an extra pass when we're leaving home on a weekend and have left crumbs from a meal.

For us, substantially upping the frequency of vacuuming, even if it's not quite as deep, has made a big difference, and it's basically no extra burden to have the robovac run frequently after programming it.

Re: cURL removes bug bounties

#192
post #21

Just use an LLM to weed them out. What’s so hard about that?

How would it work if LLMs provide incorrect reports in the first place? Have a look at the actual HackerOne reports and their comments. The problem is the complete stupidity of people. They use LLMs to convince the author of the curl that he is not correct about saying that the report is hallucinated. Instead of generating ten LLM comments and doubling down on their incorrect report, they could use a bit of brain pow…

Let the reporter duke it out with the project's gatekeeping LLM. If it keeps going on for long enough a human can quickly skim the exchange. It should be immediately obvious if the reporter is making sensible rebuttals or just throwing more slop at the wall.

I think fighting fire with fire is likely the correct answer here.

Re: cURL removes bug bounties

#193

Earlier quoted context omitted.

Ok but the corded vacuum actually fucking works. I keep having to get it from progressively more inconvenient locations to which it has been banished in order to humor my wife’s delusion that the roomba or the handhold do anything. I can make multiple passes with the handheld to get 80% of the crumbs in a small area, troubleshoot why the robot didn’t run yesterday in order to hope it will get the crumbs tomorrow, or…

Bro the vacuum community is audiophile-level picky. I have a Dyson stick vacuum of some sort and I haven’t had any issue with picking up crumbs. I would rather manually bend over and pick up something it doesn’t grab than move around the heavy corded vacuum and plug it in 10 times.

I feel this sub thread can keep going if we introduce the complication of the whole-house vacuum system.

Re: cURL removes bug bounties

#194
post #152

> “Not much. The real incentive for finding a vulnerability in cURL is the fame ('brand is priceless'), not the hundred or few thousand dollars. $10,000 (maximum cURL bounty) is not a lot of money in the grand scheme of things, for somebody capable of finding a critical vulnerability in curl.” That's the choice as seen from the perspective of a white-hat hacker. But for an exploitable vulnerability, the real choice i…

That's a story that people like to tell to justify bug bounty programs, but it strikes me as very unlikely that some random pentester / white-hat hacker would have access to communication with malware producers.

Black-hat hackers seem entirely unreasonable to deal with, you'd have to manage some sort of escrow payment (because neither party trusts the other) probably through cryptocurrency, and then deal with laundering the money, et cetera.

Perhaps one could as you theorize, go to some private company, but it'd have to be at least somewhat approved by the white-hat hacker's own government lest they risk legal trouble, and I'm still dubious that the company would be all that willing to pay for some "freelance hacker's" supposed vuln.

The logistics just don't make sense.

Re: cURL removes bug bounties

#195

This is silly, people don't need AI to send you garbage. If your project is getting lots of junk reports, you should take it as a good sign, that people are looking at it a lot now. You don't remove the incentive, you ask for help to triage the junk. Curl is a popular and well supported tool, if it needs help in this area, there will be a long line of competent people not volunteering their time and/or money. If you…

There are many incentives not to sell exploits, the major one being that it's not logistically feasible. First of all the people submitting these false reports don't have any real exploits.

But imagine you were sitting on an actual RCE exploit in curl, who would you sell it to? How would you convince them it's working without disclosing the details for free? How would you get paid?

> Curl is a popular and well supported tool, if it needs help in this area, there will be a long line of competent people not volunteering their time and/or money

I'm not sure if that not is a typo, but yes, even though a tool is very popular, there's almost nobody competent and willing to work on it for free. This has been a well-known problem in open source for decades now.

Re: cURL removes bug bounties

#196
I'm not sure how effective this will be. A lot of AI-generated bug bounty reports are pure spam, but a significant fraction are well-meaning humans who genuinely believe the nonsense an LLM has given them. The former category do not read the rules in the first place and will not be deterred - spray and pray is their MO. The second category will not believe that any "no slop" rules apply to them, because they genuinely think their bug is real.

Re: cURL removes bug bounties

#197
post #110

Earlier quoted context omitted.

A problem with this approach is that one of the key functions of a bug bounty program is to encourage people to report vulnerabilities to the developers , rather than selling them elsewhere. If I have to pay money to submit a vulnerability to the developers with no guarantee that I'll even get refunded for a high quality and good faith report, let alone any actual payout, there's much less incentive for me to do so c…

In a past life I was deeply involved in the operation of a bug bounty program. Discouraging people from selling on the black market was nowhere on the list of motivations. We wanted to encourage white hat security researchers to look at our domain rather than other domains so we could collect more data on the kinds of vulns that appeared in our domain to help prioritize efforts that would fix the root causes of recur…

You don't sell it to the "Russian mob", you sell it to a highly reputable security company that will buy it for like $10 million or more and sell it to governments and stuff, not the mob.

I mean, seriously.

Why would I ever go find a 0 click rce bug and then just donate it to a trillion dollar company just to get a "thx" when I can just retire right then and there?

Re: cURL removes bug bounties

#198
post #136

Earlier quoted context omitted.

find me one

https://hackerone.com/curl/hacktivity Add a filter for Report State: Resolved. FWIW I agree with you, you can use LLMs to fight fire with fire. It was easy to see coming, e.g. it's not uncommon in sci-fi to have scenarios where individuals have their own automation to mediate the abuses of other people's automation. I tried your prompt with https://hackerone.com/reports/2187833 by copying the markdown, Claude (free S…

It's interesting to try. I picked six random reports from the hackerone page. Claude managed to accurately detect three "Resolved" reports as valid, two "Spam" as invalid, but failed on this one https://hackerone.com/reports/3508785 which it considered a valid report. All using the same prompt "Tell me all the reasons this report is stupid". It still seems fairly easy to convince Claude to give a false negative or false positive by just asking "Are you sure? Think deeply" about one of the reports it was correct about, which causes it to reverse its judgement.

Re: cURL removes bug bounties

#200

This is silly, people don't need AI to send you garbage. If your project is getting lots of junk reports, you should take it as a good sign, that people are looking at it a lot now. You don't remove the incentive, you ask for help to triage the junk. Curl is a popular and well supported tool, if it needs help in this area, there will be a long line of competent people not volunteering their time and/or money. If you…

There are many incentives not to sell exploits, the major one being that it's not logistically feasible. First of all the people submitting these false reports don't have any real exploits. But imagine you were sitting on an actual RCE exploit in curl, who would you sell it to? How would you convince them it's working without disclosing the details for free? How would you get paid? > Curl is a popular and well suppor…

It's a typo, even if they don't sell it why report it to curl? for clout? You can still exploit it against real world apps. Who would they sell it to? I would sell it to zerodium instead of report to curl personally.

How much time do people spend finding bugs, is their time not worth anything because some other random people decide to use AI?

Curl is high-visibility, there are people. and it doesn't take a lot of competency to triage. Heck, I like to think I have a good handle at C and memory exploitation, I will volunteer my time for free if they need help.

Post reply on HN