logoalt Hacker News

bluGilltoday at 2:44 PM3 repliesview on HN

OpenAI and Anthropic have both been studying CURL for a while though. Anything they found was already fixed.

If you want to compare you need to start with something that none of studied. Somebody please take the source to a 2023 release of CURL (It shouldn't be hard to find one) - before all the current AI craze, and run all the tools on them to see what they find. Only then can we compare numbers. (and even then severity may come into place - all 6 are rated low impact)


Replies

goobreeetoday at 3:06 PM

I think you might be misunderstanding this? This is, from my understanding, what went down:

1. curl was scanned by many different things, including AISLE, and many bugs were fixed <- all this was in the past 2. curl a week ago was scanned again my Mythos and Codex Security, and both of them said: 0 issues found 3. the same curl was scanned by AISLE a day later, resulting in ~29 reports (based on the blog post and mastodon posts from Daniel Stenberg) 4. of these 29, 6 cleared the bar and got CVEs in curl 5. these 6 CVEs were just announced as fixed in curl 8.22.0 today, together with 4 more CVEs that were detected by other people prior to point 2. of this list

so imho it was head-to-head, the very same codebase => it's a legit comparison

zamadatixtoday at 3:04 PM

"How many total vulnerabilities can your tool alone identify?" and "How many unique vulnerabilities can your tool identify?" are both valid comparisons to make IMO.

thih9today at 2:58 PM

I guess this would also require models trained on pre-2023 data - or not trained on later curl code, changelogs, blog posts discussing curl security fixes, etc.

show 1 reply