top | item 46903476

(no title)

mrkeen | 24 days ago

Daniel Stenberg has been vocal the last few months on Mastodon about being overwhelmed by false security issues submitted to the curl project.

So much so that he had to eventually close the bug bounty program.

https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-b...

discuss

order

tptacek|24 days ago

We're discussing a project led by actual vulnerability researchers, not random people in Indonesia hoping to score $50 by cajoling maintainers about atyle nits.

malfist|24 days ago

Vulnerability researches with a vested interest in making LLMs valuable. The difference isn't meaningful

nextaccountic|23 days ago

> in Indonesia

That's uncalled for.. there's actual security researches in Indonesia and other countries you could use to exemplify this

PunchyHamster|24 days ago

I'm not sure the gap between the two is all that wide

ath3nd|24 days ago

Yep, very meaningful difference indeed. It's not like professionals have ever have had a vested interest to spread misinformation to shill a product.

It's not like there were ads with real doctors recommending Camel cigarettes.

It's not like the browser "breakthrough" recently which pulled 300 OSS dependencies together, removed attribution and called the mess "working".

The desperation of the Samas, Musks, Satyas and Anthropics of this world and their fanbase to paint marginal 0.0001337% improvements in a gamed SWE ranking as something worth any attention is just delicious. Opus 4.6? Please, more like Opus 4.5.0.2-RC. All I hear is the sound of a bubble going pop. Delightful.

pityJuke|24 days ago

Daniel is a smart man. He's been frustrated by slop, but he has equally accepted [0] AI-derived bug submissions from people who know what they are doing.

I would imagine Anthropic are the latter type of individual.

[0]: https://mastodon.social/@bagder/115241241075258997

kyleee|24 days ago

[deleted]