I'm doing a keynote next month at an Open Source conference about AI (abuse) in #curl's security program etc. I could use your help:
1. Give me a clever title
2. What details would you like such a talk to contain?
I'm doing a keynote next month at an Open Source conference about AI (abuse) in #curl's security program etc. I could use your help:
1. Give me a clever title
2. What details would you like such a talk to contain?
Kushal Das
in reply to daniel:// stenberg:// • • •Royce Williams
in reply to daniel:// stenberg:// • • •Curl Up and De-AI*: Defending FOSS Projects and Communities Against the Rising Tide of Slop
*This is a nod to the English colloquialism "curl up and die"
Daniel Böhmer
in reply to daniel:// stenberg:// • • •1) Why not use AI to generate a list of suggested titles? 😅
To be honest these kind of inspiration are one of the few use cases where I find AI actually helpful.
Dave
in reply to daniel:// stenberg:// • • •2. examples of AI fails, from the sublime to the ridiculous.... as a way to describe the effort wasted
Dave 🐶
in reply to daniel:// stenberg:// • • •2. Any time-related metrics to show how AI is making things more inefficient (e.g. rolling period totals/increase in PRs/bug reports and how many are assessed as completely worthless). Some key examples that show bad development/understanding that a reasonable dev should know is stupid, but still gets submitted anyway.
�
in reply to daniel:// stenberg:// • • •Elusive Man
in reply to daniel:// stenberg:// • • •Helga Secures All the Things
in reply to daniel:// stenberg:// • • •I'm thinking something punning on bugs and plagues, trolls equipped with AI bludgeons. Flattening CURL: Timewasting trolls and the AI bug report barrage.
Curl in the Time Of Plague: Responding to AI-generated bug reports DDOSing a critical project.
I'm interested in the security implications and ideas for practical measures. I think the human factors are interesting - what are the demographics of people generating this nonsense - how many bad actors are we talking about, who are they, and what are their motivations?
Daniel Böhmer
in reply to daniel:// stenberg:// • • •Regarding question 2:
Some AI content is easy to identify. How did you identify AI content in recent cases where it was less obvious?
Does time wasted handling fake "bug reports" correlate with AI generating more believable content?
For what portion of incoming reports are you unsure if AI or not? Does this influence how you handle these?
How much does this topic cost actual human reporters, e.g. by reports accidentally being closed as AI slop or time spent to prove being human?
spartanatreyu
in reply to daniel:// stenberg:// • • •Title: AI (Argumentative/Abusive Interferants)' impact on cURL's security program.
Details: A stunning rebuke against everything that executives and salespeople claim to be true about AI in open source security.
Also, since "AI" is becoming a dirty word that left a poor taste in the mouth and now the conmen are shilling a new buzzword: "Agentic", I'd love a clear line in any charts showing when "Agentic" became a term to show how it doesn't magically make security reports better.
Psycodepath
in reply to daniel:// stenberg:// • • •Graham Sutherland / Polynomial
in reply to daniel:// stenberg:// • • •no clever title for you, but some ideas on things to cover:
- key stuff like the asymmetry of effort involved with generated reports vs. responding to them
- your thoughts regarding the sustainability of bug bounties in the face of LLM submissions
- maybe a timeline + data/graph on how many nonsense reports you get
- impact on you personally (motivation, interpersonal with contributors, etc.)
- how it's changed your views on tech, FOSS, and the security community in general
nyanbinary (Teamlead Compliance @ Cybercrime Inc.)
in reply to daniel:// stenberg:// • • •Nils Brederlow
in reply to daniel:// stenberg:// • • •tante
in reply to daniel:// stenberg:// • • •Dźwiedziu
in reply to daniel:// stenberg:// • • •The Monkey Paw Curls: how techbros wish for a world without other people
The Monkey Paw Curls: how techbros wish and how we will suffer
How techbros are bringing a 16t weight to everyone's curling
A curl-iculum on how to waste a volunteer's time, money and sanity
More after I'll have my caffeine injections.
Stephen Paulger
in reply to daniel:// stenberg:// • • •Androids dream of curl security vulnerabilities.
I’d like the talk to contain statistics and/or timelines that explain the scale of the problem, when it started, if it grows linearly or exponentially. What things you’ve tried to reduce the poor submissions and your thoughts on what works best. I’d like to see the most ridiculous example and the example that wasted most time.
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Abstract:
In these days of "vibe coding" and chatbots, users ask AIs for help with everything. Asked to find security problems in Open Source projects, AI bots tell users something that sounds right. Reporting these "findings" wastes everyone's time and causes much frustration and fatigue. Daniel shows how this looks, how it DDoS projects and how totally beyond crazy stupid this is. With examples and insights from the #curl project.
----
Good enough maybe?
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Title: AI slop attacks on the curl project
---
Contains "AI slop", mentions attack, includes curl.
No pun in there, but I also like this direct style.
p
in reply to daniel:// stenberg:// • • •And gives it more credence than it deserves
@bagder
daniel:// stenberg://
in reply to p • • •Ozzelot
in reply to daniel:// stenberg:// • • •AnneH
in reply to daniel:// stenberg:// • • •Thomas Thyberg
in reply to daniel:// stenberg:// • • •Detta jävla AI-slask!
Wuäck säger jag bara
Brahms
in reply to daniel:// stenberg:// • • •"how it DDoS projects" sounds a bit hard to read, but maybe thats just me.
also, is it technically distributed? I'd say its plain DoS, isn't it?
Solemarc
in reply to daniel:// stenberg:// • • •out of curiosity I asked Gemini "are there any code vulnerabilities in curl" and it gave me an answer that was basically
"yes, obviously, just like every other project, here's some of the most recent, make sure your software is up to date."
Makes me wonder what people ask the models and what models they use to make these reports.
daniel:// stenberg://
in reply to Solemarc • • •Gustav H Meyer
in reply to daniel:// stenberg:// • • •Sebastian Lauwers
in reply to daniel:// stenberg:// • • •- I got 99 AI problems (and slop is all of ‘em)
- It’s a hard slop life
- Yesterday, all AI troubles were so far away
- Once Upon a Time in Sloppywood
- The Pursuit of Sloppyness
- Don’t Slop Me Now
- How do they slop me? Let me count the ways.
- The Perks of Being a Maintainer
- Bagderman or (The Pernicious Deceitfulness of AI Slopporters)
⁂Krafty⁂ #NoKings
in reply to daniel:// stenberg:// • • •VessOnSecurity
in reply to daniel:// stenberg:// • • •Ruud Steltenpool
in reply to daniel:// stenberg:// • • •lambtor
in reply to daniel:// stenberg:// • • •"Curl of the monkey's paw: {security headline}"
Nicolas Lœuillet
in reply to daniel:// stenberg:// • • •Dave "Wear A Goddamn Mask" Cochran
in reply to daniel:// stenberg:// • • •1) "It Doesn't Work Though: Your investors Are Not Smart Enough To Be Allowed To Decide This For You"
I mean, may be a bit wide in scope for your purposes but that's the soapbox I'm on at the moment so that's what came to mind =\
João Santos
in reply to daniel:// stenberg:// • • •kaaswe
in reply to daniel:// stenberg:// • • •2. The history, the present and the future how AI has impacted the work, statistics and some ideas on mitigation as the AI scrapers will adapt and has proven not to care about their intrusion
Flavien Scheurer
in reply to daniel:// stenberg:// • • •Timo J
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Cory Carson
in reply to daniel:// stenberg:// • • •- Bug bounty programs encourage volume vs accuracy. Especially if you get paid for AI slop findings that aren’t valid but the vendor didn’t take the time to verify all 20,000 filings.
- If you don’t know the domain, you cannot tell the difference between AI slop bugs and the real deal bugs. But you do it anyway because your cousin told you it’s a shortcut to money, fame, clout. So, make it cost $ for unvetted submitter
Jürgen Gmach
in reply to daniel:// stenberg:// • • •daniel:// stenberg://
Unknown parent • • •nadja
in reply to daniel:// stenberg:// • • •Andrew Elwell
in reply to daniel:// stenberg:// • • •vramvoolenaar
in reply to daniel:// stenberg:// • • •Sascha Mettler
in reply to daniel:// stenberg:// • • •withoutclass
in reply to daniel:// stenberg:// • • •AI Slop Makes my Hair Curl
merriam-webster.com/dictionary…
Definition of make one's hair curl
Merriam-Webster DictionaryClaus Cramon Houmann
in reply to daniel:// stenberg:// • • •Why I can never curl up on my couch
or with a sneaky ADHD bracket
Why (a)I can never curl up on my couch
Alun Jones
in reply to daniel:// stenberg:// • • •qerupasy
in reply to daniel:// stenberg:// • • •