Overrun with AI slop, cURL scraps bug bounties to ensure "intact mental health"

92 points by Helithumper


mhkohne

This sucks, but having followed the blogging for months now, it's clear the curl maintainers are getting overrun by stupid shit. For every one real report (AI assisted or not) there's a stack of ones reporting vulnerabilities in functions that don't even exist.

freddyb

We have two bounty programs. Mozilla websites/infra on HackerOne and Firefox bounty on bugzilla. Both get slop but Firefox is doing better and gets less slop reports. I think this is because of the higher cost to reporting. Not $$$ cost, but because bugzilla is a bit discouraging and annoying to use.

I suggest people think of their barrier to reporting in the context of slop reports.

As a "way out" for people who need to do scalable reporting, we still have security@. It has an auto-reply for essentially everyone that explains them how to file bugs using bugzilla. Most incoming email will only see the auto reply. But those that deserve an individual responses typically get it.

maduggan

Good on the cURL maintainers for taking the steps they need to take. I do wonder how the security scanning exploit community will survive this, as my experience with a larger API with HackerOne is most of the reports were garbage before LLMs. They'd find non-dangerous behavior and report it, which we would fix, but the bounty would be low because....the thing they found wasn't dangerous.

Helithumper

The source PR linked in the article: https://github.com/curl/curl/pull/20312

Couldn’t post the PR directly as the article link.

chris-evelyn

Maybe a related phenomenon: ggml prohibits vibe coded contributions to llama.cpp

via Brian Campbell