Overrun with AI slop, cURL scraps bug bounties to make sure “intact psychological well being”

The mission developer for one of many Web’s hottest networking instruments is scrapping its vulnerability reward program after being overrun by a spike within the submission of low-quality studies, a lot of it AI-generated slop.
“We’re only a small single open supply mission with a small variety of lively maintainers,” Daniel Stenberg, the founder and lead developer of the open supply app cURL, mentioned Thursday. “It’s not in our energy to vary how all these individuals and their slop machines work. We have to make strikes to make sure our survival and intact psychological well being.”
Manufacturing bogus bugs
His feedback got here as cURL customers complained that the transfer was treating the signs attributable to AI slop with out addressing the trigger. The customers mentioned they have been involved the transfer would get rid of a key means for guaranteeing and sustaining the safety of the device. Stenberg largely agreed, however indicated his staff had little selection.
In a separate put up on Thursday, Stenberg wrote: “We are going to ban you and mock you in public for those who waste our time on crap studies.” An replace to cURL’s official GitHub account made the termination, which takes impact on the finish of this month, official.
cURL was first launched three many years in the past, beneath the title httpget and later urlget. It has since change into an indispensable device amongst admins, researchers, and safety professionals, amongst others, for a variety of duties, together with file transfers, troubleshooting buggy net software program, and automating duties. cURL is built-in into default variations of Home windows, macOS, and most distributions of Linux.
As such a extensively used device for interacting with huge quantities of knowledge on-line, safety is paramount. Like many different software program makers, cURL mission members have relied on non-public bug studies submitted by outdoors researchers. To supply an incentive and to reward high-quality submissions, the mission members have paid money bounties in return for studies of high-severity vulnerabilities.
