Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

191–200 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#191
post #58

Earlier quoted context omitted.

One of the reasons I left North America for Europe is that such things are normalised. The cultural difference is staggering. In Germany, if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. Another neat thing is that if you get sick on vacation, you get your vacation days back, because vacation days are for resti…

> if you are on vacation, you are simply not available. You are dead to the world until you return. Emails do not get read, and devices get left at the office. It's funny because that's kind of the definition of a vacation in my book. I find it weird that some places in the world handle it differently. Note that it's also much better for the company in the long run: It's a test of resilience and redundany, the famous…

I remember vaguely from interning at a bank that there you were actually obliged to be totally isolated from the company for a continuous period of time by policy.

The thinking was that if you were cooking the books of doing some dodgy dealing on the side it would come to light without you there to actively 'manage' it.

Re: Curl will not accept vulnerability reports during July 2026

#192

The headline buried the lede -- this is a way to get some summer vacation (niiice) AND encourage enterprise support contracts, which will still have availability. I don't think I've heard of this particular open source / support / summer vacation business model before but I like it!

Here I was thinking that cURL's (non-existent) enterprise support contracts were a polite way to tell brain-dead paper pushers to GTFO: https://daniel.haxx.se/blog/2022/01/24/logj4-security-inquir...

Re: Curl will not accept vulnerability reports during July 2026

#193
post #187

Earlier quoted context omitted.

Until someone races to the bottom to do 12 months of availability.

A race to the bottom of… unpaid work that eliminates the paid work? Can you elaborate?

AI-slop PRs automerged in response to AI slop bug reports.

Re: Curl will not accept vulnerability reports during July 2026

#194
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

> Leave your work devices behind!

Specifically, if your job offers (a) to pay for your personal phone line, or (b) a work mobile phone, choose (b).

We have the choice at $WORK, and many teammates chose (a) as it allows them to save some money each month on their phone bill, but now you're basically constantly tethered.

Re: Curl will not accept vulnerability reports during July 2026

#195

as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilig…

Reminder: ‘the software is provided “as is”…’.

It’s not their problem that you, or anybody else, think you are owed 24/7/365 emergency support.

Re: Curl will not accept vulnerability reports during July 2026

#197
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

I think my POV on this is a bit different than what others are expressing… I don’t mind answering the occasional email while on vacation, but I view it as a fair trade - as long as the company doesn’t mind me handling the occasional personal obligation during work hours I don’t mind handling the occasional work obligation during personal hours. If the company wants to be strict about clock in/out hours or taking PTO for every 30 minute errand or the work trends in a way that routinely exceeds 40 hours per week total then I’ll stop doing work “off the clock”, but so long as they’re willing to be reasonable I’m willing to be reasonable.

Re: Curl will not accept vulnerability reports during July 2026

#198
post #11

For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but i…

My company have accidentally forced this on me, and it is great. I used to have a desktop that I could VPN+RDC into from my personal laptop or desktop to work away from the office¹. I've now got a laptop, that refuses to let me authenticate remotely and they have no interest in fixing that as there are other priorities, so I simply can't work if I don't have that laptop with me and I'm not carting it around when I'm…

> Not a workaholic, I don't think, but a 24/7 stress monkey when I think that I could be helping

I er... think you might be a workaholic.

But I'm glad for you that your current setup is helping :)

Re: Curl will not accept vulnerability reports during July 2026

#199
post #87

Earlier quoted context omitted.

I help immigrants integrate for a living. Germany can be a frustrating country, but this is one of its best redeeming qualities. I'd also add that the culture allows and encourages sick days. The average is 15 sick days per year IIRC.

The average number of sick days used is 15 or the number of days offered? In New Zealand we get a minimum of 10 sick working days per year but some companies offer more and allow unused sick leave to accumulate.

I wrote a primer about sick days here: https://allaboutberlin.com/guides/sick-leave

15 is the average. I use it to reassure people that it's okay to take sick days, and not one of those rights that no one dares to use.

Usually, employers ask for a doctors' note after 3 consecutive sick days, but the reason for the sickness remains hidden from the employer. The note just gives a time range, nothing more.

Re: Curl will not accept vulnerability reports during July 2026

#200
post #187

Earlier quoted context omitted.

Until someone races to the bottom to do 12 months of availability.

A race to the bottom of… unpaid work that eliminates the paid work? Can you elaborate?

Coz just about everyone wants to be that one guy in Nebraska thanklessly maintaining this bit of digital infrastructure, apparently?

Yeah me neither.

I think the only thing that would convince people to move away from curl at this point would be if curl had a heartbleed level vulnerability and failed to fix it quickly.

Post reply on HN