logoalt Hacker News

bilekastoday at 7:35 AM3 repliesview on HN

[flagged]


Replies

AnssiHtoday at 8:50 AM

The test was run by an unnamed third party, so cURL's history has no relevance to their benevolence.

Ekarostoday at 7:38 AM

Curl is likely one of the very much more combed over pieces of code at this point. It feels like it has some special draw for people looking for vulnerabilities. Not that it doesn't mean some novel idea can't be looked or checked still.

cakealerttoday at 8:09 AM

> No, based on cURL's history, it really seems like they would love to have found a really novel bug.

You just confirmed that you didn't read the article.

"Eventually, I was instead offered that someone else, who has access to the model, could run a scan and analysis on curl for me using Mythos and send me a report."

show 1 reply