Daniel   StenbergVerified account

@bagder

I do network code and protocols. I write curl. On team . I don't know anything.

Stockholm Sweden
Joined May 2008

Tweets

You blocked @bagder

Are you sure you want to view these Tweets? Viewing Tweets won't unblock @bagder

  1. Pinned Tweet
    Apr 7

    Whenever you or your team get stuck on a curl problem, help is just a support deal away: - I could literally be helping you with your issue within 24 hours.

    Undo
  2. Daniel’s weekly report May 13, 2022 release, trailing dots, curl up, hosting, past vulns

    Undo
  3. curl is 24 years old, runs in some 10 billions installations world and now has a fair amount of sponsors. I'm proposing I no longer have to pay with my own money for the server and instead spend some of our fund on it:

    Undo
  4. Bug bounty payouts in the curl project. Over time and per CVE. In total almost 35,000 USD. Recent average over 2,000 USD per issue.

    Show this thread
    Undo
  5. The Internet Bug Bounty has now paid more than 17,000 USD in reward money on the curl project's behalf. Thank you IBB sponsors!

    Show this thread
    Undo
  6. If you too want to write yourself a new minivan: 5 of the recent curl CVEs get 2,400 USD each in bounty rewards. Thank you awesome people!

    Show this thread
    Undo
  7. Happy to say we have a few official curl up 2022 sponsors now. And we're working on more content. June 6, in San Francisco: Also looking for more speakers so don't be shy!

    Undo
  8. May 12
    Undo
  9. May 12
    Undo
  10. May 12

    Answer: Why does curl send a Proxy-Connection header, even though the RFC seems to discourage it?

    Undo
  11. May 12

    I could add that we don't pre-notify the commercial operating systems. Because: Apple mostly yell at me for not giving them eons of time when I do and Microsoft doesn't provide a method for me to do so.

    Undo
  12. May 12

    The reports behind these issues are now trickling out and are made public one by one: - for some insights on how we worked on the issues before the release.

    Show this thread
    Undo
  13. May 11

    A tale of a trailing dot - how allowing a dot lead to two curl security vulnerabilities - and more. Did I tell you trailing dots are evil?

    Undo
  14. May 11

    in simple English: non-C mistake vulnerabilities in curl, remain in the code 24% longer until found than the vulnerabilities caused by C mistakes. On average.

    Show this thread
    Undo
  15. May 11

    that's 6.8 years vs 8.5 years

    Show this thread
    Undo
  16. May 11

    All vulnerabilities live a very long time until fixed in curl. On average, the non-C mistakes seem to live around ~600 days longer than the C mistakes, but the C mistake average age is still >2,500 days (vs 3178 for non-C mistakes). The graph is a little rough.

    Show this thread
    Undo
  17. May 11

    I'll make a separate run and see if there's a difference in time: how long mistakes remain in the code, C mistakes vs non-C mistakes until detected. One theory says that C mistakes are easier to find with tools.

    Show this thread
    Undo
  18. May 11

    At no point time was the share of security flaws existing in curl caused by "C mistakes" larger than the amount of vulnerabilities caused by other mistakes. (per date of when the flaw was first shipped in a release). One project. 121 flaws. Not much to draw conclusions from.

    Show this thread
    Undo
  19. May 11
    Replying to

    curl official container image curlimages/curl:7.83.1 has been released ... give it a spin> docker run -it curlimages/curl:7.83.1

    Undo
  20. May 11

    The curl 7.83.1 release presentation video

    Undo
  21. May 11

    The curl 7.83.1 release presentation live-stream starts now at

    Undo

Loading seems to be taking a while.

Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.

    You may also like

    ·