Friendica
daniel:// stenberg://
daniel:// stenberg://

daniel:// stenberg://

bagder@mastodon.social

daniel:// stenberg://

bagder@mastodon.social
I write curl. I don't know anything.
ActivityPub
2025-07-08 05:45:37 2025-07-07 13:41:28 2025-07-07 13:41:26 8180403

daniel:// stenberg://
daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

2 months ago • •

daniel:// stenberg://

2 months ago • •


So far in 2025, we have received 52 vulnerability reports submitted to #curl. Two per week on average.

5 have been confirmed security problems (and have been published)

11 were tagged AI slop; all banned and reported to HackerOne

15 were considered "normal bugs"

21 were deemed "not applicable" (various reasons)

#curl
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Jacob Garber
mastodon - Link to source

Jacob Garber

in reply to daniel:// stenberg:// • 2 months ago • •
IIRC all submissions must now state if they used AI when creating the reports. Has that changed the number of bogus AI submissions?
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Jacob Garber

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Jacob Garber • 2 months ago • •
@jwgarber maybe. I think it's too early to tell for sure. They have not stopped but maybe they slowed down.
@Jacob Garber
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Daniel Appelquist
mastodon - Link to source

Daniel Appelquist

in reply to daniel:// stenberg:// • 2 months ago • •
is that sustainable? Are there "best practices" you can share for identifying the "AI slop"?
  •  Languages
  •  Search Text
  •  Share via ...
in reply to Daniel Appelquist

daniel:// stenberg://
mastodon - Link to source

daniel:// stenberg://

in reply to Daniel Appelquist • 1 month ago • •
there's no perfect way but humans are good at detecting when things are slightly "off" : too polite, too many bullet point lists, usually not specific enough. When asked to clarify it still is vague and way politer than humans normally are. Etc
This entry was edited (1 month ago)
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Stefan Eissing
mastodon - Link to source

Stefan Eissing

in reply to daniel:// stenberg:// • 1 month ago • •
@torgo The lack of swear words and nudity is always the biggest giveaway. 💁🏻‍♂️
@Daniel Appelquist
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Harry Sintonen
mastodon - Link to source

Harry Sintonen

in reply to daniel:// stenberg:// • 2 months ago • •
I still consider this a vulnerability. sintonen.fi/advisories/curl-ss…
  •  Languages
  •  Search Text
  •  Share via ...
in reply to daniel:// stenberg://

Nico Cartron
mastodon - Link to source

Nico Cartron

in reply to daniel:// stenberg:// • 2 months ago • •
that's not **that** bad, i was expecting a lot more of category #2 (AI slop)
  •  Languages
  •  Search Text
  •  Share via ...
⇧