Related posts
Daniel Stenberg
Mastodon
Between all the vulnerability report work, I made curl's date parser twice as fast as before...
parser vulnerability curl
The the words it uses that this site has seen
least often elsewhere. Posts are matched on those words alone —
nothing here is a summary of this one.
Sources
All
Writing
Mastodon x.com GitHub Korrents Blog Recommends
Top people
Daniel Stenberg
John MacFarlane
Bruce Schneier
Daniel Lemire
Tobias Lütke
Armin Ronacher
Ajeya Cotra
Xe Iaso
David Heinemeier Hansson
Chris Wellons
Filippo Valsorda
Alice Ryhl
Showing
Profile →
Show everything
Hiding
Show them again
Show them again
Further back ↓
Hiding
Show them again
20 September
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
18 September
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
#curl 8.23.0 release candidate one is up: https://curl.se/rc/ Please take it for a spin and double-check that it works just as smooth as you would expect. Do not use release candidates in production. They are work in progress. Use them for testing and verification only. Use actual releases in production. Related
I had a look at the “project number of CVEs” that we estimated back at #curl up in late May. We then said it could end up at 55 by the end of the year. As we now already have published 45 and there are (at least) 20 coming, we have certainly exceeded those projections. The question is now rather if it will even be below 80 by the end of the year. Related
Last year I blogged about the vulnerability reporting process in #curl. It remains the same, just with about 3-4x the volume... daniel.haxx.se
Related
15 September
Computer science professor who works on fast data processing; co-author of the simdjson parser and a weekly blogger about software performance since 2004.
A new fast_float release... fast_float is a super fast number parser in C++ (used by GCC, MySQL, your browser...). The latest release adds support for parsing numbers following the JavaScript standard, so things like 05.1 can be accepted (!!!). JavaScript Related
11 September
Philosophy professor at UC Berkeley and creator of pandoc, the universal document converter, and of the CommonMark markdown specification.
9 September
Co-founder and CEO of Shopify; long-time Linux user and Omarchy contributor.
Shipped. curl https://t.co/kEElDtGYaw -H "Accept-Language: en-us, ruby" Related
7 September
Creator of Flask and Jinja. Writes about software at lucumr.pocoo.org.
3 September
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
2 September
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
1 September
Technical staff at METR, where she works on threat modelling and risk assessment for loss-of-control risks from advanced AI.
Their words
But in many of these cases, this vulnerability is just not broad or deep enough to ever actually be exploitable to get the flag. So a bunch of exploit gym problems are just unintentionally impossible. The authors estimate roughly 30 to 40% of these problems are impossible in this way.
Show the whole quote
youtube.com
27 August
Technical educator, conference speaker and developer relations engineer based in Ottawa, Canada. Author of the Anubis bot filter and of over 400 articles at xeiaso.net.
Their words
This is due to the affected components being written in C, the only programming language where these vulnerabilities regularly happen.
Show the whole quote
xeiaso.net
26 August
Creator of Ruby on Rails, CTO of 37signals, and creator of Omarchy.
Their words
So the irony here is that when you look at that field, it seems like we've reached levels of intelligence that virtually no human can match because many of these security holes are about stringing combo moves together. You find one little vulnerability here that by itself might not be the worst thing in the world, but then you combine it with four others, and suddenly you have RCE, remote command execution. Humans who are able to do that are very rare.
Show the whole quote
youtube.com
17 August
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
14 August
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
12 August
Software engineer who writes about low-level and systems programming at nullprogram.com; author of the Elfeed feed reader, the Endlessh SSH tarpit and Enchive.
3 August
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
27 July
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
HTTP Message Signatures with curl The recently published RFC 9421 describes how to do HTTP Message Signatures, and starting just now, curl experimentally supports them. Message Signatures The specification describes this as a mechanism for creating, enc…
Related
23 June
Cryptography engineer; maintains Go's cryptography libraries as a full-time open-source maintainer, funded directly by companies that use them.
8 June
Security technologist and author of books including Applied Cryptography and Data and Goliath; writes the Schneier on Security blog and the monthly Crypto-Gram newsletter.
1 June
Security technologist and author of books including Applied Cryptography and Data and Goliath; writes the Schneier on Security blog and the monthly Crypto-Gram newsletter.
20 May
Rust engineer at Google working on Android; maintains Tokio and works on Rust in the Linux kernel.
21 April
Member of technical staff at Anthropic. He has led ML/AI teams at Amazon, Alibaba and Lazada, and writes about LLMs, recommender systems and engineering at eugeneyan.com.
Great writeup by @mozilla: Mythos found 271 vulns (fixed in Firefox 150); Opus 4.6 found 22 (fixed in Firefox 148) https://t.co/wzTCxmTKbe > "So far we’ve found no category or complexity of vulnerability that humans can find that this model can’t." > "The defects are finite, and we are entering a world where we can finally find them all." ❤️ Related
18 April
Mac and iOS developer; created NetNewsWire and MarsEdit, co-created the JSON Feed format, and blogs at inessential.com.
7 March
Ruby and Rails core committer known online as "tenderlove"; maintains Nokogiri and works on Ruby performance.
24 January
Machine learning engineer and consultant focused on RAG and retrieval systems. He writes about applied AI engineering at jxnl.co and is the author of the instructor library.
Their words
Milbon Curl Mousse keeps curls hydrated and defined.
Show the whole quote
jxnl.co
21 October 2025
Writes jvns.ca, turning "hard and scary" topics — networking, debugging, Linux internals — into plain explanations and hand-drawn comics. Publishes Wizard Zines, illustrated programming zines. Software developer based in Montreal.
7 February 2025
Distributed-systems safety researcher; runs the Jepsen consistency-testing project and wrote the Riemann monitoring system.
5 July 2024
Swedish open source developer; creator and lead maintainer of curl and libcurl, and a co-founder of the Rockbox project.
4 March 2024
Historian of Ukraine at Harvard; wrote The Gates of Europe, Chernobyl and The Russo-Ukrainian War.
Their words
But next accident would actually expose new vulnerability. You deal with Chernobyl and then tsunami comes. You deal with tsunami and then war comes.
Show the whole quote
youtube.com
10 November 2023
Indian software developer working with React and TypeScript; writes and publishes a newsletter at sreetamdas.com.
Re: [patched] critical vulnerability in Sentry's Next.js SDK Of course it's regex 😅 Related
28 September 2023
Programmer and entrepreneur; co-founded GitHub and created Jekyll, Gravatar and the Semantic Versioning spec.
17 May 2023
Mac and iOS developer at the Iconfactory, where he has worked on apps including Twitterrific and Tot. He writes about development at furbo.org.
8 December 2021
Developer and podcaster; created Instapaper and Overcast, co-founded Tumblr, and co-hosts the Accidental Tech Podcast.
12 May 2014
Software developer; created Firebug, helped create Firefox on the Netscape browser team, and built the original Facebook iPhone app.
Nothing matches. Show everything
What is a korrent?
A korrent is a belief a person has stated in their own words: one
sentence stating the claim, backed by a quote and a source, kept at
korrents.com .
Under a name here, the quoted block is what they actually said.
The korrent beneath it is the claim those words support, in
korrents' wording — tap it to see the record, its source, and who
else holds it.
Nobody here wrote their own korrents. They are compiled from public
statements, and a person can change their mind, which is recorded too.
Got it
About the English under a post
Some people here publish in a language other than English. Where they
do, this site shows a machine translation beneath the post, in
this typeface — the site's own, not theirs.
The post itself is never changed, moved or hidden: what is set in the
serif above is exactly what the person published, and it is what to
quote them on. A translation can be wrong in ways that matter,
especially about tone.
Only the post's own words are translated. A quoted post, a linked
article and a belief on korrents.com
are left in their original language.
Got it