cURL 關閉漏洞賞金計畫,以遏止 AI 生成的提交內容

cURL 關閉漏洞賞金計畫,以遏止 AI 生成的提交內容

Hacker News·

廣受歡迎的開源資料傳輸工具 cURL 的維護者已決定終止其漏洞賞金計畫。此舉旨在消除提交低品質、由 AI 生成的漏洞報告的誘因,這些報告已成為沉重的負擔。

Image

Image

Image

Image

Image

Topics

Security

Off-Prem

On-Prem

Software

Offbeat

Special Features

Vendor Voice

Vendor Voice

Resources

Image

Curl shutters bug bounty program to remove incentive for submitting AI slop

Image

Maintainer hopes hackers send bug reports anyway, will keep shaming ‘silly' ones

Image

Image

The maintainer of popular open-source data transfer tool cURL has ended the project’s bug bounty program after maintainers struggled to assess a flood of AI-generated contributions.

Curler-in-chief Daniel Stenberg last week lodged a GitHub commit named “BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026”.

Readers may recall that Stenberg started complaining about AI-generated bug reports in early 2024, and by mid-2025 contemplated killing the project’s bug bounty program. After receiving some strong bug reports that a developer found with help from AI, Stenberg acknowledged that AI can be a fine bug-hunting aid.

Stenberg addressed his decision in a mailing message that opened with news that last week the project’s bug bounty scheme generated seven submissions and that while some identified bugs, none described a vulnerability.

Figuring that out took “a good while.”

He then expressed his hope that ending the bug bounty program will “remove the incentive for people to submit crap and non-well researched reports to us. AI generated or not.”

“The current torrent of submissions put a high load on the curl security team and this is an attempt to reduce the noise.”

Stenberg’s post also expresses his hope that developers continue to send reports of “actual security vulnerabilities … even if we do not pay for them.”

“The future will tell,” he added, and perhaps reveal not just whether developers will share bug reports, but also if they are willing to risk public criticism if their submissions don’t meet Stenberg’s standards.

Stenberg explained his stance in a section of the post that considers his policy of publicly shaming those who submit “silly AI-generated submissions” to the bounty program.

In that section, he reveals a recent discussion with one of the people he criticized.

“It was useful for me to make me remember that oftentimes these people are just ordinary misled humans and they might actually learn from this and perhaps even change,” he wrote.

But Stenberg reserved the right to rage in public.

“This is a balance of course, but I also continue to believe that exposing, discussing and ridiculing the ones who waste our time is one of the better ways to get the message through: you should NEVER report a bug or a vulnerability unless you actually understand it – and can reproduce it.”

“If you still do, I believe I am in the right to make fun of – and be angry at – the person doing it,” he added, before conceding that he also needs to restrain himself on some occasions.

“The person might be a teenage kid who did a single one-time mistake and will then move on in life and make excellent stuff in the future,” he wrote. ®

Image

More about

Narrower topics

Broader topics

Image

Image

More about

Narrower topics

Broader topics

Send us news

Other stories you might like

The Register Biting the hand that feeds IT

Image

Image

Image

Image

Image

Copyright. All rights reserved © 1998–2025

Hacker News

相關文章

  1. 因AI生成內容氾濫,cURL終止漏洞懸賞計畫

    3 個月前

  2. 因充斥AI生成垃圾報告,cURL取消漏洞獎勵計畫以確保「心理健康」

    3 個月前

  3. cURL專案因AI生成「垃圾報告」而取消漏洞賞金計畫

    3 個月前

  4. cURL 因 AI 生成的垃圾報告氾濫而終止漏洞賞金計畫

    3 個月前

  5. Curl 因湧入大量 AI 生成的垃圾報告而終止漏洞賞金計畫

    3 個月前