Overrun with AI slop, cURL scraps bug bounties to ensure “intact mental health”



The project developer for one of the Internet’s most popular networking tools is scrapping its vulnerability reward program after being overrun by a spike in the submission of low-quality reports, much of it AI-generated slop.

“We are just a small single open source project with a small number of active maintainers,” Daniel Stenberg, the founder and lead developer of the open source app cURL, said Thursday. “It is not in our power to change how all these people and their slop machines work. We need to make moves to ensure our survival and intact mental health.”

Manufacturing bogus bugs

His comments came as cURL users complained that the move was treating the symptoms caused by AI slop without addressing the cause. The users said they were concerned the move would eliminate a key means for ensuring and maintaining the security of the tool. Stenberg largely agreed, but indicated his team had little choice.

In a separate post on Thursday, Stenberg wrote: “We will ban you and ridicule you in public if you waste our time on crap reports.” An update to cURL’s official GitHub account made the termination, which takes effect at the end of this month, official.

cURL was first released three decades ago, under the name httpget and later urlget. It has since become an indispensable tool among admins, researchers, and security professionals, among others, for a wide range of tasks, including file transfers, troubleshooting buggy web software, and automating tasks. cURL is integrated into default versions of Windows, macOS, and most distributions of Linux.

As such a widely used tool for interacting with vast amounts of data online, security is paramount. Like many other software makers, cURL project members have relied on private bug reports submitted by outside researchers. To provide an incentive and to reward high-quality submissions, the project members have paid cash bounties in return for reports of high-severity vulnerabilities.



Source link

  • Related Posts

    Parallel Web Systems hits $2B valuation five months after its last big raise

    Parallel Web Systems, the AI agent-tool startup founded by former Twitter CEO Parag Agrawal, has raised a $100 million Series B at a $2 billion valuation led by Sequoia. Existing…

    In the coming AI future, Britain must not end up at the mercy of US tech giants | Rafael Behr

    Donald Trump is not impressed by soft power. He respects hard men with military muscle. But he can be moved by pageantry, which is the purpose of King Charles’s visit…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Parallel Web Systems hits $2B valuation five months after its last big raise

    Parallel Web Systems hits $2B valuation five months after its last big raise

    I’m enjoying the boreal cyborg world of spooky FPS Industria 2, which launches on PC today and also has an excellent diegetic crafting screen

    I’m enjoying the boreal cyborg world of spooky FPS Industria 2, which launches on PC today and also has an excellent diegetic crafting screen

    6 Sustainable Kids Luggage Brands And Suitcases

    6 Sustainable Kids Luggage Brands And Suitcases

    Eating one bag of chips a day increases dementia risk, new study suggests

    Wins for Hampshire, Essex and The Blaze in One-Day Cup

    Wins for Hampshire, Essex and The Blaze in One-Day Cup

    The Top X Highest Paid US Military Pilot Ranks in 2026

    The Top X Highest Paid US Military Pilot Ranks in 2026