Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg:// boosted
PhreakByte
PhreakByte
@nieldk@infosec.exchange  ·  activity timestamp yesterday

#curl finally updated to latest and greatest on #sailfishos in my repository https://build.sailfishos.org/package/binaries/home:nielnielsen/curl?repository=sailfish_latest_armv7hl

State of Repository sailfish_latest_armv7hl for home:nielnielsen / curl - SailfishOS Open Build Service

  • Copy link
  • Flag this post
  • Block
PhreakByte
PhreakByte
@nieldk@infosec.exchange  ·  activity timestamp yesterday

#curl finally updated to latest and greatest on #sailfishos in my repository https://build.sailfishos.org/package/binaries/home:nielnielsen/curl?repository=sailfish_latest_armv7hl

State of Repository sailfish_latest_armv7hl for home:nielnielsen / curl - SailfishOS Open Build Service

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp yesterday

If you need the latest #curl with support for #OpenSSL v1.x I have a version for you a support contract away.

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 2 days ago

Welcome calm329 as #curl commit author 1431: https://github.com/curl/curl/pull/20322

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg:// boosted
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕
@kubikpixel@chaos.social  ·  activity timestamp 2 days ago

»curl — Projekt beendet Bug-Bounty-Programm:
curl-Maintainer @bagder hat das Ende des Bug-Bounty-Programms angekündigt. Unbrauchbare KI-Meldungen nahmen wohl überhand.«

Ach was die KI ist künstlich aber nicht intelligent oder was nun?!?? Ich bin sogar der Meinung, dass dies was die KI angeht noch das rel. kleinste "Problem" ist. Schade dass deswegen das curl Bug-Bounty aufgelöst wird.

🧑‍💻 https://www.heise.de/news/curl-Projekt-beendet-Bug-Bounty-Programm-11142345.html?wt_mc=rss.red.ho.ho.rdf.beitrag.beitrag

#curl #ki #bugbounty #unbrauchbar #ai #uberhang #ausserkontrolle #it #ittools

Security

curl: Projekt beendet Bug-Bounty-Programm

curl-Maintainer Daniel Stenberg hat das Ende des Bug-Bounty-Programms angekündigt. Unbrauchbare KI-Meldungen nahmen wohl überhand.
  • Copy link
  • Flag this post
  • Block
Stefan Eissing
Stefan Eissing
@icing@chaos.social  ·  activity timestamp 2 days ago

"This is a vulnerability"
"No, it isn't"
"Yes, it is"
"Prove it!"
"Ok, it may not be now...
...but it is a trap for future developers!"

Security reporting for the utterly deranged.
#curl

  • Copy link
  • Flag this post
  • Block
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕
𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕
@kubikpixel@chaos.social  ·  activity timestamp 2 days ago

»curl — Projekt beendet Bug-Bounty-Programm:
curl-Maintainer @bagder hat das Ende des Bug-Bounty-Programms angekündigt. Unbrauchbare KI-Meldungen nahmen wohl überhand.«

Ach was die KI ist künstlich aber nicht intelligent oder was nun?!?? Ich bin sogar der Meinung, dass dies was die KI angeht noch das rel. kleinste "Problem" ist. Schade dass deswegen das curl Bug-Bounty aufgelöst wird.

🧑‍💻 https://www.heise.de/news/curl-Projekt-beendet-Bug-Bounty-Programm-11142345.html?wt_mc=rss.red.ho.ho.rdf.beitrag.beitrag

#curl #ki #bugbounty #unbrauchbar #ai #uberhang #ausserkontrolle #it #ittools

Security

curl: Projekt beendet Bug-Bounty-Programm

curl-Maintainer Daniel Stenberg hat das Ende des Bug-Bounty-Programms angekündigt. Unbrauchbare KI-Meldungen nahmen wohl überhand.
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 2 days ago

Meanwhile, we have now added 4 lines of code for every line of code still remaining in #curl

This means that on average, every single line of production code has been touched four times. Written once, then updated three more times. And yeah, some lines of course many more times than average, and some less so.

Graph showing lines of code added per lines of code still present. In curl. Over time. Reaching above 4 in early 2026.
Graph showing lines of code added per lines of code still present. In curl. Over time. Reaching above 4 in early 2026.
Graph showing lines of code added per lines of code still present. In curl. Over time. Reaching above 4 in early 2026.
  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

added a median plot to the average #curl source code complexity graph

Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this post
  • Block
hypebot and 2 others boosted
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 3 days ago

I understand #curl project decision to stop the #bugbounty and leave #hackerone. The torrent of #AIslop has become unbearable.

https://github.com/curl/curl/pull/20312

I will continue to report vulnerabilities to the project whether it has a bug bounty or not.

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

It's about sustainability too. #curl is a small project. We cannot spend multiple hours every day arguing with people who want money for having found what is perhaps a bug - but often is not even that.

It drains us. It drowns us.

Onward and upward!

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

We are at *twenty* hackerone submissions so for #curl far this year. Zero of them a confirmed vulnerability.

Lars Marowsky-Brée 😷
Lars Marowsky-Brée 😷
@larsmb@mastodon.online replied  ·  activity timestamp 3 days ago

@bagder Shld I submit a #hackerone submission for #curl, identifying hackerone as a DoS attack vector for the project, recommending depreciation?

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

We are at *twenty* hackerone submissions so for #curl far this year. Zero of them a confirmed vulnerability.

  • Copy link
  • Flag this post
  • Block
Harry Sintonen
Harry Sintonen
@harrysintonen@infosec.exchange  ·  activity timestamp 3 days ago

I understand #curl project decision to stop the #bugbounty and leave #hackerone. The torrent of #AIslop has become unbearable.

https://github.com/curl/curl/pull/20312

I will continue to report vulnerabilities to the project whether it has a bug bounty or not.

  • Copy link
  • Flag this post
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 3 days ago

It is our moral imperative to consider the "real world" and actual users when assessing the possible security impact of a reported #curl issue. If we deem that there is likely to be zero affected users, then we do more damage than good by insisting on doing the secure dance for the issue.

Then we end up with a severity level that is below LOW, and then we treat it as a bug instead. For the good of mankind.

  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 4 days ago

Ayder – HTTP-native durable event log written in C (curl as client)

https://github.com/A1darbek/ayder

#HackerNews #Ayder #HTTP-native #durable #event #log #C #curl #client #technology #open-source

GitHub

GitHub - A1darbek/ayder

Contribute to A1darbek/ayder development by creating an account on GitHub.
  • Copy link
  • Flag this post
  • Block
hypebot boosted
Stefan Eissing
Stefan Eissing
@icing@chaos.social  ·  activity timestamp 4 days ago

To be frank: the report quality on Hackerone is so low by now that the #curl team decided to make CVEs based only on the coolness of the reporter‘s username.

💁🏻‍♂️😌

  • Copy link
  • Flag this post
  • Block
JKB boosted
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 4 days ago

On the morning of the 13th day of the year we have received *checks notes* 13 #curl vulnerability reports on Hackerone this year.

None a confirmed vulnerability.

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.35 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct