GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by daniel:// stenberg:// (bagder@mastodon.social)

  1. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Thursday, 08-Oct-2026 16:38:58 JST daniel:// stenberg:// daniel:// stenberg://

    "The people holding up the internet"

    A good-looking but somewhat depressing exposé about the people holding up current digital infrastructure as a hobby.

    https://sheets.works/data-viz/holding-up-the-internet

    In conversation about a day ago from mastodon.social permalink
  2. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Thursday, 08-Oct-2026 07:55:11 JST daniel:// stenberg:// daniel:// stenberg://

    "Here you can find a full list of all New gTLD Program: 2026 Round applications"

    Yeps, exactly as crazy as you can imagine.

    https://newgtldprogram-aps.icann.org/applications

    In conversation about 2 days ago from mastodon.social permalink
  3. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 07-Oct-2026 15:41:38 JST daniel:// stenberg:// daniel:// stenberg://

    Buckle up. One of the pending #curl CVEs that we publish next week is graded severity HIGH. Considered the worst flaw found in curl in several years.

    Yes, found with AI.

    In conversation about 2 days ago from mastodon.social permalink
  4. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 06-Oct-2026 17:16:51 JST daniel:// stenberg:// daniel:// stenberg://

    Meat proxy as a service.

    https://hackerone.com/reports/4064040

    In conversation about 3 days ago from mastodon.social permalink
  5. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 06-Oct-2026 15:31:12 JST daniel:// stenberg:// daniel:// stenberg://

    RE: https://mastodon.social/@bagder/117390229872578075

    I'll write up a proposal.

    Any other topic you think I should suggest?

    In conversation about 3 days ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      daniel:// stenberg:// (@bagder@mastodon.social)
      from daniel:// stenberg://
      Should I propose a #FOSDEM 2027 main track talk about the current state of the high volume AI-supported vulnerability reporting race? [ ] Yes [ ] No
  6. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 05-Oct-2026 15:40:45 JST daniel:// stenberg:// daniel:// stenberg://

    "Google freezes open-source bug bounty program amid flood of invalid AI slop submissions"

    https://www.tomshardware.com/tech-industry/artificial-intelligence/google-suspends-part-of-the-oss-vrp-bug-bounty-program-due-to-an-influx-of-invalid-ai-submissions-product-vulnerability-submissions-ended-october-1

    In conversation about 4 days ago from mastodon.social permalink

    Attachments

    1. Domain not in remote thumbnail source whitelist: cdn.mos.cms.futurecdn.net
      Google freezes open-source bug bounty program amid flood of invalid AI slop submissions — product flaw submissions halted until 2027 as maintainers drown in hallucinations
      from https://www.tomshardware.com/author/etiido-uko
      Engineers and open-source maintainers reportedly overwhelmed by thousands of sloppy reports
  7. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Saturday, 26-Sep-2026 07:18:44 JST daniel:// stenberg:// daniel:// stenberg://

    my week: https://lists.haxx.se/pipermail/daniel/2026-September/000169.html

    25 years, security, performance, Rock-solid, Development, rc2, stickers

    In conversation about 14 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/117/333/859/045/803/342/original/8fb72951e0c9996b.png

  8. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 23-Sep-2026 16:10:44 JST daniel:// stenberg:// daniel:// stenberg://

    When we announce over 20 new #curl CVEs on October 14, you will learn that every single one of them were found by clever humans using harnesses powered by AI models. Every. Single. One.

    The holy trinity of modern vulnerability research.

    In conversation about 16 days ago from mastodon.social permalink
  9. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 21-Sep-2026 19:41:24 JST daniel:// stenberg:// daniel:// stenberg://

    because obviously on Windows "CON[superscript 1]" is also a reserved file name... *sigh* And yeah, you can write that either with ISO8859-1 *or* UTF-8 ...

    You couldn't even make these things up if you tried.

    In conversation about 18 days ago from mastodon.social permalink
  10. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Friday, 18-Sep-2026 00:07:09 JST daniel:// stenberg:// daniel:// stenberg://

    "for months on end now, most of our teams have just been triaging bugs and coordinating releases. It has truly taken all the fun out of the job"

    https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/

    In conversation about 22 days ago from mastodon.social permalink

    Attachments


    1. https://files.mastodon.social/media_attachments/files/117/279/269/176/112/381/original/691a125deba27dc7.png
    2. Domain not in remote thumbnail source whitelist: images.unsplash.com
      Maintaining the love for coding in the time of AI
      By Alex Band Over the last year, we have seen the profound effects Large Language Models (LLMs) have on our open-source software work at NLnet Labs. These can be grouped into two main areas: community contributions and security reports. Before we dive into this topic, let me first give
  11. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 16-Sep-2026 00:24:59 JST daniel:// stenberg:// daniel:// stenberg://

    Fastly reports they see requests with #curl in the user-agent at roughly 7 million requests/sec.

    In conversation about 24 days ago from mastodon.social permalink
  12. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 14-Sep-2026 20:58:15 JST daniel:// stenberg:// daniel:// stenberg://

    When was the last time you used #curl to do telnet over an HTTPS proxy?

    In conversation about a month ago from mastodon.social permalink
  13. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Sunday, 13-Sep-2026 01:35:35 JST daniel:// stenberg:// daniel:// stenberg://

    As of two minutes ago, #curl does no longer support SMB. 🎉

    In conversation about a month ago from mastodon.social permalink
  14. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 31-Aug-2026 20:32:39 JST daniel:// stenberg:// daniel:// stenberg://
    in reply to
    • Rich Felker

    @dalias curl already does SCP and SFTP with credentials, so that's not really a new problem. But yeah, I don't feel that SSH has a good story for curl.

    In conversation about a month ago from mastodon.social permalink
  15. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 31-Aug-2026 20:25:24 JST daniel:// stenberg:// daniel:// stenberg://

    So tell me. Do you think #curl should support plain SSH:// URLs to execute commands remotely?

    https://github.com/curl/curl/pull/22661

    In conversation about a month ago from mastodon.social permalink
  16. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 24-Aug-2026 22:55:37 JST daniel:// stenberg:// daniel:// stenberg://

    Heads up! In #curl 8.23.0 (end of October 2026) SMB(S) support will be gone.

    https://github.com/curl/curl/pull/22652

    In conversation about 2 months ago from mastodon.social permalink
  17. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Thursday, 13-Aug-2026 06:01:54 JST daniel:// stenberg:// daniel:// stenberg://

    Hi!

    Thanks for offering to help out and contribute to the curl project.We do have a lack of Windows contributors and developers so all additional help is appreciated!

    curl is an Open Source project. No one pays for the Windows version so there is no short-term monetary gain here, and we are not in a position where we are able to pay anyone for this help. Yes, Microsoft has been shipping curl as part of Windows since several years back and yes there are many commercial applications on (cont)

    In conversation about 2 months ago from mastodon.social permalink
  18. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 11-Aug-2026 23:43:57 JST daniel:// stenberg:// daniel:// stenberg://

    (I replied:)

    > *What are you willing to pay for someone to take care of the Windows side?*

    We get exactly zero dollars for our windows version of curl and you're welcome to get a share of this revenue!

    In conversation about 2 months ago from mastodon.social permalink
  19. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Sunday, 09-Aug-2026 17:19:37 JST daniel:// stenberg:// daniel:// stenberg://

    No one in the seven-person curl security team is on or runs Windows. People sending us Windows-only flaws makes us groan and roll eyes. And sometimes hyperventilate a little.

    Why this is so? Because no one in the team wants to be on Windows, and no other curl contributor is active enough, Windows-knowledgeable and interested in joining the team. Let me know if you are someone like that who I've just not noticed.

    In conversation about 2 months ago from mastodon.social permalink
  20. Embed this notice
    daniel:// stenberg:// (bagder@mastodon.social)'s status on Saturday, 08-Aug-2026 00:52:18 JST daniel:// stenberg:// daniel:// stenberg://

    Hey Mozilla, the CVE program made a statement that smells almost directed at you:

    "The CVE Program does not support assigning a single CVE ID to multiple distinct vulnerabilities when those vulnerabilities are independently understandable, independently exploitable, independently fixable, or independently relevant to defenders"

    https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification

    In conversation about 2 months ago from mastodon.social permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification
  • Before

User actions

    daniel:// stenberg://

    daniel:// stenberg://

    I write curl. I don't know anything.

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          5732
          Member since
          16 Aug 2022
          Notices
          938
          Daily average
          1

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.