Most of the sloptimists don't - for whatever reason - know about that.
In my experience most sloptimists don't even bother to read the bug-bounty docs - otherwise we'd receive much less reports as they are clearly about things exempt from a bug-bounty...
We will ban you and ridicule you in public if you waste our time on crap reports.
I see why that is needed, but at the same time I think there is a thin line here, what if someone simply is not sure, a false positive, is that a waste of time to perform investigation?
That ban/ridiculation threat demotivates the report, the message simply says that if you are not a high level engineer or a big company with resources to have identified something in the field, please don't report, individuals with limited knowledge not encouraged to report and that's when the person simply chooses the easiest path: Post the report publicly to some forum or microblog and then there is a disclosure of something that should have been embargoed.
I got the motivation but I don't feel good about the wording.
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •Klaus Frank
in reply to daniel:// stenberg:// • • •Alerta! Alerta!
in reply to daniel:// stenberg:// • • •From my experience: No.
Most of the sloptimists don't - for whatever reason - know about that.
In my experience most sloptimists don't even bother to read the bug-bounty docs - otherwise we'd receive much less reports as they are clearly about things exempt from a bug-bounty...
It'S fire&forget...
Every minute spent reading is lost revenue
Bruno Cesar Rocha ★ rochacbruno
in reply to daniel:// stenberg:// • • •I see why that is needed, but at the same time I think there is a thin line here, what if someone simply is not sure, a false positive, is that a waste of time to perform investigation?
That ban/ridiculation threat demotivates the report, the message simply says that if you are not a high level engineer or a big company with resources to have identified something in the field, please don't report, individuals with limited knowledge not encouraged to report and that's when the person simply chooses the easiest path: Post the report publicly to some forum or microblog and then there is a disclosure of something that should have been embargoed.
I got the motivation but I don't feel good about the wording.
daniel:// stenberg://
in reply to Bruno Cesar Rocha ★ rochacbruno • • •Wolf480pl
in reply to daniel:// stenberg:// • • •it links to curl.se/dev/vuln-disclosure.ht… which still mentions HackerOne.
I thought you were no longer using HackerOne? Or do you still use it, just with no bounties?
curl - Vulnerability Disclosure Policy
curl.sedaniel:// stenberg://
in reply to Wolf480pl • • •BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026 by bagder · Pull Request #20312 · curl/curl
GitHubdaniel:// stenberg://
in reply to daniel:// stenberg:// • • •Neil Craig
in reply to daniel:// stenberg:// • • •💯
daniel:// stenberg://
in reply to daniel:// stenberg:// • • •We will ban you and ridicule you in public if you waste our time on crap reports | Hacker News
news.ycombinator.comgary
in reply to daniel:// stenberg:// • • •