Curl 因人工智能错误而取消漏洞奖励计划。
cURL removes bug bounties

原始链接: https://etn.se/index.php/nyheter/72808-curl-removes-bug-bounties.html

开源库cURL将在1月底结束漏洞赏金计划,旨在减少低质量、AI生成的漏洞报告涌入。维护者们被“AI垃圾”淹没——这些毫无意义的报告消耗了大量宝贵的时间来验证。虽然一些AI辅助报告*确实*促成了真正的修复(多年来贡献了101,020美元的赏金),但大量无用的提交是不可持续的。 值得注意的是,即使是著名的AI驱动漏洞猎人乔舒亚·罗杰斯,他成功地使用AI工具报告了许多漏洞,也支持这一决定。他认为,名声,而不是金钱,是发现cURL等项目关键问题的首要动力,而且赏金金额对于熟练的研究人员来说相对较小。 罗杰斯承认这会对低收入地区的研究人员产生影响,因为赏金对他们来说是一笔可观的收入,但他最终认为这一举措对于优先考虑真正的安全改进是必要的。cURL希望移除财务激励措施可以减少“垃圾”报告的“泛滥”,并让维护者专注于合法问题。

Hacker News 新闻 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 Curl 因为 AI 漏洞取消奖励计划 (etn.se) 40 分,作者 jnord,52 分钟前 | 隐藏 | 过去 | 收藏 | 2 条评论 eknkc 16 分钟前 [–] 漏洞列表,供感兴趣者参考:https://gist.github.com/bagder/07f7581f6e3d78ef37dfbfc81fd1d... 回复 husaku 8 分钟前 | 父评论 [–] > 为了重现问题,我在 Bard 中搜索了此漏洞。 提到 Bard 作为 LLM 让我回忆起以前的事情 :) 回复 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

Open source code library cURL is removing the possibility to earn money by reporting bugs, hoping that this will reduce the volume of AI slop reports. Joshua Rogers – AI wielding bug hunter of fame – thinks it's a great idea.

cURL has been flooded with AI-generated error reports. Now one of the incentives to create them will go away.

The vast majority of AI-generated error reports submitted to cURL are pure nonsense. Other open source projects are caught in the same pandemic.

cURL maintainer Daniel Stenberg made an impact with his reporting on AI-generated bug reports last year – ”Death by a thousand slops.”

Determining that they are nonsense is time-consuming, causing the maintainers lots of extra work.

”AI slop and bad reports in general have been increasing even more lately, so we have to try to brake the flood in order not to drown”, says cURL maintainer Daniel Stenberg to Swedish electronics industry news site etn.se.

Therefore, cURL is terminating the bounty payouts as of the end of January.

“We hope this removes some of the incentives for people to send us garbage. We spend far too much time handling slop due to findings that are not real, exaggerated, or misunderstood.”

Not all AI-generated bug reports are nonsense. It’s not possible to determine the exact share, but Daniel Stenberg knows of more than a hundred good AI assisted reports that led to corrections.

In total, 87 bug reports to cURL have over the years amounted to USD 101,020 in bounties.

How many of them would have gone under the radar if the bounty money had not existed?

Elektroniktidningen passes that question on to debugging champion Joshua Rogers, who last year flooded open source projects with bug reports – good reports.

Interestingly, his reports were generated with the help of AI tools. But he doesn’t just vibe along in the dark — he reviews and adds to AI's analysis before submitting anything.

Despite being an active code vulnerabilities hunter himself, he thinks removing the bounty money is a stellar idea ; something that should have been done a long time ago. He documented that view in a 2025 year-end posting.

“I think it's a good move and worth a bigger consideration by others. It's ridiculous that it went on for so long to be honest, and I personally would have pulled the plug long ago,” he says to etn.se.

But without the bounties an incentive to do code reviews disappears?

”*An incentive*, but not all,” he comments, ”especially for anything that will be reported which actually matters”.

So you think the effect won’t be that big?

“Not much. The real incentive for finding a vulnerability in cURL is the fame ('brand is priceless'), not the hundred or few thousand dollars. $10,000 (maximum cURL bounty) is not a lot of money in the grand scheme of things, for somebody capable of finding a critical vulnerability in curl.”

He realizes, though, that not everyone might share that attitude.

“My view is that there is an asymmetric relationship between developers (open source or not) and so-called "security researchers" (or even real security researchers). Regardless of whether the researchers are in expensive or cheap countries, the value provided to the developer is the same. However, on the flipside, the value of a bounty is not the same for every reporter -- in low socio-economic locations, a reward which would be the cost of lunch in Sweden can be massive for those low socio-economic-located people,” says Joshua Rogers.

联系我们 contact @ memedata.com