Live data from Hacker News

cURL removes bug bounties

etn.se

251–260 of 271 posts

Re: cURL removes bug bounties

#251

Earlier quoted context omitted.

> The purpose of a tool is important. > Guns have no other purpose than doing harm. Objects don't have purposes or intent until people use them, and many objects have multiple reasonable and dual purposes. Objects can be used for net good and net harm. A bow and arrow isn't specifically for harming humans but can be used for such. Chainsaws and meat cleavers too. What would you like a machine gun-wielding terrorist t…

Yes, guns are designed to harm people. You're arguing semantics about the obvious.

Wrong. That's your projection and your value judgement. Guns are designed to shoot bullets. That's all that can be stated honestly. They can be used for "benign" activities, "good" things, and "bad" things... where the value varied depending on who is asked the question.

Even if they were designed only for "harm", you seem to believe "all harm bad". So should criminals in the midst of committing violent acts not be stopped because that would "harm" them? You won't answer this. Extreme pacifism is insane, morally-inconsistent, ideological, thoughtless drivel that fails to acknowledge the monopolies on violence delegated to police and military that they benefit from.

Perhaps you might want to have your military abolished because they are "designed to cause harm"? Or the whole abolish prisons and police nonsense? Real anarchy is really bad.

Re: cURL removes bug bounties

#252

The solution for this, IMO, is flags. Just like with CTFs, host an instance of your software with a flag that can only be retrieved after a successful exploit. If someone submits the flag to you, there is no argueing about wether or not they found a valid vulnerability. Yes, this does not work for all vulnerability classes, but it is the best compromise in my mind.

How exactly would that work? Curl isn't exactly software that can be "hosted" somewhere, and I'm not sure where you'd hide the flag in the software? Either very few actual vulns would end up being able to retrieve the flag, or it would be trivial to retrieve the flag without an exploit.

Simple. You multiple instances with different flags covering different threat models. RCE, file read, etc. You then expose a webapplication for every instance that lets users control only those curl flags, that must be safe to be user controlled in the reapective threat model.

Re: cURL removes bug bounties

#253

Earlier quoted context omitted.

Last time I checked, there are still undecided cases wrt fair use. Sure, it’s looking favorable for LLM training, but it’s definitely still up in the air. > it’s completely transformative IANAL, but apparently hinges on how the training material is acquired

> IANAL, but apparently hinges on how the training material is acquired That doesn't make sense. You are either transforming something or you are not. There might be other legal considerations based on how you acquired, but it doesn't affect if something is transformative.

So there are mixed messages, per my understanding. Kadrey v Meta seems to favor the transformative nature. Bartz v Anthropic went to summary judgement but the court expressed skepticism that the use in that case was “transformative”. We won’t know because of the settlement.

Again, IANAL, so take this with a big grain of salt.

Re: cURL removes bug bounties

#254

Hackerone (where cURL hosted their bounty program) tracks the reputation of bounty hunters. I don't understand why they are not taking advantage of this. Make a private program, invite only hackers who have proved themselves by submitting relevant reports.

Say all projects did just that, only allowing reports from proven hackers. How does a new hacker then prove themselves?

find bugs for free at first. implement negative reputation for BS bugs

Re: cURL removes bug bounties

#255

Earlier quoted context omitted.

I'm not sure I completely agree, I don't think it's that black and white, it's a similar analogy to Guns and gun violence. Without the prevalence of guns there is simply less gun violence, but you could argue that it's also a human problem. Giving people who have no business using an LLM to submit slop bug bounties is a problem of the tools accessibility. But also a human problem of course. Edit: I should mention, I…

You can't ignore what guns are designed for.

Of course not, but they're inanimate.

Re: cURL removes bug bounties

#256
post #31

Earlier quoted context omitted.

> Consequently, there's some ~20 pages even in large companies. As someone working on Confluence to XWiki migration tools, I wish this was remotely true, my life would be way easier (and probably more boring :-)).

Interesting. First I've heard of Xwiki - it does look nice, and what with Atlassian's price increases... do you have any migration tips? [edit] I found https://extensions.xwiki.org/xwiki/bin/view/Extension/Conflu... - hopefully that's a good reference.

> hopefully that's a good reference

It is!

> what with Atlassian's price increases

And the end of their self hosting offerings (Server, Data Center), which is currently driving a lot of people towards XWiki, for other reasons than money. XWiki SAS being mainly in Europe makes it attractive to EU users too.

> do you have any migration tips?

I don't have specific migration tips. I hope the docs are complete enough!

However, I may suggest having a look at XWiki SAS's professional offering: https://store.xwiki.com/xwiki/bin/view/Extension/Confluence%...

The Confluence Migration Toolkit is based on the Confluence XML module you found, but it adds a nice and convenient UI, converts some more macros that XWiki SAS sells, there's support, and there's consulting for larger migration projects or projects with special requirements.

(note: despite some paying features, everything is open source)

(disclaimer in case it was not obvious, I work for XWiki SAS)

Re: cURL removes bug bounties

#257

Earlier quoted context omitted.

I started watching it but the modern presentation style of shouting everything instead of speaking at a normal volume, and using many many gestures and facial expressions to state a simple sentence made me switch it off rapidly. It seems to be a presentation style afflicting the YouTube generation, where they think you want to see a colossal microphone in someone's face (directional microphones work very well, and is…

I guess that's modern yt. At least it's not an AI slop channel .

That's true, but still it's small mercies!

Re: cURL removes bug bounties

#258

This is silly, people don't need AI to send you garbage. If your project is getting lots of junk reports, you should take it as a good sign, that people are looking at it a lot now. You don't remove the incentive, you ask for help to triage the junk. Curl is a popular and well supported tool, if it needs help in this area, there will be a long line of competent people not volunteering their time and/or money. If you…

Curl did already tend to get a decent number of junk reports from people who just didn't know what they were doing, but this was limited to the number of productive idiots who focused their productivity on curl specifically. AI allows significantly less motivated idiots to create substantially more workload, and therefore upgrades this phenomenon from a minor annoyance to a big problem, one that may just render publicly submitted bug reports not worth the project's time.

(And no, curl does not have a huge pool of potential maintainers to pull from on this. Open-source software in general suffers from a big lack of manpower, especially relative to the popularity of the tool)

Re: cURL removes bug bounties

#259

Earlier quoted context omitted.

> This is silly, people don't need AI to send you garbage People also don't need cigarettes to fall ill. But smoking still causes health problems.

What's your point? Because people smoke cigarettes, people who buy unrelated things should be punished? Or because a store sells cigarettes, stores in general shouldn't be paid for what they sell? Or is the time and effort to find vulns valueless?

The point is that "can happen without [THING] as well" does not mean the argument "[THING]s existence exacerbates the problem" is wrong.

Re: cURL removes bug bounties

#260

Earlier quoted context omitted.

What's your point? Because people smoke cigarettes, people who buy unrelated things should be punished? Or because a store sells cigarettes, stores in general shouldn't be paid for what they sell? Or is the time and effort to find vulns valueless?

The point is that "can happen without [THING] as well" does not mean the argument "[THING]s existence exacerbates the problem" is wrong.

No, the implication that "THING" is the cause of something and therefore something needs to be done must withstand the scrutiny of "other THINGS" also causing that thing, and therefore the solution is attacking either only one cause or not the real root cause.

The fact that bad reports have to be triage doesn't change with AI. What changed is the volume, clearly. So the reasonable response is not to blame "AI" but to ask for help with the added volume.

If HN gets flooded by AI spam, is the right response shutting down HN? spam is spam whether AI does it or a dedicated and coordinated large numbers of humans do it. The problem doesn't change because of who is causing it in this case.

Post reply on HN