theregister.com/2026/01/21/cur…
(I will blog about the details next week)
Curl shutters bug bounty program to remove incentive for submitting AI slop
: Maintainer hopes hackers send bug reports anyway, will keep shaming ‘silly' onesSimon Sharwood (The Register)
Oliver Schönrock
in reply to daniel:// stenberg:// • • •👍👌
Money talks
screwlisp
in reply to daniel:// stenberg:// • • •though I noticed while I was visiting I was served an ad for buying and I quote
"See why AI-driven products demand new sourcing. Qualify alternates early, diversify"
BaseFortify
in reply to daniel:// stenberg:// • • •Ehay2k
in reply to daniel:// stenberg:// • • •So sorry you (and many other code maintainers) have to deal with this slop.
With AI, it's now far too easy for unqualified people to automate their bug bounty submissions. It's a numbers game: submit 1K (or maybe even 10K) alleged bugs and if you land just one bounty, it's worth it.
I was wondering if making people pay for each bounty submission would help deter this behavior? One reason they bulk submit slop is that it's basically free.
I'm not sure of the mechanics here though.