Conversation

High-Quality chaos. This is where we're at right now, security reporting wise.

https://daniel.haxx.se/blog/2026/04/22/high-quality-chaos/

3
12
0

@bagder what did you change?

It says in the post that Curl was off HackerOne from February 1st 2026 till some time in March 2026, but nothing says why the report quality changed in that month all of a sudden

1
0
0

@luc we changed nothing, the tooling changed

0
0
0

@bagder so I guess the puzzle for me after reading this piece is

How do you feel about this?

In the "slop era" you were (rightfully) upset, used words like "terrorism", and took active defensive measures like turning bug bounties off

Now you're back on Hackerone. Since the quality is higher, I presume it's not purely "time wasting" and providing value

But you don't seem exactly pleased, yet also don't actually say?

My apologies if I'm missing something, I'm still getting my morning caffeine

1
0
0

@jhwgh1968 I've tried to describe the situation as-is, without declaring any feelings about it at all.

0
0
0
@bagder hey, just wondering, considering the recent 270~ security issue found in Mozilla recently with Mythos.
Did you get contacted by Anthropic to test their tool ?
1
0
0

@clegoffic I suppose we can say "indirectly". I am in the process of getting access, although it has not actually materialized just yet.

1
0
1
@bagder eager to see your point of view after the first test
0
0
0