The end of the #curl bug-bounty
-
@addison I believe it will be removed by the end of January when this officially goes into effect
@bagder@mastodon.social Gotcha, just wanted to ask to make sure since they were listed separately.
-
The end of the #curl bug-bounty
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
@bagder great write up. Thanks for all you do
-
The end of the #curl bug-bounty
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
The bugbounty crash of 2025 in a single image (from the blog post)
-
The bugbounty crash of 2025 in a single image (from the blog post)
@bagder@mastodon.social hey Daniel, I'm curious, were you financing the bug bounty payouts by yourself?
-
@bagder@mastodon.social hey Daniel, I'm curious, were you financing the bug bounty payouts by yourself?
@ulveon no, the IBB did that
-
The bugbounty crash of 2025 in a single image (from the blog post)
@bagder talking about graphs maybe one showing the payout per month/year might be nice?
"The bugbounty cash"
-
@bagder talking about graphs maybe one showing the payout per month/year might be nice?
"The bugbounty cash"
-
@poolitzer there's also this
-
The end of the #curl bug-bounty
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
Charging people money in an International context is complicated and a maintenance burden.
I think if it does come to this, you might consider requiring a small donation to a charity? This would dramatically reduce the hassle on all sides, and do something good as a bonus.
-
Charging people money in an International context is complicated and a maintenance burden.
I think if it does come to this, you might consider requiring a small donation to a charity? This would dramatically reduce the hassle on all sides, and do something good as a bonus.
@fre receiving money for vulnerability *reports* would not mean that we ship vulnerabilities though...
-
@fre receiving money for vulnerability *reports* would not mean that we ship vulnerabilities though...
@bagder of course not, but I guess someone could spin it like "they now have incentive to publish buggy code", right? Anyway, that wasn't the point of the post and I didn't want to insinuate any bad intentions, sorry. I'll remove that part.
-
The end of the #curl bug-bounty
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
@bagder Is the header image for the blogpost AI generated?
-
@bagder Is the header image for the blogpost AI generated?
@nini to illustrate the point of the blog post, I should probably just say: maybe, maybe not. =)
-
@ulveon no, the IBB did that
@bagder@mastodon.social Were you pressured to remove the payouts by them, or was it a decision you requested unilaterally due to slop reports?
-
@bagder@mastodon.social Were you pressured to remove the payouts by them, or was it a decision you requested unilaterally due to slop reports?
@ulveon I asked them to stop.
-
The end of the #curl bug-bounty
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
@bagder I feel that this onslaught of AI slop reports is a DOS attack that weakens the security.
-
@bagder I feel that this onslaught of AI slop reports is a DOS attack that weakens the security.
@ollej that is certainly a risk, yes
-
@poolitzer there's also this
@bagder should have looked that up first, ofc you had them ready :D
-
@nini to illustrate the point of the blog post, I should probably just say: maybe, maybe not. =)
@bagder I shall wink in your direction and touch my nose on the side in acceptance of this.
-
The end of the #curl bug-bounty
https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/
@bagder "not even one in twenty was real" is one of the most damning things I've ever heard about the state of BBPs. that's abysmal.