Post B6X6qSKvxAq25comR6 by wolf480pl@mstdn.io
 (DIR) More posts by wolf480pl@mstdn.io
 (DIR) Post #B6X5wDCX2XCevn4Kiu by domi@donotsta.re
       1 likes, 0 repeats
       
       you idiots. you doofuses. you absolute spoiled bags of rice. how fucking stupid do you have to be to unironically think that this is gonna result in “all vulnerabilities being patched”sweet summer children who haven’t ever touched a line of code, if there’s a logical conclusion to this madness it’s open source ceasing to exist as we know it, not more security for everyone. take your rose-tinted glasses off
       
 (DIR) Post #B6X6IE7QJDAy9EB1lo by famfo@frogs.lgbt
       1 likes, 0 repeats
       
       @domi "you absolute spoiled bag of rice" :neocat_sob: damn
       
 (DIR) Post #B6X6JtRW9VRybNN1tI by domi@donotsta.re
       0 likes, 0 repeats
       
       @famfo WITH NO OFFENSE TO ACTUAL RICE
       
 (DIR) Post #B6X6qSKvxAq25comR6 by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @domi so you think it's not just fuzzers 2.0?
       
 (DIR) Post #B6X79ZjMgdUGWYMWXI by domi@donotsta.re
       0 likes, 0 repeats
       
       @wolf480pl have you SEEN the sheer volume?98% of those are nothingburgers or not even valid reports. remaining stuff is released publicly with PoCs because the “security researchers” don’t fucking understand how to empty the bathwater without fucking massacring the child
       
 (DIR) Post #B6X7d9iNyeR0Wc0ddI by filmroellchen@chaos.social
       0 likes, 0 repeats
       
       @domi my hope/suspicion is that number of vulns will also go up with vibecoding (there’s some preliminary evidence to support this, but idk how relevant it will be to larger projects), so we will get both: more vulns and more reports.(as long as vibecoders get all the vulns, i’m happy, because those stupid ass fuckers have it coming)
       
 (DIR) Post #B6X7dA8yNnhZr4Rs4e by domi@donotsta.re
       0 likes, 0 repeats
       
       @filmroellchen it already has come up, see virtually any project that does a significant amount of slop. rustfs comes to mind, the code stinks so badly even just through the list of CVEswhat happens remains to be seen, but i’m worried for the worst
       
 (DIR) Post #B6X8eMXDtl6gWrvYpM by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @domi I have not, the volume of CVEs was already too much for me to comprehend 10 years ago.All I've seen is curl maintainer's reaction.As for PoCs - yeah, that's shitty, but it doesn't fundamentally change whether the world will eventually run out of bugs that these "tools" are capable of finding.Though in the meantime, that does make using open-source software a liability :/
       
 (DIR) Post #B6XvD8Rp3re6m332QK by Lili@donotsta.re
       1 likes, 0 repeats
       
       @domi can't believe they profane the poor Fluttershy like that :neocat_sob: