Earlier quoted context omitted.
> I can’t remember the word for “prosocial through lowering cost to zero” is but sometimes that too. Wiktionary: Benevolent, altruistic, unselfish, beneficent, philanthropic, selfless
Philanthropic! Thanks.
Curl will not accept vulnerability reports during July 2026
311–320 of 326 posts
Re: Curl will not accept vulnerability reports during July 2026
#312Earlier quoted context omitted.
I liked the idea as well, maybe OSS should adopt 6 months availability and 6 months for enterprise support schedule. This way both could benefit, OSS gets more funding, enterprise gets support (cheaper than hiring full-time employee for specific OSS)
nice idea to time vacation in the summar, right around major security conferences (blackhat, defcon, etc), when large bulk of CVEs get published, to put some fire under the enterprise butts
Re: Curl will not accept vulnerability reports during July 2026
#313Re: Curl will not accept vulnerability reports during July 2026
#314Earlier quoted context omitted.
Right, but nobody actually uses curl as the end destination, right? You use it to download something so that you can run another tool on it. And as such, you need to already be sandboxing the tool (since it processes untrusted data you received over the internet).
How would sandboxing curl help with vulnerabilities in your pdf reader?
Re: Curl will not accept vulnerability reports during July 2026
#315Earlier quoted context omitted.
Yeah, I have seen several people who are completely shadowbanned (all comments dead) without any visible reason. There seems to be no way to report this.
Just email hn@ycombinator.com and Dang will look into it. He responds quick and will always address any concerns.
Re: Curl will not accept vulnerability reports during July 2026
#316Earlier quoted context omitted.
> Turns out they're as human as software engineers. Lawyers start out as humans but something about going into law school and then private practice, and feeding them after midnight turns them into... something else entirely.
Arguably the same is true for some software engineers. One minute they're a good friend that you respect, next thing you know they're building killbots or AI non consensual porn generators or surveillance platforms that are illegal for government agencies to operate. Perhaps it happens more often to lawyers?
Re: Curl will not accept vulnerability reports during July 2026
#317Earlier quoted context omitted.
Here I was thinking that cURL's (non-existent) enterprise support contracts were a polite way to tell brain-dead paper pushers to GTFO: https://daniel.haxx.se/blog/2022/01/24/logj4-security-inquir...
https://curl.se/support.html What do you mean by non-existent?
Re: Curl will not accept vulnerability reports during July 2026
#318An evil way to extort money via support contracts.
Re: Curl will not accept vulnerability reports during July 2026
#319Earlier quoted context omitted.
Doing the fix yourself is almost always the easy part. Disclosing it and getting a patch shipped across the entire Internet is the hard part.
Why would you personally need the entire internet to receive a fix?
Re: Curl will not accept vulnerability reports during July 2026
#320Earlier quoted context omitted.
Mythos found only one. Would have to be pretty serious bad guys. https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-v...
Remember though that many other AIs had already run and found issues that were fixed. If you had a time machine and took Mythos back a year it probably would have found a lot more. (if anyone has access to mythos it wouldn't be hard to test - download a release from last year and check)
Mythos might have seen last years bug reports so that might be cheating, kind-of. Bug reports ought to be great study material for LLM training.