Marking them as spam now. #curl #hackerone (AI slop as "security vulnerability reports")

"This experience has unfortunately made me reconsider my support for curl"

I'm sorry you feel that way, but you need to realize your own role here. We receive AI slop like this regularly and at volume. You contribute to unnecessary load of curl maintainers and I refuse to take that lightly and I am determined to act swiftly against it. Now and going forward.

(cont)

You submitted what seems to be an obvious AI slop "report" where you say there is a security problem, probably because an AI tricked you into believing this. You then waste our time by not telling us that an AI did this for you and you then continue the discussion with even more crap responses - seemingly also generated by AI.

(cont)

By all means, use AI to learn things and to figure out potential problems, but when you just blindly assume that a silly tool is automatically right just because it sounds plausible, then you're doing us all (the curl project, the world, the open source community) a huge disservice. You should have studied the claim and verified it before you reported it. You should have told us an AI reported this to you.

(cont)

What tells me this is AI slop;

1. The wall of text that is too long and unspecific, talking about a potential problem

2. The over-politeness when asked to clarify and provide more info. Humans rarely speak like that.

3. The inability to become specific when asked. It can't point out the flaw exactly, because it does not actually know about any flaw.

(cont)

I'm sorry you feel less enthusiastic about curl now because of this. I hope you after some time in a future will come to reassess what happened here and maybe even understand why we act the way we do.

Now, let's go back to improving curl.

Thanks

@bagder

Certainly a more thorough and thoughtful reply than was deserved.

Keep up the excellent work Daniel. Enthusiastic kudos to all the #curl maintainers.