Skip to content
0
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
  • Home
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse

Wandering Adventure Party

daniel:// stenberg://B

bagder@mastodon.social

@bagder@mastodon.social
About
Posts
5
Topics
4
Shares
0
Groups
0
Followers
0
Following
0

View Original

Posts

Recent Best Controversial

  • #curl and its website feature no trackers, no cookies, no ads, no website analytics, no telemetry, no logs.
    daniel:// stenberg://B daniel:// stenberg://

    #curl and its website feature no trackers, no cookies, no ads, no website analytics, no telemetry, no logs. We truly don't know you and what you do with curl - unless you tell us in our annual survey.

    Uncategorized curl

  • CycloneDX cancels their bug-bounty program blaming AI slop:
    daniel:// stenberg://B daniel:// stenberg://

    CycloneDX cancels their bug-bounty program blaming AI slop:

    "This caused a lot of extra work which is why we decided to abandon the program. Thanks AI."

    https://github.com/CycloneDX/cyclonedx-rust-cargo/pull/786

    Uncategorized

  • "thank you for your existence" - I do get lovely emails as well in my #inbox
    daniel:// stenberg://B daniel:// stenberg://

    "thank you for your existence" - I do get lovely emails as well in my #inbox

    https://daniel.haxx.se/email/2025-05-20.html

    Uncategorized inbox

  • If you can trick a user to run a command tool in a way that ends up causing the user problems, that is not a security problem in that tool.
    daniel:// stenberg://B daniel:// stenberg://

    the latest incarnation of this is someone saying that curl can be used to download a ".curlrc" into your $HOME and then curl might do bad things in subsequent invokes.

    The first step is "just" to trick a user to run a curl command line doing the bad.

    ... if you can trick a user into running an arbitrary command, you can of course do so much more harm than just this.

    Uncategorized

  • If you can trick a user to run a command tool in a way that ends up causing the user problems, that is not a security problem in that tool.
    daniel:// stenberg://B daniel:// stenberg://

    If you can trick a user to run a command tool in a way that ends up causing the user problems, that is not a security problem in that tool.

    Just saying. In case you're thinking of submitting such a report about a command line tool in your toolbox.

    But surely no sane person would. Right? Right?

    Uncategorized
  • Login

  • Login or register to search.
Powered by NodeBB Contributors
  • First post
    Last post