Live data from Hacker News

Curl will not accept vulnerability reports during July 2026

daniel.haxx.se

321–326 of 326 posts

Re: Curl will not accept vulnerability reports during July 2026

#321

What this shows me (again) is that the whole system where vulnerabilities need to be constantly discovered, reported, analyzed, then patched, then the new version distributed to every singe user - again and again - is quite obviously unsustainable. The industry must come up with some alternative system for dealing with bugs and security issues. Currently the industry prefers to play dumb and turn its own failures int…

Yeah, pay the foss maintainers. Anyone, who uses these projects must pay a minimum fee. Companies expected to pay a lot more.

Re: Curl will not accept vulnerability reports during July 2026

#322
post #3

> > The bad guys won’t rest > Probably not. But we will. A pleasant dose of humanity in decidedly inhuman times.

>A pleasant dose of humanity in decidedly inhuman times.

As opposed to when?

Do tell.

I see this crap so much online. You just want an excuse to give up and be a victim. I hear it online and irl. You young people are broken, broken yet you have everything.

How old are you, and where do you live?

Life is better now than ever. I in Sweden can buy everything, access everything, and I own my apartment. Problem?

As opposed to what?

WW1? WW2? Vietnam war and corrupt nixon? The cold war when Russians accidentally invaded Sweden? Nuclear bomb fear? the 90s debt crisis? 90s balkan war? And refugee crisis? 9/11 and all that? 2015 refugee crisis?

When?

What do you compare to?

The truth is, life is getting better. All the time. We had 10% unemployment in 2016 and even worse in 2008 when I graduated. Grow up.

Re: Curl will not accept vulnerability reports during July 2026

#323
post #98

Earlier quoted context omitted.

Yeah, I have seen several people who are completely shadowbanned (all comments dead) without any visible reason. There seems to be no way to report this.

Just email hn@ycombinator.com and Dang will look into it. He responds quick and will always address any concerns.

It worked, Dang now unbanned this user.

Re: Curl will not accept vulnerability reports during July 2026

#324
post #187

Earlier quoted context omitted.

Until someone races to the bottom to do 12 months of availability.

A race to the bottom of… unpaid work that eliminates the paid work? Can you elaborate?

I mean.. isn't this basically open source?

Re: Curl will not accept vulnerability reports during July 2026

#325

Earlier quoted context omitted.

I generally work for small companies, and while I'll do something very similar when taking leave (or just at the weekend) I do also make sure someone has contact details for me in the case of anything that truly can't wait until I get back. My experience of doing this has been that people will be judicious about whether something actually warrants interrupting someone's holiday, and it also results in me being less i…

I was the only full time sysadmin of a 20 person company. I went on vacation for three whole weeks. I was half way around the globe and not reachable. The company still existed after I came back. They did have a problem. They tried to reach me. They couldn't. They figured it out by themselves. I think we believe ourselves to be more irreplaceable than we are. And if you really think you are irreplaceable then the pro…

In one case I was the only full time technical person in the company. This was a very early stage startup that had literally nobody else who would know how to even start reading the code, never mind find the particularly gnarly bug that was causing paid for orders to disappear which surfaced while I was on holiday. (Because I was the only person capable of writing code I could also be pretty certain the bug was one I'd introduced and missed, so I wasn't too grumpy at debugging it from the back of a moving vehicle while on holiday).

Yes, ultimately the problem there is having a bus factor of one, and we resolved that in time but in those early days sometimes there really is nobody else who can fix things.

Re: Curl will not accept vulnerability reports during July 2026

#326

Earlier quoted context omitted.

How would sandboxing curl help with vulnerabilities in your pdf reader?

Obviously, you need to sandbox all tools in the chain that handles untrusted data. This is security 101 stuff

Do you sandbox the sandbox? When do you stop?
Post reply on HN