pull down to refresh
FOSS devs these days
Just few PRs more honey and I am coming to bed...
reply
These days you wish you never gave your code to claude and kimi and gpt and all your other friends because you're raw from hitting that. Leave me alone, it hurts. Nothing else to do because the bots are doing it all. The reason those panties are down there is because it hurts too much to actually pull 'em up.
reply
it hurts too much to actually pull 'em up
LOLOLOL
reply
Besides k00b's remark above, which I agree with:
The biggest risk with these kinds of things: lagging projects get slapped with a public disclosure deadline in a timeline where they cannot deploy the fix. The reporter says "this is for the public good" and then half the users get rekt.
Additionally, when you receive an email from someone you don't really know and didn't hire, telling you that you have a vuln and it is critical, you're feeling like you're taken hostage. Especially when they've already told the world they're doing this, and possibly your users. Big PR stunts are no good for this because they add to the pressure. I've talked many a FOSS dev off the ledge in the past 10 years in such situations, or when the deadlines seem impossible to manage. It's extremely stressful.
What I worry most about: how the hell are you going to manage 300+ vuln reports you're the source of? Going to take a lot of patience already when you have 5 ongoing ones, this is 60x that. For the red team, these are business as usual. But for the other side it isn't. So I see this going wrong in many, many ways. Let's hope they are more experienced in managing vulns from the reporter side than I currently estimate.