• T156@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    2 days ago

    Right, but the volume was the issue. The cURL team could only work through and verify them so quickly, so the deluge of bug reports just made it impractical for them to dedicate time to sort through it. The idea in getting rid of the bug bounty being that there would be less of an incentive to generate and write a bogus bug report.

    If it was just a small handful of fake security reports, they wouldn’t have minded nearly as much.

    • TheBlackLounge@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      Uhu, and if it was still as obvious as in 2023 they could have made a filter by now… Which is why I called hindsight bias. But AI improved with being more convincing, that’s the actual problem, not volume. Imagine if AI actually got more correct, they would also have a higher volume of reports. Maybe not that much but ones they’d actually have to spend time to fix.