The part where he gets contacted over the hit-and-run reads like the curl guy’s experience with people investigating “hacking”.
I wonder how often this happens outside of software? Do fence manufacturers get emails asking to identify the culprit when someone crashes through a fence?
I feel like it's a "cast a wide net" type of strategy. Doesn't really hurt to ask and there _could_ be the tiniest hint that could lead to something. Maybe?
Rings a bell, I think it was because Curl showed up as the user agent for malicious activity.
You have to be kind of lost to contact Daniel about it, but I think it's ok behaviour for junior sysadmins that are just starting out, everyone was starting out sometime, and curl is like a lightning catcher for the world's daily lucky thousand.
Actually, it wasn't unreasonable. If the guy caused the damage while picking up a sonde, to know who's sonde it was would help identify the culprit.