<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[AIs have been finding bugs and vulnerabilities in #curl for some time.]]></title><description><![CDATA[<p>AIs have been finding bugs and vulnerabilities in <a href="https://chaos.social/tags/curl" rel="tag">#<span>curl</span></a> for some time.</p><p>Is it work to fix those? Yes.</p><p>Has someone paid for this? Partially (wolfSSL and <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span>)</p><p>Are the AIs annoying? Yes, very.</p><p>Could humans find the same bugs? Yes, if they‘d somehow avoid being bored to death through it.</p><p>Was there something „heartbleed“ like? No.</p><p>Were there lots of C mistakes? No, logic bugs mostly.</p><p>Do AIs run out of steam? Yes. After a while a model stops finding things. Findings differ per model.</p>]]></description><link>https://forum.fedi.dk/topic/7cad457c-3ca0-4bb1-a737-2465d55dc714/ais-have-been-finding-bugs-and-vulnerabilities-in-curl-for-some-time.</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 17:40:09 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/7cad457c-3ca0-4bb1-a737-2465d55dc714.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 18 Apr 2026 06:34:29 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 11:16:36 GMT]]></title><description><![CDATA[<p><span><a href="/user/jfbucas%40mastodon.dias.ie">@<span>jfbucas</span></a></span> <span><a href="/user/icing%40chaos.social">@<span>icing</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> <span><a href="/user/bortzmeyer%40mastodon.gougere.fr">@<span>bortzmeyer</span></a></span> For a while, I guess. There is a limit we already seem to be seeing: the amount of bugs is large, but not infinite. Also: once we integrate a check using these LLM’s into our build chains, the amount of bugs discovered after release may actually go down, eventually.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.nl/users/mkoek/statuses/116425424670804276</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.nl/users/mkoek/statuses/116425424670804276</guid><dc:creator><![CDATA[mkoek@mastodon.nl]]></dc:creator><pubDate>Sat, 18 Apr 2026 11:16:36 GMT</pubDate></item><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 09:33:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/tkissing%40mastodon.social">@<span>tkissing</span></a></span> <span><a href="/user/icing%40chaos.social">@<span>icing</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> Even better: <a href="https://chaos.social/tags/Anthropic" rel="tag">#<span>Anthropic</span></a>’s own employees whipped up some pipeline to channel all the findings to Upwork and similar click-work platforms, which then makes underpaid laborers do the actual work.</p>]]></description><link>https://forum.fedi.dk/post/https://chaos.social/users/fnwbr/statuses/116425020408126748</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://chaos.social/users/fnwbr/statuses/116425020408126748</guid><dc:creator><![CDATA[fnwbr@chaos.social]]></dc:creator><pubDate>Sat, 18 Apr 2026 09:33:48 GMT</pubDate></item><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 09:23:17 GMT]]></title><description><![CDATA[<p><span><a href="/user/icing%40chaos.social">@<span>icing</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> Call me overly skeptic, but remembering Builder.ai I would not be surprised if Anthropic has a bunch of engineers run Mythos on a few high-profile projects and filter out all the bad reports before they get actually posted to make their model look better than it is.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/tkissing/statuses/116424979081124038</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/tkissing/statuses/116424979081124038</guid><dc:creator><![CDATA[tkissing@mastodon.social]]></dc:creator><pubDate>Sat, 18 Apr 2026 09:23:17 GMT</pubDate></item><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 09:00:55 GMT]]></title><description><![CDATA[<p><span><a href="/user/connynasch%40mastodon.social">@<span>connynasch</span></a></span> <span><a href="/user/icing%40chaos.social">@<span>icing</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> <br />Update from daniel<br /><a href="https://mastodon.social/@bagder/116407367327224765" rel="nofollow noopener"><span>https://</span><span>mastodon.social/@bagder/116407</span><span>367327224765</span></a></p>]]></description><link>https://forum.fedi.dk/post/https://mas.to/users/aliengasmask/statuses/116424891110634248</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mas.to/users/aliengasmask/statuses/116424891110634248</guid><dc:creator><![CDATA[aliengasmask@mas.to]]></dc:creator><pubDate>Sat, 18 Apr 2026 09:00:55 GMT</pubDate></item><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 08:28:13 GMT]]></title><description><![CDATA[<p><span><a href="/user/jfbucas%40mastodon.dias.ie">@<span>jfbucas</span></a></span> <span><a href="/user/mkoek%40mastodon.nl">@<span>mkoek</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> <span><a href="/user/bortzmeyer%40mastodon.gougere.fr">@<span>bortzmeyer</span></a></span> </p><p>The speed is enabled by skewing the economics. People can search for bugs using billions of investment at little cost.</p><p>Open Source has increased load due to this, but is not at risk. We do not guarantee any fitness for purpose.</p><p>Businesses, especially the ones not *always* running the latest version of software, are more exposed.</p><p>But we do not see an uptake of investment into project security from the commercial side.</p>]]></description><link>https://forum.fedi.dk/post/https://chaos.social/users/icing/statuses/116424762530923115</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://chaos.social/users/icing/statuses/116424762530923115</guid><dc:creator><![CDATA[icing@chaos.social]]></dc:creator><pubDate>Sat, 18 Apr 2026 08:28:13 GMT</pubDate></item><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 08:14:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/mkoek%40mastodon.nl">@<span>mkoek</span></a></span> <span><a href="/user/icing%40chaos.social">@<span>icing</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> <span><a href="/user/bortzmeyer%40mastodon.gougere.fr">@<span>bortzmeyer</span></a></span></p><p>Isn't the fundamental difference the speed of discovering new issues, mixing highlevel knowledge from various parts of the stack?</p><p>It's going to be a bit hairy for the next months/years while everybody cope on?</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.dias.ie/users/jfbucas/statuses/116424708650620553</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.dias.ie/users/jfbucas/statuses/116424708650620553</guid><dc:creator><![CDATA[jfbucas@mastodon.dias.ie]]></dc:creator><pubDate>Sat, 18 Apr 2026 08:14:30 GMT</pubDate></item><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 07:39:23 GMT]]></title><description><![CDATA[<p><span><a href="/user/icing%40chaos.social">@<span>icing</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> <a href="https://thenewstack.io/curls-daniel-stenberg-ai-is-ddosing-open-source-and-fixing-its-bugs/" rel="nofollow noopener"><span>https://</span><span>thenewstack.io/curls-daniel-st</span><span>enberg-ai-is-ddosing-open-source-and-fixing-its-bugs/</span></a> I found this <img src="https://forum.fedi.dk/assets/plugins/nodebb-plugin-emoji/emoji/android/1f914.png?v=94543ec6bc6" class="not-responsive emoji emoji-android emoji--thinking_face" style="height:23px;width:auto;vertical-align:middle" title="🤔" alt="🤔" /></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/connynasch/statuses/116424570509084898</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/connynasch/statuses/116424570509084898</guid><dc:creator><![CDATA[connynasch@mastodon.social]]></dc:creator><pubDate>Sat, 18 Apr 2026 07:39:23 GMT</pubDate></item><item><title><![CDATA[Reply to AIs have been finding bugs and vulnerabilities in #curl for some time. on Sat, 18 Apr 2026 07:18:48 GMT]]></title><description><![CDATA[<p><span><a href="/user/icing%40chaos.social">@<span>icing</span></a></span> <span><a href="https://mastodon.social/@sovtechfund">@<span>sovtechfund</span></a></span> I’ve been in security almost 30 years and seen so many claims of “this will change the industry forever”. What’s remarkable to me is how constant it has been. We are still seeing basically the same issues as in 1999: bad passwords, missing updates, code injections, and, well, Microsoft. I may be getting blasé but I’m highly skeptical that this AI stuff is going to change anything fundamental about that. <span><a href="/user/bortzmeyer%40mastodon.gougere.fr">@<span>bortzmeyer</span></a></span></p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.nl/users/mkoek/statuses/116424489579609178</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.nl/users/mkoek/statuses/116424489579609178</guid><dc:creator><![CDATA[mkoek@mastodon.nl]]></dc:creator><pubDate>Sat, 18 Apr 2026 07:18:48 GMT</pubDate></item></channel></rss>