LinkedIn and 3rd parties use essential and non-essential cookies to provide, secure, analyze and improve our Services, and to show you relevant ads (including professional and job ads) on and off LinkedIn.

curl Maintainer Daniel Stenberg Responds to AI-Generated Security Report Spam on HackerOne
Photo: LinkedIn

curl Maintainer Daniel Stenberg Responds to AI-Generated Security Report Spam on HackerOne

Daniel Stenberg, the lead developer and CEO of curl, has publicly expressed his frustration over a surge of low-quality, AI-generated security reports submitted via HackerOne. In a recent LinkedIn post, Stenberg announced new measures to address what he describes as a form of denial-of-service (DDoS) attack on project maintainers: every reporter must now declare if AI was used in their submission, and those submitting reports deemed ‘AI slop’ will be instantly banned. Stenberg noted that, so far, no valid security report generated with AI assistance has been accepted, and the overwhelming volume of such reports is wasting valuable time and resources. The post sparked a wide-ranging discussion among open source security professionals, who suggested potential solutions such as requiring a deposit for report submissions to discourage frivolous or low-effort entries. Others debated the role of AI in security research, distinguishing between using AI to write reports versus using it to find vulnerabilities. The consensus among maintainers is that while AI can be a helpful tool, it should not replace human expertise or due diligence. The conversation highlights a growing challenge facing open source projects: balancing openness with the need to protect maintainers from abuse and ensuring the quality of security disclosures in the age of generative AI.

Leave a Reply

Your email address will not be published. Required fields are marked *