Today we celebrate four years since Apple pulled the ghost CVE prank on us:

https://daniel.haxx.se/blog/2022/03/23/anatomy-of-a-ghost-cve/

#curl

Anatomy of a ghost CVE

"The Lord giveth and the Lord taketh away."Job 1:21 On March 16 2022, the curl security team received an email in which the reporter highlighted an Apple web page. What can you tell us about this? I hadn't seen it before. On this page with the title "About the security content of macOS Monterey 12.3", … Continue reading Anatomy of a ghost CVE β†’

daniel.haxx.se
@bagder Any guesses on how much time you and the team wasted for pretty much nothing?
How is the "productive work" vs. "chasing other people's mess for nothing" ratio in general?

@thoralf that's really hard to tell. Also, the "for nothing" depends on who you ask and how you determine it. Most chases like this actually contribute and add *something* to the project. Code, experience, documentation etc.

But since we don't try to measure or count this, I can't even guess!