Asriel's Avatar

Asriel

@asriel.camora.dev

I have the power of god and anime on my side I code stuff, currently mostly ffxiv πŸ‡ \\ she/her \\ 20 \\ πŸ³οΈβ€βš§οΈ \\ ♀️♀️ Mastodon: @mstdn.camora.dev

92
Followers
107
Following
13
Posts
02.01.2025
Joined
Posts Following

Latest posts by Asriel @asriel.camora.dev

Post image

Windows 14 rumored to have a free trial with no limit on playtime all the way up to level 70, including the award winning expansions "Heavensward" and "Stormblood," sources say.

05.03.2026 16:03 πŸ‘ 6327 πŸ” 2396 πŸ’¬ 60 πŸ“Œ 17
04.03.2026 17:12 πŸ‘ 945 πŸ” 191 πŸ’¬ 7 πŸ“Œ 1
Post image
05.03.2026 04:41 πŸ‘ 106 πŸ” 11 πŸ’¬ 2 πŸ“Œ 0
Post image

ai is the future

03.03.2026 01:37 πŸ‘ 78 πŸ” 6 πŸ’¬ 2 πŸ“Œ 0
02.03.2026 15:29 πŸ‘ 141 πŸ” 40 πŸ’¬ 3 πŸ“Œ 0

>look up rust crate
>need to evaluate if it's any good
>see author is a transgender furry
>cargo add

01.03.2026 14:46 πŸ‘ 157 πŸ” 19 πŸ’¬ 1 πŸ“Œ 0

the worlds not over
keep taking your meds
keep taking your HRT
keep scheduling surgeries
keep talking to friends
keep eating
keep sleeping
the worlds not over
you're still needed

28.02.2026 15:28 πŸ‘ 3452 πŸ” 1809 πŸ’¬ 23 πŸ“Œ 18
Post image

DAY 790 - Nebula bunny

27.02.2026 22:09 πŸ‘ 1059 πŸ” 167 πŸ’¬ 7 πŸ“Œ 1
*elementary school teacher calling roll in 2037*

teacher: "naruto"
"here"
teacher: "pepe"
"here"
teacher: "jeff"
"here"
teacher: "jeff"
"here"
teacher: "jeff"
"here"
teacher: "beter"
"its pronounced πŸ…±οΈeter"

*elementary school teacher calling roll in 2037* teacher: "naruto" "here" teacher: "pepe" "here" teacher: "jeff" "here" teacher: "jeff" "here" teacher: "jeff" "here" teacher: "beter" "its pronounced πŸ…±οΈeter"

28.02.2026 10:26 πŸ‘ 122 πŸ” 27 πŸ’¬ 0 πŸ“Œ 0
Post image

text me when you get home

27.02.2026 20:48 πŸ‘ 8907 πŸ” 1665 πŸ’¬ 40 πŸ“Œ 5
Post image

Duo CampingπŸ’œπŸ’™

23.02.2026 18:19 πŸ‘ 2792 πŸ” 808 πŸ’¬ 15 πŸ“Œ 2
Bandcamp download page with the following formats:

MP3 V0 - 64.7MB
MP3 320 - 76.8MB
FLAC - 341.8MB
Ogg Vorbis - 49.8MB
Ogg Morbus - 2B
MQA - 346.3MB
MIDI - 52.2MB
DivX - 862MB
Unreal Engine Pak - 346.3MB
unitypackage - 201.2MB
KEVIN - 456.3MB
Game Boyβ„’ Advance - 14 cartridges

Bandcamp download page with the following formats: MP3 V0 - 64.7MB MP3 320 - 76.8MB FLAC - 341.8MB Ogg Vorbis - 49.8MB Ogg Morbus - 2B MQA - 346.3MB MIDI - 52.2MB DivX - 862MB Unreal Engine Pak - 346.3MB unitypackage - 201.2MB KEVIN - 456.3MB Game Boyβ„’ Advance - 14 cartridges

can someone tell me what format is best to download in?

22.02.2026 19:16 πŸ‘ 124 πŸ” 27 πŸ’¬ 16 πŸ“Œ 0
Post image
19.02.2026 20:10 πŸ‘ 434 πŸ” 260 πŸ’¬ 5 πŸ“Œ 6
Kit cat with bite marks through 3 fingers

Kit cat with bite marks through 3 fingers

Straight up don’t give a shit anymore

14.02.2026 17:25 πŸ‘ 2082 πŸ” 200 πŸ’¬ 117 πŸ“Œ 54
Preview
The evolution of OpenAI’s mission statement As a USA 501(c)(3) the OpenAI non-profit has to file a tax return each year with the IRS. One of the required fields on that tax return is to β€œBriefly …

I had some fun pulling OpenAI's mission statement out of their IRS tax filings from 2016 to 2024, loading them into a git repo with fake commit dates and then taking a look at the diffs simonwillison.net/2026/Feb/13/...

13.02.2026 23:40 πŸ‘ 240 πŸ” 45 πŸ’¬ 7 πŸ“Œ 2
a classic forum interface for bluesky

a classic forum interface for bluesky

a classic forum interface for hacker news

a classic forum interface for hacker news

a classic forum interface for the new york times

a classic forum interface for the new york times

coding assistance lets you fast-track important projects that improve your life, such as reformatting every single site you read into the old vbulletin 3.x default template

10.02.2026 14:05 πŸ‘ 728 πŸ” 125 πŸ’¬ 21 πŸ“Œ 34

defence contractor ran by dog girls call that raytherian

07.02.2026 18:33 πŸ‘ 20 πŸ” 4 πŸ’¬ 0 πŸ“Œ 0
meme with the text: "repost this if trans people should have free 40 piece any type of wings" with artwork at the bottom showing trans people with chicken wings

meme with the text: "repost this if trans people should have free 40 piece any type of wings" with artwork at the bottom showing trans people with chicken wings

08.02.2026 03:43 πŸ‘ 1564 πŸ” 858 πŸ’¬ 11 πŸ“Œ 20
speech bubble from weird dog on a high containing a reddit post on r/Physics saying "What to do if i have theories? I contacted a college and they ignored me"

speech bubble from weird dog on a high containing a reddit post on r/Physics saying "What to do if i have theories? I contacted a college and they ignored me"

29.01.2026 21:59 πŸ‘ 359 πŸ” 54 πŸ’¬ 0 πŸ“Œ 1
glowing fed

glowing fed

"yeah i'm a cybersecurity expert. signal isn't safe don't use it. privacy isn't even actually real at all, the governmemt has an orb that shows them what you're doing at all times. anyway just use discord or email or something normal."

27.01.2026 03:19 πŸ‘ 1674 πŸ” 253 πŸ’¬ 27 πŸ“Œ 5

me: hold on to this thing for me please
github actions cache: no problem boss. i've got it
me: you got it?
github actions cache: i successfully confirm i do not got it
github actions cache: hey all your builds failed
github actions cache: also you're a terrible human

27.01.2026 16:40 πŸ‘ 97 πŸ” 13 πŸ’¬ 6 πŸ“Œ 1
Preview
The end of the curl bug-bounty tldr: an attempt to reduce the _terror reporting_. **There is no longer a curl bug-bounty program.** It officially stops on January 31, 2026. After having had a few half-baked previous takes, in April 2019 we kicked off the first real curl bug-bounty with the help of Hackerone, and while it stumbled a bit at first it has been quite successful I think. We attracted skilled researchers who reported plenty of actual vulnerabilities for which we paid fine monetary rewards. We have certainly made curl better as a direct result of this: **87 confirmed vulnerabilities and over 100,000 USD** paid as rewards to researchers. I’m quite happy and proud of this accomplishment. I would like to especially highlight the awesome Internet Bug Bounty project, which has paid the bounties for us for many years. We could not have done this without them. Also of course Hackerone, who has graciously hosted us and been our partner through these years. Thanks! ## How we got here Looking back, I think we can say that the downfall of the bug-bounty program started slowly in the second half of 2024 but accelerated badly in 2025. We saw an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop – presumably because they too were actually misled by AI but with that fact just hidden better. Maybe the first five years made it possible for researchers to find and report the low hanging fruit. Previous years we have had a rate of somewhere north of 15% of the submissions ending up confirmed vulnerabilities. Starting 2025, the confirmed-rate plummeted to below 5%. Not even one in twenty was _real_. The never-ending slop submissions take a serious mental toll to manage and sometimes also a long time to debunk. Time and energy that is completely wasted while also hampering our will to live. I have also started to get the feeling that a lot of the security reporters submit reports with a _bad faith attitude._ These β€œhelpers” try too hard to twist whatever they find into something horribly bad and a critical vulnerability, but they rarely actively contribute to actually _improve_ curl. They can go to extreme efforts to argue and insist on their specific current finding, but not to write a fix or work with the team on improving curl long-term etc. I don’t think we need more of that. There are these three bad trends combined that makes us take this step: the mind-numbing AI slop, humans doing worse than ever and the apparent will to poke holes rather than to help. ## Actions In an attempt to do something about the sorry state of curl security reports, this is what we do: * We no longer offer any monetary rewards for security reports – no matter which severity. In an attempt to remove the incentives for submitting made up lies. * We stop using Hackerone as the recommended channel to report security problems. To make the change immediately obvious and because without a bug-bounty program we don’t need it. * We refer everyone to submit suspected curl security problems on GitHub using their _Private vulnerability reporting_ feature. * We continue to immediately _ban and publicly_ _ridicule_ everyone who submits AI slop to the project. ## Maintain curl security We believe that we can maintain and continue to evolve curl security in spite of this change. Maybe even improve thanks to this, as hopefully this step helps prevent more people pouring sand into the machine. Ideally we reduce the amount of wasted time and effort. I believe the best and our most valued security reporters still will tell us when they find security vulnerabilities. ## Instead If you suspect a security problem in curl going forward, we advise you to head over to GitHub and submit them there. Alternatively, you send an email with the full report to `security @ curl.se`. In both cases, the report is received and handled privately by the curl security team. But with _no monetary reward offered_. ## Leaving Hackerone Hackerone was good to us and they have graciously allowed us to run our program on their platform for free for many years. We thank them for that service. As we now drop the rewards, we feel it makes a clear cut and displays a clearer message to everyone involved by also moving away from Hackerone as a platform for vulnerability reporting. It makes the change more visible. ## Future disclosures It is probably going to be harder for us to publicly disclose every incoming security report in the same way we have done it on Hackerone for the last year. We need to work out something to make sure that we can keep doing it at least imperfectly, because I believe in the goodness of such transparency. ## We stay on GitHub Let me emphasize that this change does not impact our presence and mode of operation with the curl repository and its hosting on GitHub. We hear about projects having problems with low-quality AI slop submissions on GitHub as well, in the form of issues and pull-requests, but for curl we have not (yet) seen this – and frankly I don’t think switching to a GitHub alternative saves us from that. ## Other projects do better Compared to others, we seem to be affected by the sloppy security reports to a higher degree than the average Open Source project. With the help of Hackerone, we got numbers of how the curl bug-bounty has compared with other programs over the last year. It turns out curl’s program has seen more volume and noise than other public open source bug bounty programs in the same cohort. Over the past four quarters, curl’s inbound report volume has risen sharply, while other bounty-paying open source programs in the cohort, such as Ruby, Node, and Rails, have not seen a meaningful increase and have remained mostly flat or declined slightly. In the chart, the pink line represents curl’s report volume, and the gray line reflects the broader cohort. Inbound Report Volume on Hackerone: curl compared to OSS peers We suspect the idea of getting money for it is a big part of the explanation. It brings in real reports, but makes it too easy to be annoying with little to no penalty to the user. The reputation system and available program settings were not sufficient for us to prevent sand from getting into the machine. The exact reason why we suffer more of this abuse than others remains a subject for further speculation and research. ## If the volume keeps up There is a non-zero risk that our guesses are wrong and that the volume and security report frequency will keep up even after these changes go into effect. If that happens, we will deal with it then and take further appropriate steps. I prefer not to overdo things or _overplan_ already now for something that ideally does not happen. ## We won’t charge People keep suggesting that one way to deal with the report tsunami is to _charge_ security researchers a small amount of money for the privilege of submitting a vulnerability report to us. A _curl reporters security club_ with an entrance fee. I think that is a less good solution than just dropping the bounty. Some of the reasons include: * Charging people money in an International context is complicated and a maintenance burden. * Dealing with charge-backs, returns and other complaints and friction add work. * It would limit who could or would submit issues. Even some who actually find legitimate issues. Maybe we need to do this later anyway, but we stay away from it for now. ## Pull requests are less of a problem We have seen other projects and repositories see similar AI-induced problems for pull requests, but this has not been a problem for the curl project. I believe for PRs we have better much means to sort out the weed with automatic means, since we have tools, tests and scanners to verify such contributions. We don’t need to waste any human time on pull requests until the quality is good enough to get green check-marks from 200 CI jobs. ## Related I will do a talk at FOSDEM 2026 titled Open Source Security in spite of AI that of course will touch on this subject. ## Future We never say never. This is now and we might have reasons to reconsider and make a different decision in the future. If we do, we will let you know. These changes are applied now with the hope that they will have a positive effect for the project and its maintainers. If that turns out to not be the outcome, we will of course continue and apply further changes later. ## Media Since I created the pull request for updating the bug-bounty information for curl on January 14, almost two weeks before we merged it, various media picked up the news and published articles. Long before I posted this blog post. * The Register: Curl shutters bug bounty program to remove incentive for submitting AI slop * Elektroniktidningen: cURL removes bug bounties * Heise online: curl: Projekt beendet Bug-Bounty-Programm * Neowin: Beloved tool, cURL is shutting down its bug bounty over AI slop reports * Golem: Curl-Entwickler dreht dem β€œKI-Schrott” den Geldhahn zu * Linux Easy: cURL chiude il programma bug bounty: troppi report generati dall’AI * Bleeping Computer: Curl ending bug bounty program after flood of AI slop reports * The New Stack: Drowning in AI slop, cURL ends bug bounties * Ars Technica: Overrun with AI slop, cURL scraps bug bounties to ensure β€œintact mental health” * PressMind Labs: cURL ko?czy program bug bounty – czy to koniec jako?ci zg?osze?? * Socket: curl Shuts Down Bug Bounty Program After Flood of AI Slop Reports Also discussed (indirectly) on Hacker News.

The end of the #curl bug-bounty

https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/

26.01.2026 07:25 πŸ‘ 65 πŸ” 80 πŸ’¬ 5 πŸ“Œ 4
Post image

ctf pattern recognition test

24.01.2026 17:44 πŸ‘ 77 πŸ” 18 πŸ’¬ 5 πŸ“Œ 0

locked in? bro i’m tucked in

24.01.2026 04:00 πŸ‘ 2601 πŸ” 1034 πŸ’¬ 6 πŸ“Œ 7

"Just fucking transition already" in all its forms is necessary counterculture to the endless fucking eggslop that litters the trans internet. "When you wish you were a–" you are one. Transition about it. Quit romanticising the closet.

20.01.2026 01:09 πŸ‘ 1110 πŸ” 326 πŸ’¬ 16 πŸ“Œ 12

this data format could've been sqlite

12.01.2026 18:45 πŸ‘ 200 πŸ” 20 πŸ’¬ 4 πŸ“Œ 3

Mamdani’s New York is out of control

09.01.2026 01:45 πŸ‘ 10225 πŸ” 3080 πŸ’¬ 23 πŸ“Œ 4
Wuk lamat with her hands on her hips and leaning forward angrily. #drawing

Wuk lamat with her hands on her hips and leaning forward angrily. #drawing

Forgot I had an unused Wuk Lamat from that last comic

13.12.2025 23:32 πŸ‘ 896 πŸ” 237 πŸ’¬ 10 πŸ“Œ 0
Firefox message
"Close 65 tabs?"
A checkbox below says "ask before closing multiple tabs". Two buttons below say "Close tabs" and "Cancel"

Firefox message "Close 65 tabs?" A checkbox below says "ask before closing multiple tabs". Two buttons below say "Close tabs" and "Cancel"

just wrote a bash script

05.12.2025 21:55 πŸ‘ 95 πŸ” 8 πŸ’¬ 3 πŸ“Œ 1
Post image

I propose a solution to our ongoing RAM shortage:

06.12.2025 02:32 πŸ‘ 1845 πŸ” 491 πŸ’¬ 30 πŸ“Œ 19