"The people holding up the internet"
A good-looking but somewhat depressing exposé about the people holding up current digital infrastructure as a hobby.
"The people holding up the internet"
A good-looking but somewhat depressing exposé about the people holding up current digital infrastructure as a hobby.
"Here you can find a full list of all New gTLD Program: 2026 Round applications"
Yeps, exactly as crazy as you can imagine.
Buckle up. One of the pending #curl CVEs that we publish next week is graded severity HIGH. Considered the worst flaw found in curl in several years.
Yes, found with AI.
Meat proxy as a service.
RE: https://mastodon.social/@bagder/117390229872578075
I'll write up a proposal.
Any other topic you think I should suggest?
"Google freezes open-source bug bounty program amid flood of invalid AI slop submissions"
my week: https://lists.haxx.se/pipermail/daniel/2026-September/000169.html
25 years, security, performance, Rock-solid, Development, rc2, stickers
When we announce over 20 new #curl CVEs on October 14, you will learn that every single one of them were found by clever humans using harnesses powered by AI models. Every. Single. One.
The holy trinity of modern vulnerability research.
because obviously on Windows "CON[superscript 1]" is also a reserved file name... *sigh* And yeah, you can write that either with ISO8859-1 *or* UTF-8 ...
You couldn't even make these things up if you tried.
"for months on end now, most of our teams have just been triaging bugs and coordinating releases. It has truly taken all the fun out of the job"
https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/
Fastly reports they see requests with #curl in the user-agent at roughly 7 million requests/sec.
When was the last time you used #curl to do telnet over an HTTPS proxy?
As of two minutes ago, #curl does no longer support SMB. 🎉
@dalias curl already does SCP and SFTP with credentials, so that's not really a new problem. But yeah, I don't feel that SSH has a good story for curl.
So tell me. Do you think #curl should support plain SSH:// URLs to execute commands remotely?
Heads up! In #curl 8.23.0 (end of October 2026) SMB(S) support will be gone.
Hi!
Thanks for offering to help out and contribute to the curl project.We do have a lack of Windows contributors and developers so all additional help is appreciated!
curl is an Open Source project. No one pays for the Windows version so there is no short-term monetary gain here, and we are not in a position where we are able to pay anyone for this help. Yes, Microsoft has been shipping curl as part of Windows since several years back and yes there are many commercial applications on (cont)
(I replied:)
> *What are you willing to pay for someone to take care of the Windows side?*
We get exactly zero dollars for our windows version of curl and you're welcome to get a share of this revenue!
No one in the seven-person curl security team is on or runs Windows. People sending us Windows-only flaws makes us groan and roll eyes. And sometimes hyperventilate a little.
Why this is so? Because no one in the team wants to be on Windows, and no other curl contributor is active enough, Windows-knowledgeable and interested in joining the team. Let me know if you are someone like that who I've just not noticed.
Hey Mozilla, the CVE program made a statement that smells almost directed at you:
"The CVE Program does not support assigning a single CVE ID to multiple distinct vulnerabilities when those vulnerabilities are independently understandable, independently exploitable, independently fixable, or independently relevant to defenders"
https://www.cve.org/Media/News/item/blog/2026/06/16/Preserving-Vulnerability-Level-Identification
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.