Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 9 hours ago

On the morning of the 13th day of the year we have received *checks notes* 13 #curl vulnerability reports on Hackerone this year.

None a confirmed vulnerability.

  • Copy link
  • Flag this post
  • Block
Thoralf Will 🇺🇦🇮🇱🇹🇼
Thoralf Will 🇺🇦🇮🇱🇹🇼
@thoralf@soc.umrath.net replied  ·  activity timestamp 9 hours ago

@bagder How many credible reports from that source?
If the ratio is too bad, I would consider to simply ignore reports from trash sources. Not worth the effort.

  • Copy link
  • Flag this comment
  • Block
Carsten
Carsten
@realmurphy@social.linux.pizza replied  ·  activity timestamp 9 hours ago

@bagder

*sigh* that does NOT bode well for the remaining days.

Thanks for enduring this!

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 9 hours ago

I suppose the upside is that lots of people are scrutinizing and try really hard to poke holes.

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 9 hours ago

Ironically, we have also received complaints from people who get annoyed when we disclose so many rubbish reports on Hackerone...

  • Copy link
  • Flag this comment
  • Block
niallor
niallor
@niallor@mastodon.ie replied  ·  activity timestamp 6 hours ago

@bagder shooting the messenger is ever the easy option

  • Copy link
  • Flag this comment
  • Block
Luke Nelson
Luke Nelson
@luc122c@social.nelson.zone replied  ·  activity timestamp 7 hours ago

@bagder
> it clogs hacktivity for people wanting to read good disclosures

I don't user hackerone but I'd imagine there are filters in the UI to hide these?

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 7 hours ago

@luc122c yes there is

  • Copy link
  • Flag this comment
  • Block
Mike Anderson
Mike Anderson
@mspcommentary@mastodon.online replied  ·  activity timestamp 8 hours ago

@bagder thank you for doing this and being vocal about it. The many-eyes principle does not work if some of the 'eyes' are crying wolf.

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 9 hours ago

and of course some of the people I ridicule, ban and expose in these reports come back to me all up in arms about them being completely innocent and they did not know and now I have ruined their professional lives because their cool hacker aliases are now tainted.

  • Copy link
  • Flag this comment
  • Block
Brokar
Brokar
@Brokar@mastodon.social replied  ·  activity timestamp 6 hours ago

@bagder If they don't check their AI slop before posting, it's up to them to take the (rightful) beating for it.

No mercy.

  • Copy link
  • Flag this comment
  • Block
Volker Stolz
Volker Stolz
@fm_volker@mastodon.social replied  ·  activity timestamp 6 hours ago

@bagder 🎻 – pity there isn’t an emoji with an even smaller one.

  • Copy link
  • Flag this comment
  • Block
jwz
jwz
@jwz@mastodon.social replied  ·  activity timestamp 8 hours ago

@bagder You mean I can't keep using "The Master of Disaster" on GitHub???

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 8 hours ago

@jwz pfft, there are not even *one* "leet speak" letter in that name! 😁

  • Copy link
  • Flag this comment
  • Block
Mike Anderson
Mike Anderson
@mspcommentary@mastodon.online replied  ·  activity timestamp 8 hours ago

@bagder they were happy enough thinking that they would boost their reputation by finding a vulnerability in curl...

  • Copy link
  • Flag this comment
  • Block
Gregory
Gregory
@grishka@mastodon.social replied  ·  activity timestamp 8 hours ago

@bagder huh??? Doesn't curl policy explicitly mention that the use of AI must be disclosed? Is it not entirely their own fault that they always miss this part?

  • Copy link
  • Flag this comment
  • Block
Stefan Eissing
Stefan Eissing
@icing@chaos.social replied  ·  activity timestamp 8 hours ago

@bagder Very sad indeed.

But we *do* let reports through if the hacker alias is really cool. Which, in these cases, they really weren‘t. 🔥💁🏻‍♂️

  • Copy link
  • Flag this comment
  • Block
Christopher Snowhill
Christopher Snowhill
@chris@social.losno.co replied  ·  activity timestamp 9 hours ago

@bagder Cue one of Steve Burke's "AI AI AI AI AI" montages from CES or such.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-beta.26 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct