the latest vuln we got reported was detected by... a Chinese AI thing. They're on it as well.
Notices by daniel:// stenberg:// (bagder@mastodon.social), page 2
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 20-May-2026 21:37:49 JST
daniel:// stenberg://
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 19-May-2026 22:17:45 JST
daniel:// stenberg://
Now I'm happy I wasted time making those silly sinus-moving things for the alternative #curl progress meter. (seen in the log output for a failed GitHub CI job)
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 18-May-2026 21:54:12 JST
daniel:// stenberg://
A slide from my talk this Thursday. How we view our role in the curl project.
https://www.meetup.com/openinfra-user-group-sweden/events/313615139/
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Sunday, 17-May-2026 00:14:42 JST
daniel:// stenberg://
"Trailing dots in hostnames is a menace and a plague that keeps haunting us and the world at large."
I felt I had to put this into this CVE advisory I'm drafting...
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Friday, 15-May-2026 06:18:03 JST
daniel:// stenberg://
18 security reports in a single day. Let's not beat this record.
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Friday, 15-May-2026 00:12:51 JST
daniel:// stenberg://
Day off. National holiday. Fourteen security reports have arrived in the last fourteen hours... 😱
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 13-May-2026 21:25:09 JST
daniel:// stenberg://
"Packages that can't be rebuilt byte-for-byte are now blocked from entering Debian's testing branch."
https://itsfoss.com/news/debian-makes-reproducible-builds-mandatory/
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 13-May-2026 19:03:53 JST
daniel:// stenberg://
ENHANCE_YOUR_CALM
In conversation from mastodon.social permalink -
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 12-May-2026 18:18:12 JST
daniel:// stenberg://
I like the Register's headline: "Anthropic’s bug-hunting Mythos was greatest marketing stunt ever, says cURL creator"
... even though I did not say that. 😂
In conversation from mastodon.social permalink Attachments
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 12-May-2026 15:29:08 JST
daniel:// stenberg://
Bandwidth spend per hour on my blog the last week. Can you spot when I posted?
In conversation from mastodon.social permalink Attachments
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 11-May-2026 16:01:38 JST
daniel:// stenberg://
My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing.
In conversation from mastodon.social permalink -
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Monday, 11-May-2026 16:01:21 JST
daniel:// stenberg://
#Mythos finds a #curl vulnerability
yes, as in singular one.
https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
In conversation from mastodon.social permalink -
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Sunday, 10-May-2026 02:08:01 JST
daniel:// stenberg://
I'm on it. There is a Mythos scanning #curl blog post pending.
In conversation from mastodon.social permalink -
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Tuesday, 05-May-2026 02:49:51 JST
daniel:// stenberg://
"Science runs on Open Source. Let’s fund it."
In conversation from mastodon.social permalink Attachments
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Thursday, 30-Apr-2026 17:43:38 JST
daniel:// stenberg://
I had to save the book quote as a blog post: https://daniel.haxx.se/blog/2026/04/30/inspired/
In conversation from mastodon.social permalink Attachments
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Thursday, 30-Apr-2026 09:14:18 JST
daniel:// stenberg://
Reading this brings me close to medal-receiving levels of joy.
In conversation from mastodon.social permalink Attachments
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Wednesday, 29-Apr-2026 22:29:22 JST
daniel:// stenberg://
RE: https://toot.yosh.is/@yosh/116487778402803336
Excuses. They forgot to run their site as they should and instead got lost working on AI features we never asked for. That's why.
In conversation from mastodon.social permalink Attachments
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Saturday, 25-Apr-2026 23:28:36 JST
daniel:// stenberg://
"Pre-built GitHub profiles with five-year commit histories and Arctic Code Vault Contributor badges sell for approximately $5,000 on Telegram."
https://awesomeagents.ai/news/github-fake-stars-investigation/
In conversation from mastodon.social permalink Attachments
-
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Saturday, 25-Apr-2026 18:06:24 JST
daniel:// stenberg://
Remember: this is a time when every open source project out there suffers from an extreme issue and security report avalanche and overload.
Ask yourself what you do to make the situation better.
Make sure your employer does as well.
In conversation from mastodon.social permalink -
Embed this notice
daniel:// stenberg:// (bagder@mastodon.social)'s status on Saturday, 18-Apr-2026 15:20:44 JST
daniel:// stenberg://
After just having responded to the third #curl security report for the evening I noticed a post that cheered me up...
Have a good Friday everyone!
In conversation from mastodon.social permalink Attachments