frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Mythos Finds a Curl Vulnerability

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
58•TangerineDream•1h ago

Comments

ahofmann•37m ago
Putting on my tinfoil-hat: Sooo, the guy who runs the test and delivers the report could just have removed the more interesting bugs and delivered those to any three letter agency?
bilekas•34m ago
No, based on cURL's history, it really seems like they would love to have found a really novel bug. Now if it was a for profit company.. Tinfoil hat would be shared!
Ekaros•31m ago
Curl is likely one of the very much more combed over pieces of code at this point. It feels like it has some special draw for people looking for vulnerabilities. Not that it doesn't mean some novel idea can't be looked or checked still.
rzmmm•36m ago
Quote:

"My personal conclusion can however not end up with anything else than that the big hype around this model so far was primarily marketing. I see no evidence that this setup finds issues to any particular higher or more advanced degree than the other tools have done before Mythos. Maybe this model is a little bit better, but even if it is, it is not better to a degree that seems to make a significant dent in code analyzing."

It's a good reminder for us all that the competition in this space is rough and lots of more or less subtle marketing is involved.

greendude29•22m ago
I'd go out and say the marketing is not subtle. The hype and fanboys/girls are so in line with the marketing that any level of skepticism is seen a an act of defection, but if you look at the words, hyperbole and volume that is used, there is nothing subtle about it.

It's almost Trump-esque - "this model will change everything forever; we are doomed; we are saved; we will all be fired; we will all be rich", etc

xantronix•8m ago
That's a pretty good encapsulation of the parallels between the political and the technological: One necessarily thrives upon the other and are inextricable. This moment is a culmination of all the disenfranchisement the bodypolitik have suffered, looking for any possible means of escape or elevation. AI and Trumpism, for their own respective cohorts, are salvation, on offer by different frontmen but ultimately in service of the same system.

They need the hype to pay off way more than we do. So many of us who still write code directly stand to lose nothing of our capabilities if the marketing claims cannot hold water.

coldtea•6m ago
>It's a good reminder for us all that the competition in this space is rough and lots of more or less subtle marketing is involved.

About as subtle as a personal injury lawyer's billboard

te_chris•3m ago
A thankfully American reference
bilekas•35m ago
> The single confirmed vulnerability is going to end up a severity low CVE planned to get published in sync with our pending next curl release 8.21.0 in late June

My mind still cannot understand the quality and refinement that's gone into cURL. It really is the perfect example of something done so right, that people barely think twice about.

dotancohen•11m ago
Curl and SQLite are my favourite examples of properly engineered, rigourously tested _anything_. It's really philosophical - those projects' contribution requirements demand such rigor, and the maintainers stand by that demand. A non-load-bearing document (not project code) is what makes that possible - very reminiscent of Einstein's thought experiments leading to tangible projects such as GPS or Descartes's belief that all problems can be solved through rational thinking.
yjftsjthsd-h•35m ago
> The source code consists of 660,000 words, which is 12% more words than the entire English edition of the novel War and Piece.

Typo, or is there a spoof I should go read?

dotancohen•8m ago
Perhaps he was dictating.

Does it say anything else? Just 'Aaaarggghhhh'?

Hamuko•4m ago
Doubt it considering that Daniel Stenberg is Swedish. English dictation when you speak English as a second language with an accent is quite annoying.
yjftsjthsd-h•32m ago
> Not particularly “dangerous”

I'm not sure that follows. As noted, curl was already analyzed to death with every tool available; most software isn't at that level.

bilekas•29m ago
I don't think I understand what you mean, the "not particularly dangerous" comment was in relation to the vulnerability that was found right ? Surely they would know what constitutes a lower severity level.
Ekaros•27m ago
My guess is that it is in category of "you are holding it wrong". Still worth fixing, but requires very specific user input for example. Or very weird scenario. Or in some less used protocol or flag combination.
AntiUSAbah•22m ago
There is always marketing involved and people should be able to put marketing into perspective.

Also curl in this regard is a open source project, relativly small but critical, well known and used everywhere. Besides image libraries, tools like curl or sudo, su, passwd, etc. would also be my first try.

Mythos is still not known at all what it can do. What does it mean from cost and benchmark pov to have a 10 Trillion parameter model?

Nonetheless, the fact that LLMs got significant better in finding this, better than humans, started to happen half a year ago? so at one point we need to address the elefant in the room and state that today you need to do security scanning additional with LLMs. You need to take this serious.

In worst case, use Anthropics marketing to state that its a must now and something changed.

Sandbox Your Agents

https://philippkuhnhardt.de/blog/sandbox-your-agents/
1•Extasia785•49s ago•0 comments

ProgramBench (Meta) Repro: variance across runs and findings

https://nickcheng0921.github.io/2026/05/10/thoughts-on-programbench-part1.html
1•porterbaseball•4m ago•1 comments

Show HN: DialYourShot – interactive espresso parameter tool

https://dialyourshot.com/
3•pirotechnique•12m ago•0 comments

Show HN: Harper, a free ocean forecast for surfers

https://harper.surf/
1•fbenevides•13m ago•0 comments

Somewhere Nearby is Colossal Cave (2007)

https://dhq.digitalhumanities.org/vol/1/2/000009/000009.html
1•exvi•15m ago•0 comments

GitHub Copilot is deprecating Grok Code Fast 1

https://github.blog/changelog/2026-05-08-upcoming-deprecation-of-grok-code-fast-1/
1•whtsky•15m ago•0 comments

Apple Faces £3B UK Trial over iCloud Lock-In Claims

https://www.macrumors.com/2026/05/07/apple-icloud-lock-in-uk-lawsuit/
2•johneth•18m ago•0 comments

The Brand Age

https://www.paulgraham.com/brandage.html
1•KnuthIsGod•19m ago•0 comments

European Lisp Symposium 2026

https://european-lisp-symposium.org/2026/index.html
2•Igrom•20m ago•1 comments

Writers are fleeing the Substack Tax

https://www.theverge.com/tech/927294/substack-tax-ghost-beehiiv
3•articsputnik•21m ago•1 comments

UX Dark Patterns and Social Media Addiction

https://www.designorate.com/ux-dark-patterns-and-social-media-addiction/
1•rrm1977•23m ago•0 comments

Squatt.ing – The state of the .ing top level domain shortly after public release

https://blog.ioces.com/matt/posts/squatt.ing/
1•shoobs•24m ago•0 comments

Modi urges Indians to WFH and limit foreign travel as Iran war continues

https://www.bbc.com/news/articles/c8r8e2ne1v6o
1•penguin_booze•28m ago•0 comments

Young evil genius forces hamster to run on wheel to power his gadgets

https://www.theregister.com/offbeat/2026/05/06/youtuber-turns-hamster-wheel-into-phone-charger/52...
1•luckys•30m ago•0 comments

Show HN: Built a tool that analyzes product reviews and shows real pros/cons

https://chromewebstore.google.com/detail/astrea/ddlhfimgdflliapbjpfaeoheahhmgikl
1•adrianrogers04•31m ago•0 comments

A Tour of Txtar

https://rednafi.com/go/txtar/
1•ingve•35m ago•0 comments

Connections – James Burke

https://www.youtube.com/playlist?list=PLf02uWXhaGRng_YzH-Ser_VEV4lGSLX_1
1•gurjeet•36m ago•0 comments

Encouraging Autonomous Driving Companies to Share Safety-Critical Data

https://dl.acm.org/doi/pdf/10.1145/3757493
3•luu•36m ago•0 comments

Toward Worker-Owned Delivery Platforms with the OpenCourier Protocol

https://platform.coop/blog/toward-worker-owned-delivery-platforms-with-the-opencourier-protocol/
1•utopiah•36m ago•1 comments

Detachment 201, the US Army unit led by tech executives

https://english.elpais.com/technology/2026-04-13/detachment-201-the-us-army-unit-led-by-tech-exec...
2•BaudouinVH•36m ago•0 comments

Why is AI trust so much higher in China (87%) than the US (32%)? [pdf]

https://www.edelman.com/sites/g/files/aatuss191/files/2025-11/2025%20Edelman%20Trust%20Barometer%...
2•nilen•38m ago•3 comments

Bashism – Greg's Wiki

https://mywiki.wooledge.org/Bashism
2•dr_girlfriend•42m ago•0 comments

Gmail registration now requires scanning a QR code and sending a text message

https://discuss.privacyguides.net/t/google-account-registration-now-requires-sending-an-sms-via-p...
3•negura•43m ago•1 comments

Bring Kindness Back to Open Source

https://www.hanselman.com/blog/bring-kindness-back-to-open-source
2•mashally•43m ago•1 comments

Ask HN: What is your workflow for filtering academic papers?

1•hydra-f•43m ago•0 comments

Bash Pitfalls - Greg's Wiki

https://mywiki.wooledge.org/BashPitfalls
2•dr_girlfriend•44m ago•0 comments

ASTro: AST-Based Reusable Optimization Framework

https://github.com/ko1/astro/
1•riffraff•44m ago•0 comments

BashFAQ - Greg's Wiki

https://mywiki.wooledge.org/BashFAQ
2•dr_girlfriend•45m ago•0 comments

AI native flights search built in a weekend

https://flightzombie.com
1•mk0y•46m ago•0 comments

Roaring Bitmaps

https://roaringbitmap.org/
2•tosh•48m ago•0 comments