Live data from Hacker News

cURL removes bug bounties

etn.se

241–250 of 271 posts

Re: cURL removes bug bounties

#241
post #31

Earlier quoted context omitted.

> An entry fee that is reimbursed if the bug turns out to matter would stop this, real quick. I refer to this as the Notion-to-Confluence cost border. When Notion first came out, it was snappy and easy to use. Creating a page being essentially free of effort, you very quickly had thousands of them, mostly useless. Confluence, at least in west EU, is offensively slow. The thought of adding a page is sufficiently demor…

> Consequently, there's some ~20 pages even in large companies. As someone working on Confluence to XWiki migration tools, I wish this was remotely true, my life would be way easier (and probably more boring :-)).

Interesting. First I've heard of Xwiki - it does look nice, and what with Atlassian's price increases... do you have any migration tips?

[edit] I found https://extensions.xwiki.org/xwiki/bin/view/Extension/Conflu... - hopefully that's a good reference.

Re: cURL removes bug bounties

#242

Earlier quoted context omitted.

Because the vulnerability was published and it appeared real.

I’m sure AI also found real vulnerabilities on cURL. My question is why you know cURL is being “spammed” but that FFMPEG is just getting legitimate problems.

> I’m sure AI also found real vulnerabilities on cURL.

The curl maintainer published the reports and they were very clearly not security vulnerabilities in curl.

> My question is why you know cURL is being “spammed” but that FFMPEG is just getting legitimate problems.

To put it bluntly, because i can read. Did you actually read the reports in question?

Re: cURL removes bug bounties

#243

It's really hard to comprehend how entitled "reward which would be the cost of lunch in Sweden can be massive for those low socio-economic-located people" is. A lunch in central Stockholm is well within 200 kronor. I can't imagine a country where an person with a computer and skills necessary to claim a bounty in cURL would consider that amount massive. Get real.

Is he entitled for considering the difficultied from developing countries?

Maybe he's exaggerating a bit with the comparison, but if we consider the ceiling of 10k, that's more than a year of minimum wage in Portugal, or a handful of years in certain developing counties. Certainly significant!

Re: cURL removes bug bounties

#244
post #9

It seems open source loses the most from AI. Open source code trained the models, the models are being used to spam open source projects anywhere there's incentive, they can be used to chip away at open source business models by implementing paid features and providing the support, and eventually perhaps AI simply replaces most open source code

"AI" kills every part of open source

it kills the incentive to contribute, the incentive to maintain, the incentive to learn, the incentive to collaborate, and the ability to build a business based on your work

and it even kills the idea of traditional employment writing non-open source code

all so three USian companies can race to the bottom to sell your former employer a subscription based on your own previous work

Re: cURL removes bug bounties

#245
post #77

Earlier quoted context omitted.

> I've since learned that anything heavily regulated like hospitals and banks will have security procedures catering to compliance, not actual security. I personally came to that conclusion thanks to the GrapheneOS situation regarding device attestation. Insecure devices get full features from some apps because they are certified, although they cite security, while GrapheneOS get half featured apps because it's "inse…

It's not about securing your device from external threats or bad actors; it's about securing the device from you.

Play Integrity certifies (and banks/etc approve) that Android 8.0 (oreo) unpatched for several years, full of vulnerabilities for RCE, 0-click, privilege escalation, etc, so full of holes it's trivial to get a root and then hide it (or use leaked cert), is absolutely a-ok, safe to use and secure for user.

Yes?

Is this what you're suggesting? :)

Because this is what's certified and embraced.

Re: cURL removes bug bounties

#247

A video showing some of the gems which most likely led to this frustration: https://youtu.be/8w6r4MKSe4I?si=7nfRd0VmX8tvXAnY

I started watching it but the modern presentation style of shouting everything instead of speaking at a normal volume, and using many many gestures and facial expressions to state a simple sentence made me switch it off rapidly. It seems to be a presentation style afflicting the YouTube generation, where they think you want to see a colossal microphone in someone's face (directional microphones work very well, and is…

I guess that's modern yt. At least it's not an AI slop channel.

Re: cURL removes bug bounties

#248

Earlier quoted context omitted.

I’m sure AI also found real vulnerabilities on cURL. My question is why you know cURL is being “spammed” but that FFMPEG is just getting legitimate problems.

> I’m sure AI also found real vulnerabilities on cURL. The curl maintainer published the reports and they were very clearly not security vulnerabilities in curl. > My question is why you know cURL is being “spammed” but that FFMPEG is just getting legitimate problems. To put it bluntly, because i can read. Did you actually read the reports in question?

> because i can read

So you looked their the bug list and then the source code and found which issues were legitimate or someone did so on your behalf?

Re: cURL removes bug bounties

#249

Earlier quoted context omitted.

> I’m sure AI also found real vulnerabilities on cURL. The curl maintainer published the reports and they were very clearly not security vulnerabilities in curl. > My question is why you know cURL is being “spammed” but that FFMPEG is just getting legitimate problems. To put it bluntly, because i can read. Did you actually read the reports in question?

> because i can read So you looked their the bug list and then the source code and found which issues were legitimate or someone did so on your behalf?

I read the specific examples that the maintainers of each project gave. The ones the ffmpeg maintainers complained about appeared to be real bugs. In fact i dont think the ffmpeg maintainers even dispute that. The ffmpeg maintainers after all fixed the issue in question. The ones the curl maintainers gave were clearly nonsense. The curl maintainers did not fix the issue because there was nothing to fix because the report didn't actually report anything that could be fixed because it made no sense.
Post reply on HN