Live data from Hacker News

cURL removes bug bounties

etn.se

221–230 of 271 posts

Re: cURL removes bug bounties

#221
post #43
post #9

It seems open source loses the most from AI. Open source code trained the models, the models are being used to spam open source projects anywhere there's incentive, they can be used to chip away at open source business models by implementing paid features and providing the support, and eventually perhaps AI simply replaces most open source code

> they can be used to chip away at open source business models by implementing paid features and providing the support There are a lot of things to be sad about AI, but this is not it. Nobody has a right to a business model, especially one that assumes nobody will compete with you. If your business model relies on the rest of the world bring sucky so you can sell some value-added to open-core software, i'm happy when…

I wouldn’t see it as having a “right” to a business model but more like an accelerated tragedy of the commons. LLMs can’t reason but they can chip away at the easiest parts of the job, which is great initially if you can take advantage of that but it means fewer people will put free things in the commons or develop the skills needed to do what LLMs fail at. This feels like the way bars changed their “free lunch” specials a century ago to prevent people from costing them money: nobody has a right to it, etc. but the free loader problem leads to something many people like going away.

Re: cURL removes bug bounties

#222

Hackerone (where cURL hosted their bounty program) tracks the reputation of bounty hunters. I don't understand why they are not taking advantage of this. Make a private program, invite only hackers who have proved themselves by submitting relevant reports.

Say all projects did just that, only allowing reports from proven hackers. How does a new hacker then prove themselves?

Start a lemonade stand?

Re: cURL removes bug bounties

#223

Hackerone (where cURL hosted their bounty program) tracks the reputation of bounty hunters. I don't understand why they are not taking advantage of this. Make a private program, invite only hackers who have proved themselves by submitting relevant reports.

Say all projects did just that, only allowing reports from proven hackers. How does a new hacker then prove themselves?

i think that hypothetical is too simplistic to accurately frame the situation. we're talking about one of the largest, most widely used libraries in the open source world. at that level, they don't really need unknowns to use their project to "prove themselves" - they can contribute to smaller projects or put their own work out into the world.

Re: cURL removes bug bounties

#224

Earlier quoted context omitted.

> Actually, you don't have to. You just want to. Fair. > The point of Free Software isn't for developers to sort-of-but-not-quite give away the code. The point of Free Software is to promote self-sufficient communities. … that are all reliant on gatekeepers, who also decide the model ethics unilaterally, among other things. > (INB4: The fact that good LLMs are themselves owned by some multinational corps is irrelevan…

> > Actually, you don't have to. You just want to. > Fair. I don't think it's fair. That ideology was unquestionably developed with humans in mind. It happened in the 80s, and back then I don't think anyone had a crazy idea that software can think for itself and so terms "use" and "learn" can apply to it. (I mean, it's a crazy idea still, but unfortunately not to everyone.) One can suggest that free software ideology…

> It happened in the 80s, and back then I don't think anyone had a crazy idea that software can think for itself and so terms "use" and "learn" can apply to it. (I mean, it's a crazy idea still, but unfortunately not to everyone.)

Sure they did. It was the golden age of Science Fiction, and let's just say that the stereotype of programmers and hackers being nerds with sci-fi obsession actually had a good basis in reality.

Also those ideas aren't crazy, they're obvious, and have already been obvious back then.

Re: cURL removes bug bounties

#225

Earlier quoted context omitted.

>“Free software” means software that respects users' freedom and community. Roughly, it means that the users have the freedom to run, copy, distribute, study, change and improve the software. https://www.gnu.org/philosophy/free-sw.html Being able to learn from the code is a core part of the ideology embedded into the GPL. Not only that, but LLMs learning from code is fair use.

> Being able to learn from the code is a core part of the ideology embedded into the GPL. I have to imagine this ideology was developed with humans in mind. > but LLMs learning from code is fair use If by “fair use” you mean the legal term of art, that question is still very much up in the air. If by “fair use” you mean “I think it is fair” then sure, that’s an opinion you’re entitled to have.

> I have to imagine this ideology was developed with humans in mind.

Given what a big deal RMS made over not descriminating over purpose (https://www.gnu.org/philosophy/free-sw.html#run-the-program) i think that is far from clear.

Re: cURL removes bug bounties

#226

Earlier quoted context omitted.

Bro the vacuum community is audiophile-level picky. I have a Dyson stick vacuum of some sort and I haven’t had any issue with picking up crumbs. I would rather manually bend over and pick up something it doesn’t grab than move around the heavy corded vacuum and plug it in 10 times.

I feel this sub thread can keep going if we introduce the complication of the whole-house vacuum system.

We can also spin off a subthread about pets, and another one about using vacuum cleaners on surfaces other than floor/carpet.

Re: cURL removes bug bounties

#227
post #34

Earlier quoted context omitted.

There is a difference between AI discovering real vulnerabilities (e.g. the ffmpeg situation), and AI being used to spam fake vulnerabilities

> the ffmpeg situation How do you know that?

Because the vulnerability was published and it appeared real.

Re: cURL removes bug bounties

#228

Earlier quoted context omitted.

>question is still very much up in the air It is not up in the air at all. It's completely transformative.

Last time I checked, there are still undecided cases wrt fair use. Sure, it’s looking favorable for LLM training, but it’s definitely still up in the air. > it’s completely transformative IANAL, but apparently hinges on how the training material is acquired

> IANAL, but apparently hinges on how the training material is acquired

That doesn't make sense. You are either transforming something or you are not. There might be other legal considerations based on how you acquired, but it doesn't affect if something is transformative.

Re: cURL removes bug bounties

#229

Earlier quoted context omitted.

It's a human problem, not a tool one.

I'm not sure I completely agree, I don't think it's that black and white, it's a similar analogy to Guns and gun violence. Without the prevalence of guns there is simply less gun violence, but you could argue that it's also a human problem. Giving people who have no business using an LLM to submit slop bug bounties is a problem of the tools accessibility. But also a human problem of course. Edit: I should mention, I…

You can't ignore what guns are designed for.

Re: cURL removes bug bounties

#230

Earlier quoted context omitted.

The purpose of a tool is important. Guns have no other purpose than doing harm. E.g. We don't blame cars, the tool, for driving into a gathering of people that can kill a dozen of them, we blame the driver. The purpose is transport, the same way LLMs for coding are a tool for assisting coding tasks.

> The purpose of a tool is important. > Guns have no other purpose than doing harm. Objects don't have purposes or intent until people use them, and many objects have multiple reasonable and dual purposes. Objects can be used for net good and net harm. A bow and arrow isn't specifically for harming humans but can be used for such. Chainsaws and meat cleavers too. What would you like a machine gun-wielding terrorist t…

Yes, guns are designed to harm people. You're arguing semantics about the obvious.
Post reply on HN