Skip to content
0
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Sketchy)
  • No Skin
Collapse

Wandering Adventure Party

  1. Home
  2. Uncategorized
  3. Log4j, *the* project that escalated the need for funding open source in the first place, is currently being DOS’d by slop vulnerability reports.

Log4j, *the* project that escalated the need for funding open source in the first place, is currently being DOS’d by slop vulnerability reports.

Scheduled Pinned Locked Moved Uncategorized
8 Posts 4 Posters 1 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Jan Lehnardt :couchdb:J This user is from outside of this forum
    Jan Lehnardt :couchdb:J This user is from outside of this forum
    Jan Lehnardt :couchdb:
    wrote last edited by
    #1

    Log4j, *the* project that escalated the need for funding open source in the first place, is currently being DOS’d by slop vulnerability reports. Well done everyone. Slow fucking clap.

    Link Preview Image
    Addressing AI-slop in security reports · apache/logging-log4j2 · Discussion #4052

    Addressing AI-slop in security reports

    favicon

    GitHub (github.com)

    degenerating degenerateH Rihards OlupsR 2 Replies Last reply
    1
    0
    • Jan Lehnardt :couchdb:J Jan Lehnardt :couchdb:

      Log4j, *the* project that escalated the need for funding open source in the first place, is currently being DOS’d by slop vulnerability reports. Well done everyone. Slow fucking clap.

      Link Preview Image
      Addressing AI-slop in security reports · apache/logging-log4j2 · Discussion #4052

      Addressing AI-slop in security reports

      favicon

      GitHub (github.com)

      degenerating degenerateH This user is from outside of this forum
      degenerating degenerateH This user is from outside of this forum
      degenerating degenerate
      wrote last edited by
      #2

      @janl Maintainer saying they'll pay for bugs... attracts people looking for a low-effort income stream.

      This is a problem that doesn't exist if you don't incentivize it...

      Jan Lehnardt :couchdb:J 1 Reply Last reply
      0
      • degenerating degenerateH degenerating degenerate

        @janl Maintainer saying they'll pay for bugs... attracts people looking for a low-effort income stream.

        This is a problem that doesn't exist if you don't incentivize it...

        Jan Lehnardt :couchdb:J This user is from outside of this forum
        Jan Lehnardt :couchdb:J This user is from outside of this forum
        Jan Lehnardt :couchdb:
        wrote last edited by
        #3

        @hopeless yes it’s their own fault. Really. Jfc.

        degenerating degenerateH 1 Reply Last reply
        0
        • Jan Lehnardt :couchdb:J Jan Lehnardt :couchdb:

          @hopeless yes it’s their own fault. Really. Jfc.

          degenerating degenerateH This user is from outside of this forum
          degenerating degenerateH This user is from outside of this forum
          degenerating degenerate
          wrote last edited by
          #4

          @janl Do you maintain anything?

          Jan Lehnardt :couchdb:J 1 Reply Last reply
          0
          • degenerating degenerateH degenerating degenerate

            @janl Do you maintain anything?

            Jan Lehnardt :couchdb:J This user is from outside of this forum
            Jan Lehnardt :couchdb:J This user is from outside of this forum
            Jan Lehnardt :couchdb:
            wrote last edited by
            #5

            @hopeless yup, dozens of projects some of which with millions of deploys, including an ASF Top Level project.

            degenerating degenerateH 1 Reply Last reply
            0
            • Jan Lehnardt :couchdb:J Jan Lehnardt :couchdb:

              @hopeless yup, dozens of projects some of which with millions of deploys, including an ASF Top Level project.

              degenerating degenerateH This user is from outside of this forum
              degenerating degenerateH This user is from outside of this forum
              degenerating degenerate
              wrote last edited by
              #6

              @janl I also maintain a FOSS project that's in AOSP, all the distros, and used by FAANG with multi-million deploys.

              I don't pay any bounty, mainly because I don't have any money, and the huge companies that ship it, do their own Static Analysis.

              I have been approached - by someone with a .bg email domain - asking about bounties, if I had said "yes", I also would be wading through the slop. So when I tell you this is self-inflicted by the maintainer, I have good reason to say it.

              kalipso (24723)K 1 Reply Last reply
              1
              • Jan Lehnardt :couchdb:J Jan Lehnardt :couchdb:

                Log4j, *the* project that escalated the need for funding open source in the first place, is currently being DOS’d by slop vulnerability reports. Well done everyone. Slow fucking clap.

                Link Preview Image
                Addressing AI-slop in security reports · apache/logging-log4j2 · Discussion #4052

                Addressing AI-slop in security reports

                favicon

                GitHub (github.com)

                Rihards OlupsR This user is from outside of this forum
                Rihards OlupsR This user is from outside of this forum
                Rihards Olups
                wrote last edited by
                #7

                @janl I propose a slop-slap reflex theory.
                It basically states that developing a quick reaction to "slap" whenever "slop" is observed is crucial for many projects.

                Or:

                Developing a reflex of slop-slap is self-defence.

                1 Reply Last reply
                0
                • degenerating degenerateH degenerating degenerate

                  @janl I also maintain a FOSS project that's in AOSP, all the distros, and used by FAANG with multi-million deploys.

                  I don't pay any bounty, mainly because I don't have any money, and the huge companies that ship it, do their own Static Analysis.

                  I have been approached - by someone with a .bg email domain - asking about bounties, if I had said "yes", I also would be wading through the slop. So when I tell you this is self-inflicted by the maintainer, I have good reason to say it.

                  kalipso (24723)K This user is from outside of this forum
                  kalipso (24723)K This user is from outside of this forum
                  kalipso (24723)
                  wrote last edited by
                  #8

                  @hopeless @janl okay i also maintain stuff by fang, bang and shang and still think its doesnt make sense to blame the dev here - now what?

                  1 Reply Last reply
                  0
                  • Pteryx the Puzzle SecretaryP Pteryx the Puzzle Secretary shared this topic

                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  Powered by NodeBB Contributors
                  • First post
                    Last post