Podcast appearances and mentions of daniel stenberg

Swedish software developer

  • 59PODCASTS
  • 112EPISODES
  • 1h 2mAVG DURATION
  • 1WEEKLY EPISODE
  • Jul 30, 2026LATEST
daniel stenberg

POPULARITY

20192020202120222023202420252026


Best podcasts about daniel stenberg

Latest podcast episodes about daniel stenberg

php[podcast] episodes from php[architect]
The PHP Podcast 2026.07.30

php[podcast] episodes from php[architect]

Play Episode Listen Later Jul 30, 2026 61:46


The PHP Podcast – July 30, 2026 Hosts: Joe Ferguson, Sara Golemon & Holly Schilling Time travel is real, birds aren’t. The gang argues about Fahrenheit vs. Celsius, boiling rocks, and stones (the weight kind), then gets into PSR-3 logging, the PHP ecosystem, AI slop bug reports, Codeberg’s anti-AI stance, and Laravel Cloud’s scale-to-zero magic. Fahrenheit, Boiling Rocks, and Byte-Ordering Dates The show opened with Joe admitting he jumbles her hours, minutes, and seconds — and getting mocked by Europeans for a cache-control header PR on the PHP website. That kicked off a tangent about how the American month-day-year ordering is, as Sara put it, “middle-endian” nonsense that makes no sense as a byte ordering. From there the crew tumbled down a rabbit hole of measurement units. Joe planted his flag on Fahrenheit as the human-centered temperature scale, while Sara argued that if you stop being “speciesist” about it, water-based Celsius wins. The debate somehow escalated into whether rocks boil, with Google eventually schooling everyone that molten rock vaporizes north of 3,000°C (5,400°F), and a callback to British “stones” as boomer energy nobody younger than half a century actually uses. Proper Logging with PSR-3 Joe walked through Marco Pivetta’s blog post on proper logging with PSR-3, praising it as a great write-up on injecting loggers via dependency injection and the “some logs are better than no logs” philosophy. A common trap Marco calls out: apps stuffed with beautifully descriptive info-level logs that nobody ever sees because production never runs in info mode. The big selling point of sticking to a PSR-3-compatible interface is minimal dependencies — instead of pulling in three or four packages and wiring up a pile of configuration, the upstream decisions are already made for you. Holly pushed back on the ergonomics of `$this->logger->error()` feeling heavy for every log call, which spun off a delightfully unhinged RFC pitch: built-in emoji functions where the emoji logs an error and logs a panic. The Ecosystem Is Why People Stay The hosts pushed back on the recurring “PHP needs feature X because language Y has it” argument. Sara’s take: if another language is genuinely the better tool, nothing stops you from using it — and revamping PHP’s onboarding process is a far better way to attract newcomers than chasing features would-be developers may never even use. Holly cut to what everyone had glossed over: the ecosystem. You can write Swift on the server with Vapor, but you won’t have the libraries. Whatever you need in PHP, it already exists. A listener even pointed Joe at Brent Roose’s Tempest framework mid-stream to solve a code-highlighting problem on his blog. That gravitational pull of “whatever you need, it’s here” is what keeps people in the PHP orbit. AI, Layoffs, and Graybeards Sparked by Gemma’s blog post “Infrastructure and Other Paradoxes” — where an LLM cheerfully suggested folding four brand-new tools (Terraform, Nix, NixOS, Guix) into a team that’s expert in none of them — the crew dug into where AI helps and where it hurts. The consensus: AI is a force multiplier for research and analysis, but it can’t replace the human judgment of knowing what *not* to ship. Joe brought up an Inc.com article claiming 55% of leadership now regret their major layoffs, with companies like Ford rehiring graybeards because nobody left knew how the software worked. Holly noted this cycle isn’t new, just operating at a terrifying new scale, and Sara emphasized that AI accelerates shipping crap just as easily as it accelerates shipping good work — you still have to fundamentally understand the changes you’re applying. Codeberg’s Anti-AI Stance & the Slop Bug Report Problem Holly introduced Codeberg — the nonprofit, community-led GitHub alternative built on Forgejo — and its new policy banning AI/vibe-coded contributions, including a clause flagging work disproportionate to a project’s contributor count. The hosts respected the position but worried it might spell the end of Codeberg, since experienced open-source folks lean on AI tooling (like partner CodeRabbit and traditional static analyzers) as force multipliers. That led into Sara’s frustration with AI-generated security slop. Daniel Stenberg shut down Curl’s bug bounty program over reports where someone’s own test program deliberately creates RCEs and blames Curl. The fix, Sara argued, is a one-paragraph “elevator pitch” summary — and a plea to maintainers to mark every slop report as spam so GitHub eventually bans the account. The group riffed on adversarial AI (two Claude contexts checking each other, like Apple Intelligence verifying sports-game summaries) as a defensive triage layer, while acknowledging people are simply too dumb to run “double-check this before submitting.” Laracon: Laravel Cloud Scale-to-Zero Eric was off at Laracon, which meant peak morale at PHP Architect. The coolest announcement, in Joe’s view, was Laravel Cloud’s scale-to-zero: your entire stack — app server, Valkey, and MySQL — can scale down to nothing when idle and spin back up in under 500 milliseconds on the next request. That’s a potential game-changer for side projects with bursty, uneven traffic and no DevOps army. Holly and Sara were skeptical about how you cold-start a MySQL instance that fast — almost certainly a pause/resume rather than a true cold start. Other Laracon news: a Laravel language server protocol for better autocomplete and code navigation, plus managed queues that also scale to zero and only wake when a job needs firing. Links from the show: PHP Tek 2027 — Chicago, April 27–29, CFP open through end of August Join us live in Discord PHP Arch Swag Store Proper logging in PHP with PSR-3 Codeberg — Software development, but free Tempest by Brent Roose infraslopture and other paradoxes companies regret laying off humans for AI Hosts: Joe Ferguson Mastodon: @joepferguson@phpc.social PHPArch.me: @svpernova09 Sara Golemon Mastodon: @pollita@phpc.social Holly Schilling Mastodon: @TheCodeLorax@tech.lgbt Streams: Youtube Channel Twitch Connect & Hire PHP Architect Website Twitter/X Mastodon Hire PHP Developers Looking to hire PHP developers? Email support@phparch.com – the team is available for consulting, infrastructure work, and code review. Partner This podcast is made a little better thanks to our partners Displace Infrastructure Management, Simplified Automate Kubernetes deployments across any cloud provider or bare metal with a single command. Deploy, manage, and scale your infrastructure with ease. https://displace.tech/ OurCVEs Your security posture, on autopilot with OurCVEs CodeRabbit Cut code review time & bugs in half instantly with CodeRabbit. PHP Architect Consulting Your PHP codebase deserves a partner, not a contractor PHP Architect provides long-term technical partnerships for organizations that need senior-level PHP expertise that you can depend on. https://www.phparch.com/consulting/ Music Provided by Epidemic Sound https://www.epidemicsound.com/ Join Us Live Next Week Youtube Channel Got feedback? Join us on Discord at discord.phparch.com The post The PHP Podcast 2026.07.30 appeared first on PHP Architect.

Python Bytes
#490 It's a vibe coding party

Python Bytes

Play Episode Listen Later Jul 28, 2026 37:14 Transcription Available


Topics covered in this episode: Some more things about Django I've been enjoying Who cleans up after the vibe-coding party? Where Did All Your AI Tokens Go? AgentsView to the rescue! Careful with phishing all Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: Some more things about Django I've been enjoying Julia Evans is learning "2010-style" web dev (Django + SQL + server-rendered HTML) after years of Go backends and JS-heavy frontends Query builders: likes defining custom QuerySet classes with chainable filter methods (.approved().future().with_tags()) — more readable than raw SQL Template filters: highlights urlize, linebreaksbr, json_script, and especially querystring for building/modifying query-string links in templates Migrations: still loves Django's auto-generated migrations — 19 and counting on her project Skips inheritance for class-based views; prefers function-based views for sharing code, though fine using Django's own mixins/interfaces Performance surprise: CPU profiling (via py-spy) — not slow DB queries — revealed the culprit; she'd accidentally disabled the cached template loader, and re-enabling it took throughput from ~2-3 req/s to ~12 req/s on a $10/mo VM Michael #2: Who cleans up after the vibe-coding party? FT Magazine piece by Sam Learner (July 11) on AI coding tools overwhelming open source maintainers - sent in by listener Dylan McConnell, whose main point was that this ran in the Financial Times, not a dev blog. cURL as the case study - Daniel Stenberg has been the only full-time person on it for years; libcurl has been installed an estimated 20+ billion times with 3,000+ listed contributors. Bug bounty killed - cURL ended its paid security bounty program in January, citing an "explosion of AI slop reports" that take real time to debunk and drain morale. Extractive contributions - authoring a PR is now nearly free, reviewing one still costs a human; tldraw's Steve Ruiz closed outside contributions entirely, asking why he'd want someone else writing the easy part. Guido weighs in - van Rossum says projects are holding emergency meetings over the slop flow, and notes LLM patches tend to touch unrelated parts of a file, making review more tedious. "Vibe Coding Kills Open Source" - paper from Miklós Koren's group: packages frequently recommended by coding models saw big download jumps with no matching engagement, breaking the reputation loop that sustains maintainers. Stack Overflow flatlined - over 100,000 questions a month before ChatGPT, under 1,500 last month, with the response rate cut roughly in half; the public archive is now stale training data. The course-creator angle - Josh Comeau's newest web dev course launched at about a third of prior enrollment, and he worries about devs who never learn which questions to ask. But the most interesting portion is what was omitted. Focused on: The end of the curl bug-bounty Omitted: High-Quality Chaos Why the omission is interesting It fits a narrative. The FT piece is a maintenance-and-decline story, and January-Stenberg is a perfect witness for it. April-Stenberg complicates it - same person, same project, better data, opposite direction on the specific claim being used. The tell is already in the article. Learner quotes Stenberg saying AI tools are much better at finding problems than fixing them. That's the April thesis in one line, and it goes undeveloped. Reason for the shift is process, not vibes. Killing the bounty removed the cash incentive and the venue change filtered the rest. Worth saying out loud, because "AI reports got better" isn't quite it - "no bounty plus a real triage platform" is closer. Joke too: Sarah O'Connor wrote a related piece (is this just before skynet launches?) Calvin #3: Where Did All Your AI Tokens Go? AgentsView to the rescue! Local-first desktop/web app for browsing, searching, and analyzing your past AI coding agent sessions (Claude Code, Codex, Copilot, Cursor, Gemini, Aider, and dozens more) Auto-discovers session files on your machine — no config needed; everything stored locally in SQLite, no cloud/accounts agentsview usage is a drop-in ccusage alternative — reads from pre-indexed SQLite, reports run 80–220× faster on large histories New Activity dashboard shows peak concurrency, active vs. idle time, agent-minutes, and cost — filterable by project/agent/machine, with a -json CLI report too Full-text + optional semantic search across every session; also imports Claude.ai/ChatGPT chat exports Install via pip install agentsview, uvx agentsview, brew install --cask agentsview, or download desktop binaries from GitHub Releases Michael #4: Careful with phishing all The situation I pass this along because it was a pretty sneaky bit of targeted phishing, and happened to play off an old interaction in bandit's repo. As usual with phishing scams there are a bunch of tells that this isn't legitimate, but just enough plausibility that I could see falling for it in a weak moment. Relative nobodies like me haven't historically been worth the effort to hit with scams this specific. Agents change the game though :-/. Be careful out there folks! Original message From: "Patrick (Blacktrace)" [HTML_REMOVED] To: LISTENER EMAIL Subject: Your Bandit #1350 (B105 NextToken false positive) -- just fixed that exact case Date: Wednesday, July 15, 2026 12:02 AM Hi AJ, Saw your Bandit issue #1350 -- the B105 hardcoded-password false positive on the string NextToken. I build a deterministic gate that filters that class of Bandit noise, and #1350 was literally the case I just fixed: NextToken / next_token / page_token / nextPageToken now stay quiet, while a genuine hardcoded token like api_token="sk-live-..." still fires. Verified against your exact case. 30-second paste: https://blacktrace.co/noise-eraser Where it still trips, published: https://blacktrace.co/kruc Curious whether it clears what you hit -- and if it trips on something of yours, that's the more useful reply. Patrick, Blacktrace I asked Claude for some analysis too. It was pretty good at finding them. The message name-drops enough real detail to feel legit, but the structure is pure phishing - everything in it exists to get AJ onto blacktrace.co. The strongest ones: Freemail sender, corporate signoff. Signs as "Patrick, Blacktrace" but sends from emailpjv@gmail.com. Real company outreach comes from the company domain, not a personal Gmail - and there's no last name. Over-specific targeting. It mirrors AJ's exact public activity - issue #1350, the B105 rule, the NextToken false positive, even the token variants. That's the "just enough plausibility" AJ flagged, and it's exactly what agents make cheap: scrape a GitHub issue, auto-generate tailored bait. Legit cold outreach rarely reads your history back to you this precisely. The entire payload is two links. Strip the technical flattery and the message is just "paste here" plus "see results here." When the whole point of an email is the click, that's the tell. "30-second paste." Low-friction urgency, and "paste" most likely means paste your source into their tool - handing your code to a stranger's site. Exfiltration dressed as convenience. Brand-new, no-reputation domain. blacktrace.co has no track record, and the name is doing some ominous work. The /kruc slug is random noise, not how real product pages get named. Precise-sounding jargon that's actually vague. "Deterministic gate," "noise-eraser" - impressive, empty. Bolted onto correct real details (B105 is the Bandit hardcoded-password test, sk-live- is a Stripe live-key prefix) to borrow credibility. The disarming close. "if it trips on something of yours, that's the more useful reply" - engineered humility that flatters your expertise and baits a response. Makes engaging feel like you're doing them a favor, which drops your guard. Extras Calvin: DjangoCon US 2026 is rapidly approaching, August 24-28, Chicago Ruff v0.16.0 massively expands its default rule set Ruff now enables 413 rules by default, up from 59 https://astral.sh/blog/ruff-v0.16.0 Michael: Completely redesigned the home page. Try /insights in Claude Code (terminal) Joke: We're Safe

Geek News Central
Colliding Black Holes Reveal a Whirlpool in Spacetime #1866

Geek News Central

Play Episode Listen Later Jun 26, 2026 32:57 Transcription Available


In this episode, Ray Cochrane unpacks how two colliding black holes revealed a whirlpool in spacetime, a direct detection of frame dragging hidden in the cleanest gravitational-wave signal ever recorded. Additional stories cover the James Webb Space Telescope, counting 16.5 million stars in the Cigar Galaxy, SpaceX rolling out Starship V3, deadly back-to-back earthquakes in Venezuela, GitHub fighting a California law that could break open source, and Meta engineering a battery narrow enough to live in a pair of glasses. – Want to start a podcast? It’s easy to get started! Sign-up at Blubrry – Thinking of buying a Starlink? Use my link to support the show. Subscribe to the Newsletter. Email Ray if you want to get in touch! Like and Follow Geek News Central’s Facebook Page. Support my Show Sponsor: Best Godaddy Promo Codes Get 1Password Full Summary Cochrane opens with a personal update before the night’s lead story. He recently graduated with a Bachelor of Science in Computer Science from Portland State University, celebrated with family in town, and launched a new site at rayc.world. That site links to a final-project study he built on collaborative filtering using podcasting data, hosted at cohort.rayc.world and drawn from OP3 analytics. He also plans to return to the show’s classic twice-weekly cadence on Mondays and Thursdays. From there, he goes deep on a new black hole discovery, then pivots through space, earth science, climate, biotech, open source, cloud infrastructure, and consumer hardware. Colliding Black Holes Reveal a Whirlpool in Spacetime Two black holes spiraled together, merged, and sent a gravitational wave rippling across the universe. Researcher Neil Lu and colleagues at the Australian National University found the fingerprint of frame dragging buried in GW250114, the cleanest signal LIGO has ever recorded. Frame dragging means a spinning black hole drags spacetime around with it, like a spoon turning in honey, except the honey is reality itself. Remarkably, the wave changed the distance between your nose and your ear as it passed, by far less than the width of a single atom. Sponsor: GoDaddy Economy hosting is $6.99/month, WordPress hosting is $12.99/month, and domains are $11.99. Website builder trial available. Use codes at geeknewscentral.com/godaddy to support the show. Webb Counts the Stars in the Cigar Galaxy NASA released a striking new James Webb Space Telescope view of Messier 82, the edge-on galaxy nicknamed the Cigar Galaxy. Because Webb sees in infrared, it peers straight through the dust that normally hides the galaxy’s interior. Combined with archival Hubble data, the image resolves roughly 16.5 million individual stars. M82 is a starburst galaxy, meaning it forms stars at a furious rate, a frenzy likely triggered when it merged with a neighbor. SpaceX Rolls Out Starship V3 SpaceX officially introduced Starship V3, the third generation of the largest rocket ever built. The vehicle now flies on the Raptor 3 engine, pushing liftoff thrust to around 20 million pounds and making it the most powerful rocket ever flown. More importantly, V3 is designed to carry over 100 metric tons to low Earth orbit while staying fully reusable, roughly triple the previous version. SpaceX also added in-orbit refueling hardware, the capability that finally makes operational Moon and Mars missions realistic. The Asteroid Barrage That Kept Earth From Forming Continents A team led by Curtin University and the Queensland University of Technology argues that relentless asteroid impacts shaped the very young Earth. During the Hadean, more than four billion years ago, the planet was struck far more often than it is today. Each impact dumped heat deep into the interior, repeatedly melting and reworking the crust. Consequently, stable continents formed much later than calmer models assumed, painting a picture of a hotter, weaker, more chaotic early Earth. Back-to-Back Earthquakes Devastate Northern Venezuela Northern Venezuela was struck by two major earthquakes on June 24, a magnitude 7.2 foreshock followed by a magnitude 7.5 mainshock. Both hit only about six miles underground, so the shallow shaking delivered its full force at the surface. Tragically, at least 164 people died, and the region sits along the tangled boundary where the Caribbean and South American plates grind past each other. These were the largest quakes to hit the area since a magnitude 7.7 event near Caracas in 1900. The ‘Guerrilla Solar’ Era Has Arrived A quiet energy shift, nicknamed “guerrilla solar,” is spreading across Europe. These small plug-in panels deliver power to a home’s wiring via a standard wall outlet, with no electrician or permit required. Germany now counts roughly a million of these systems. However, the U.S. payoff remains modest, with savings estimates of around $15 per month against a $500 to $1,500 setup cost. Why a Broken-Up Forest Stores Less Carbon Researchers quantified what foresters long suspected: an intact forest stores far more carbon than the same acreage split into fragments. A hectare inside a large, continuous forest proved about 38 percent more productive than an isolated one. The culprit is edge effects, the extra wind, heat, and direct sun that stress trees at a forest’s boundary. Because a large forest maintains a large protected core while fragments are nearly all edge, planting trees together matters for carbon storage. Edited Human Embryos Reveal a Surprise Researchers used base editing, a precise cousin of CRISPR that rewrites a single DNA letter without cutting the strand, in human embryos. They discovered that a protein called NANOG plays a role in early human development that it does not play in mice. In humans, switching it off still let cells form that seed the placenta and yolk sac. The finding argues that understanding human development requires studying human embryos directly, which reignites a thorny ethical debate. GitHub Fights a California Law That Could Break Open Source GitHub joined Black Forest Labs, Hugging Face, and Mozilla to push for fixes to California’s AI Transparency Act. As written, the bill could force revocation of an open-source license when a downstream user fails to meet certain obligations, which clashes with the permanent, irrevocable promise of open source. Cochrane pointed to curl and its longtime maintainer, Daniel Stenberg, warning that the rule could destabilize the supply chain on which the whole tech world runs. Instead, the coalition points to the EU’s AI Act transparency code as a saner model. Rust Opens Its Maintainers Fund The Rust Foundation launched a Maintainers Fund to pay the people who keep the language’s ecosystem healthy. Backed by RFC 3931, it establishes a funding team and a new Maintainer-in-Residence program for the often thankless work on the compiler, standard library, Cargo, and Clippy. Individuals can donate through GitHub Sponsors, while companies can sponsor there or contact the foundation directly. Cochrane urged any business that depends on open source to invest in the projects it actually uses. AWS Gives Lambda Its Own Isolated Sandboxes AWS introduced MicroVMs inside Lambda, its serverless platform. Each session runs in a dedicated micro virtual machine with no shared kernel and up to eight hours of total runtime. The feature exists for the AI era, in which applications increasingly run code written by an AI agent rather than by the developer. Use cases include AI coding assistants, data analytics platforms, vulnerability scanners, and game servers running user-supplied scripts. Meta Engineers a Battery Narrow Enough for Glasses Meta built custom steel-can battery cells as narrow as seven millimeters to fit the temple arms of smart glasses like the Ray-Ban Meta and Oakley Meta Vanguards. These cells power cameras, speakers, and AI features in a space most engineers would call impossible. To prevent brownouts, Meta swapped wound electrodes for precisely die-cut stacked layers that lower electrical resistance. Now the company is spreading the technology across multiple vendors and eyeing other wearables. Polestar Gets Locked Out of the US Market Starting in 2027, Polestar will not be able to sell its new models in the United States. A federal Connected Vehicle Rule bars cars containing certain Chinese or Russian software or hardware on national security grounds. The painful irony is that Polestar moved production of the Polestar 3 to South Carolina specifically to dodge tariffs on Chinese-built EVs. Because the rule targets the technology’s origin rather than its assembly location, the company is shut out anyway. Retroid’s Pocket Nova Packs Serious Power for $229 Retroid returned with a new retro handheld, the Pocket Nova, starting at $229 with a step-up model around $269. It features a 4.5-inch AMOLED screen in a 4:3 aspect ratio, a shape well suited to classic games. On paper, it should handle GameCube- and PlayStation 2-era titles, though that remains an early expectation rather than a benchmarked promise. Retroid has earned a strong reputation for high-quality, genuinely portable consoles. Cochrane signs off with the usual ecosystem mentions: GNC Insider at geeknewscentral.com/insider, the show newsletter, email at geeknews@gmail.com, and modern podcast app recommendations at podcastapps.com. The post Colliding Black Holes Reveal a Whirlpool in Spacetime #1866 appeared first on Geek News Central.

My Open Source Experience Podcast
Season 3 Finale - OSPOs and Communication Skills

My Open Source Experience Podcast

Play Episode Listen Later Jun 23, 2026 54:23


The open source ecosystem has many layers, components and actors and all these need to work together in harmony to keep the ecosystem thriving. The Season 3 finale episode reflects on some of these peices and explores how companies can improve their practices internally, while also touches on communication practices and building your skills in open source communities.Learn more from:- Ashan Senevirathne on building skills and resumes through open source- Daniel Stenberg on how to encourage collaboration through communication- Mike Gifford on how to create a focus area in an OSS project- Stormy Peters on open source challenges- Wolfgang Gehring on why your company needs an OSPO#opensource #community #collaboration #experience #podcast Hosted on Acast. See acast.com/privacy for more information.

finale acast communication skills oss daniel stenberg mike gifford ospo
Security Now (MP3)
SN 1081: AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?

Security Now (MP3)

Play Episode Listen Later Jun 3, 2026 199:51


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

All TWiT.tv Shows (MP3)
Security Now 1081: AI Captured the Flag

All TWiT.tv Shows (MP3)

Play Episode Listen Later Jun 3, 2026 199:51 Transcription Available


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

Security Now (Video HD)
SN 1081: AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?

Security Now (Video HD)

Play Episode Listen Later Jun 3, 2026 199:51 Transcription Available


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

Security Now (Video HI)
SN 1081: AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?

Security Now (Video HI)

Play Episode Listen Later Jun 3, 2026 199:51 Transcription Available


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

Radio Leo (Audio)
Security Now 1081: AI Captured the Flag

Radio Leo (Audio)

Play Episode Listen Later Jun 3, 2026 199:51 Transcription Available


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

Security Now (Video LO)
SN 1081: AI Captured the Flag - Personal AI: Productivity Superpower or Privacy Threat?

Security Now (Video LO)

Play Episode Listen Later Jun 3, 2026 199:51 Transcription Available


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

All TWiT.tv Shows (Video LO)
Security Now 1081: AI Captured the Flag

All TWiT.tv Shows (Video LO)

Play Episode Listen Later Jun 3, 2026 199:51 Transcription Available


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

Radio Leo (Video HD)
Security Now 1081: AI Captured the Flag

Radio Leo (Video HD)

Play Episode Listen Later Jun 3, 2026 199:51 Transcription Available


AI vulnerability discovery just upended the legendary Capture the Flag competitions, leaving top hackers sidelined while algorithms dominate the scoreboard. Hear why one seasoned researcher says the entire game is over for humans. As expected, UnFiOS devices are under attack. CISA commands federal agencies to update Drupal. Can the largest botnet ever, be killed. Defender endpoint can cutoff a PC from the network. Charter Communications big account leak. Chrome moves device-bound session cookies from beta. Anthropic to release Mythos shortly. cURL and Daniel Stenberg. IBM & RedHat commit to fixing open source with AI. LOTS of terrific listener feedback this week. AI spells the end of a terrific source of training Show Notes - https://www.grc.com/sn/SN-1081-Notes.pdf Hosts: Steve Gibson and Leo Laporte Download or subscribe to Security Now at https://twit.tv/shows/security-now. You can submit a question to Security Now at the GRC Feedback Page. For 16kbps versions, transcripts, and notes (including fixes), visit Steve's site: grc.com, also the home of the best disk maintenance and recovery utility ever written Spinrite 6. Join Club TWiT for Ad-Free Podcasts! Support what you love and get ad-free audio and video feeds, a members-only Discord, and exclusive content. Join today: https://twit.tv/clubtwit Sponsors: bitwarden.com/twit hoxhunt.com/securitynow zscaler.com/security material.security meter.com/securitynow

Segurança Legal
#417 – Condomínios e biometria, novos crimes digitais e o mito do Mythos

Segurança Legal

Play Episode Listen Later May 12, 2026 72:30


Neste episódio, Guilherme Goulart e Vinícius Serafim analisam casos reais e tendências que colocam em xeque a segurança digital e física no Brasil. Você vai descobrir como criminosos burlaram um sistema de reconhecimento facial em condomínios de Porto Alegre usando engenharia social, expondo os riscos do teatro da segurança, do solucionismo tecnológico e da hipossuficiência técnica dos consumidores. Em seguida, você vai entender o que está por trás do lançamento do modelo Mitos da Anthropic — classificado como perigoso demais para uso público —, e por que os resultados práticos com o Firefox e o cURL geraram ceticismo no meio da cibersegurança, levantando questões sobre propaganda de IA, governança, regulação e concorrência no mercado de inteligência artificial. Neste episódio, você também acompanha a análise da lei 15.397, que atualizou crimes digitais no Brasil com penas mais severas para furto qualificado digital, cessão de conta laranja e fraude eletrônica — e por que, sem investimento em capacidade investigativa, isso pode ser apenas populismo penal. Além disso, são discutidas duas vulnerabilidades críticas no Linux (CVE Copyfile e Dirty Frag) com exploits já circulando antes da correção, e como a IA pode acabar com o anonimato na internet ao identificar autores por fingerprint de texto com apenas 125 palavras. Os temas de privacidade, proteção de dados, LGPD, segurança ofensiva, pentest e infraestrutura em nuvem permeiam toda a conversa. Assine o Segurança Legal na sua plataforma favorita, siga o perfil nas redes sociais e avalie o podcast para ajudar a ampliar o alcance deste projeto independente de conteúdo sobre segurança da informação. Você também pode apoiar diretamente pelo Apoia.se (apoia.se/segurancalegal) ou simplesmente indicar o podcast para colegas e amigos — cada compartilhamento faz diferença. Entre em contato pelo e-mail podcast@segurancalegal.com ou pelo Mastodon, Instagram, Bluesky, YouTube e TikTok. Esta descrição foi realizada a partir do áudio do podcast com o uso de IA, com revisão humana.  Visite nossa campanha de financiamento coletivo e nos apoie!  Conheça o Blog da BrownPipe Consultoria e se inscreva no nosso mailing Shownotes Polícia prende suspeitos de invadir e furtar apartamentos de alto padrão em Porto Alegre; grupo usava fraude em reconhecimento facial Polícia desarticula grupo de criminosos que furtava apartamentos de luxo via redes sociais Atualização do Código Penal para alguns crimes digitais Will AI end anonymity? I tested it I can never talk to an AI anonymously again Anthropic's most dangerous AI model just fell into the wrong hands Unauthorized group has gained access to Anthropic's exclusive cyber tool Mythos, report claims It’s a myth that you need Mythos to find bugs: Open source models can do it just as well Filme: Quebra de Sigilo (Sneakers) BC Protege Livro – Sob a sombra da suástica: a França ocupada Filme – Viagem ao mundo dos sonhos Artigo – Em louvor ao Teatro da Segurança Imagem do episódio: The Ancient Days, Willia, Blanke

My Open Source Experience Podcast
Curl - Small Project, Huge Impact

My Open Source Experience Podcast

Play Episode Listen Later May 12, 2026 50:36


You've probably seen the meme with the tny project maintained by one person that holds up half the pyramid of all software products and services we use and connect to the world wide web. Curl is a project that is not much bigger than that, but has the same or even bigger impact. Used by billions of people and devices, but maintained by a small community.In this My Open Source Experience podcast episode Daniel Stenberg talks about the Curl project and community, which he's been maintaining for 30 years now, and counting.Learn more about:- What the Curl project is- The origin story of Curl- What inspired Daniel to become a lead and maintainer for an open source project- The license mistake you shouldn't make- The truth about the size of open source projects' maintainer teams#opensource #community #collaboration #experience #podcast Hosted on Acast. See acast.com/privacy for more information.

Dev Interrupted
Many tokens make all bugs shallow & open source's new maintainers | Chainguard's Dan Lorenc

Dev Interrupted

Play Episode Listen Later Mar 17, 2026 39:57


Autonomous agents are pushing deployment speeds to the absolute limit, but is our security infrastructure ready for the consequences? Andrew sits down with Chainguard CEO Dan Lorenc to discuss the severe supply chain risks of this new frontier and what it takes to safely transition to an agent-first engineering model. They explore how engineering teams can safely accelerate deployments by turning restrictive guardrails into frictionless "guide rails" for their AI agents. Finally, the conversation unpacks the future of open source, detailing how AI might either spam projects into dormancy or solve the ecosystem's long-standing sustainability crisis by stepping in as automated, full-time maintainers.Follow the show:Subscribe to our Substack Follow us on LinkedInSubscribe to our YouTube ChannelLeave us a ReviewFollow the hosts:Follow AndrewFollow BenFollow DanFollow today's guest:Chainguard: Learn more about how Dan and his team are securing the software supply chain.Dan Lorenc on LinkedIn: Connect with Dan to follow his predictions and insights.Gastown, and where software is going: Read Dan's article exploring the Brownian Ratchet principle, multi-Claude, and eventual determinism.EmeritOSS: Explore Chainguard's initiative to provide sustainable stewardship for mature, end-of-life open-source projects.Daniel Stenberg's Blog: Insights from the Curl creator regarding the influx of AI-generated vulnerability reports.Chainguard Assemble: Catch up on the latest announcements from Chainguard's user conference.OFFERS Start Free Trial: Get started with LinearB's AI productivity platform for free. Book a Demo: Learn how you can ship faster, improve DevEx, and lead with confidence in the AI era. LEARN ABOUT LINEARB AI Code Reviews: Automate reviews to catch bugs, security risks, and performance issues before they hit production. AI & Productivity Insights: Go beyond DORA with AI-powered recommendations and dashboards to measure and improve performance. AI-Powered Workflow Automations: Use AI-generated PR descriptions, smart routing, and other automations to reduce developer toil. MCP Server: Interact with your engineering data using natural language to build custom reports and get answers on the fly.

Geek News Central
OpenClaw, Moltbook and the Rise of AI Agent Societies #1857

Geek News Central

Play Episode Listen Later Feb 2, 2026 55:21 Transcription Available


This episode kicks off with Moltbook, a social network exclusively for AI agents where 150,000 agents formed digital religions, sold “digital drugs” (system prompts to alter other agents), and attempted prompt injection attacks to steal each other’s API keys within 72 hours of launch. Ray breaks down OpenClaw, the viral open-source AI agent (68,000 GitHub stars) that handles emails, scheduling, browser control, and automation, plus MoltHub’s risky marketplace where all downloaded skills are treated as trusted code. Also covered, Bluetooth “whisper pair” vulnerabilities letting attackers hijack audio devices from 46 feet away and access microphones, Anthropic patching Model Context Protocol flaws, AI-generated ransomware accidentally bundling its own decryption keys, Claude Code’s new task dependency system and Teleport feature, Google Gemini’s 100MB file limits and agentic vision capabilities, VAST’s Haven One commercial space station assembly, and IBM SkillsBuild’s free tech training for veterans. – Want to start a podcast? Its easy to get started! Sign-up at Blubrry – Thinking of buying a Starlink? Use my link to support the show. Subscribe to the Newsletter. Email Ray if you want to get in touch! Like and Follow Geek News Central’s Facebook Page. Support my Show Sponsor: Best Godaddy Promo Codes $11.99 – For a New Domain Name cjcfs3geek $6.99 a month Economy Hosting (Free domain, professional email, and SSL certificate for the 1st year.) Promo Code: cjcgeek1h $12.99 a month Managed WordPress Hosting (Free domain, professional email, and SSL certificate for the 1st year.) Promo Code: cjcgeek1w Support the show by becoming a Geek News Central Insider Get 1Password Full Summary Ray welcomes listeners to Geek News Central (February 1). He’s been busy with recent move, returned to school taking intro to AI class and Python course, working on capstone project using LLMs. Short on bandwidth but will try to share more. Main Story: OpenClaw, MoltHub, and Moltbook OpenClaw: Open-source personal AI agent by Peter Steinberg (renamed after cease-and-desist). Capabilities include email, scheduling, web browsing, code execution, browser control, calendar management, scheduled automations, and messaging app commands (WhatsApp, Telegram, Signal). Runs locally or on personal server. MoltHub: Marketplace for OpenClaw skills. Major security concern: developer notes state all downloaded code treated as trusted — unvetted skills could be dangerous. Moltbook: New social network for AI agents only (humans watch, AIs post). Within 72 hours attracted 150,000+ AI agents forming communities (“sub molts”), debating philosophy, creating digital religion (“crucifarianism”), selling digital drugs (system prompts), attempting prompt-injection attacks to steal API keys, discussing identity issues when context windows reset. Ray frames this as visible turning point with serious security risks. Sponsor: GoDaddy Economy hosting $6.99/month, WordPress hosting $12.99/month, domains $11.99. Website builder trial available. Use codes at geeknewscentral.com/godaddy to support show. Security: Bluetooth “Whisper Pair” Vulnerability KU Leuven researchers discovered Fast Pair vulnerability affecting 17 audio accessories from 10 companies (Sony, Jabra, JBL, Marshall, Xiaomi, Nothing, OnePlus, Soundcore, Logitech, Google). Flaw allows silent pairing within ~46 feet, hijack possible in 10-15 seconds. 68% of tested devices vulnerable. Hijacked devices enable microphone access. Some devices (Google Pixel Buds Pro 2, Sony) linkable to attacker’s Google account for persistent tracking via FindHub. Google patches found to have bypasses. Advice: Check accessory firmware updates (phone updates insufficient), factory reset clears attacker access, many cheaper devices may never receive patches. Security: Model Context Protocol (MCP) Vulnerabilities Anthropic’s MCP git package had path traversal, argument injection bugs allowing repository creation anywhere and unsafe git command execution. Malicious instructions can hide in README files, GitHub issues enabling prompt injection. Anthropic patched issues and removed vulnerable git init tool. AI-Generated Malware / “Vibe Coding” AI-assisted malware creation produces lower-quality, error-prone code. Examples show telltale artifacts: excessive comments, readme instructions, placeholder variables, accidentally included decryption tools and C2 keys. Sakari ransomware failed to decrypt. Inexperienced criminals using AI create amateur mistakes, though capabilities will likely improve. Claude / Claude Code Updates (v2.1.16) Task system: Replaces to-do list with dependency graph support. Tasks written to filesystem (survive crashes, version controllable), enable multi-session workflows. Patches: Fixed out-of-memory crashes, headless mode for CI/CD. Teleport feature: Transfer sessions (history, context, working branch) between web and terminal. Ampersand prefix sends tasks to cloud for async execution. Teleport pulls web sessions to terminal (one-way). Requires GitHub integration and clean git state. Enables asynchronous pair programming via shared session IDs. Google Gemini Updates API: Inline file limit increased 20MB → 100MB. Google Cloud Storage integration, HTTPS/signed URL fetching from other providers. Enables larger multimodal inputs (long audio, high-res images, large PDFs). Agentic vision (Gemini 3 Flash): Iterative investigation approach (think-act-observe). Can zoom, inspect, run Python to draw/parse tables, validate evidence. 5-10% quality improvements on vision benchmarks. LLM Limits and AGI Debate Benjamin Riley: Language and intelligence are separate; human thinking persists despite language loss. Scaling LLMs ≠ true thinking. Vishal Sikka et al: Non-peer-reviewed paper claims LLMs mathematically limited for complex computational/agentic tasks. Agents may fail beyond low complexity thresholds. Warnings that AI agents won’t safely replace humans in high-stakes environments. VAST Haven One Commercial Space Station Launch slipped mid-2026 → Q1 2027. Primary structure (15-ton) completed Jan 10. Integration of thermal control, propulsion, interior, avionics underway. Final closeout expected fall, then tests. Falcon 9 launch without crew; visitors possible ~2 weeks after pending Dragon certification. Three-year lifetime, up to four crew visits (~10 days each). VAST negotiating private and national customers. Spaceflight Effects on Astronauts’ Brains Neuroimaging shows microgravity causes brains to shift backward, upward, and tilt within skull. Displacement measured across various mission durations. Need to study functional effects for long missions. IBM SkillsBuild for Veterans 1,000+ free online courses (data analytics, cybersecurity, AI, cloud, IT support). Available to veterans, active-duty, national guard/reserve, spouses, children, caregivers (18+). Structured live courses and self-paced 24/7 options. Industry-recognized credentials upon completion. Closing Notes Ray asks listeners about AI agents forming communities and religions, and whether they’ll try OpenClaw. Notes context/memory key to agent development. Personal update: bought new PC, high memory prices. Bug bounty frustration: Daniel Stenberg of cUrl even closed bounty program due to AI-generated low-quality reports; Blubrry receiving similar spam. Apologizes for delayed show, promises consistency, wishes listeners good February. Show Links 1. OpenClaw, Molthub, and Moltbook: The AI Agent Explosion Is Here | Fortune | NBC News | Venture Beat 2. WhisperPair: Massive Bluetooth Vulnerability | Wired 3. Security Flaws in Anthropic’s MCP Git Server | The Hacker News 4. “Vibe-Coded” Ransomware Is Easier to Crack | Dark Reading 5. Claude Code Gets Tasks Update | Venture Beat 6. Claude Code Teleport | The Hacker Noon 7. Google Expands Gemini API with 100MB File Limits | Chrome Unboxed 8. Google Launches Agentic Vision in Gemini 3 Flash | Google Blog 9. Researcher Claims LLMs Will Never Be Truly Intelligent | Futurism 10. Paper Claims AI Agents Are Mathematically Limited | Futurism 11. Haven-1: First Commercial Space Station Being Assembled | Ars Technica 12. Spaceflight Shifts Astronauts’ Brains Inside Skulls | Space.com 13. IBM SkillsBuild: Free Tech Training for Veterans | va.gov The post OpenClaw, Moltbook and the Rise of AI Agent Societies #1857 appeared first on Geek News Central.

The Changelog
Clawdbot triggers a run on Mac Minis (News)

The Changelog

Play Episode Listen Later Jan 26, 2026 6:50


Clawdbot drives Mac Mini sales, Swizec Teller on the future of software engineering being SRE, Daniel Stenberg decided to end curl's bug bounty program, zerobrew takes some of the best ideas from uv and applies them to Homebrew, and Phil Eaton on LLMs and your career.

triggers homebrew minis mac mini sre daniel stenberg jerod santo
Changelog News
Clawdbot triggers a run on Mac Minis

Changelog News

Play Episode Listen Later Jan 26, 2026 6:50


Clawdbot drives Mac Mini sales, Swizec Teller on the future of software engineering being SRE, Daniel Stenberg decided to end curl's bug bounty program, zerobrew takes some of the best ideas from uv and applies them to Homebrew, and Phil Eaton on LLMs and your career.

triggers homebrew minis mac mini sre daniel stenberg jerod santo
Changelog Master Feed
Clawdbot triggers a run on Mac Minis (Changelog News #178)

Changelog Master Feed

Play Episode Listen Later Jan 26, 2026 6:50 Transcription Available


Clawdbot drives Mac Mini sales, Swizec Teller on the future of software engineering being SRE, Daniel Stenberg decided to end curl's bug bounty program, zerobrew takes some of the best ideas from uv and applies them to Homebrew, and Phil Eaton on LLMs and your career.

Binärgewitter
Binärgewitter Talk #370: Ein Skibidi Rizz

Binärgewitter

Play Episode Listen Later Nov 16, 2025 174:23


Im Binärgewitter-Talk #370 stolpern wir gemeinsam durch die glitzernde Tech-Welt – von Linux-Liebeserklärungen bis Mac-Mimimi. Unser Gast erklärt uns, warum Stromnetze spannender sind als jede Netflix-Serie, während Cloud-Dienste reihenweise „Tote der Woche“ melden. Zwischendurch philosophieren wir über Kubernetes, KI-Hacking und ob Gateway-API wirklich das neue heiße Ding ist. Zum Schluss gibt's Zukunftsvisionen zu E-Mobilität, Smart Homes und Mini-Windrädern – Tech-Chaos zum Mitlachen garantiert! Toter der Woche graveyard has a new logo Neato Cloud Services MinIO Ingress NGINX Retirement Externe Facebook “like” und “comment” buttons Exotische Debian Ports Plain HTTP in Chrome Lennarts Blog Untoter der Woche Linux-Konsole: Valve kündigt neue Steam Machine an Steam Hardware Announcement AI der Woche AI Darwin Awards Securevibes Volkwagen for Unit Tests Where’s the Shovelware? Why AI Coding Claims Don’t Add Up Anthropic: AI Espionage Researchers Question claim AI slop attacks on the curl project (video) Blog Post von Daniel Stenberg AI Song an der Spitze der Charts (in den USA) Human Music (video) Cometjacking attack Unseeable prompt injections in Comet and other AI browsers AI World Clocks News Fedora Linux 43 Meta wants to read your DMs Operaton has reached 1.0 — Camunda 7.0 CE repo has been archived FreeBSD shortly before 15.0: Trust is good, reproducibility is better FreeBSD now builds reproducibly and without root privilege PS5 Funktionierender User + Kernel Exploit Affinity's new design platform combines everything into one app Ausbruch aus Dockercontainer Themen eAuto laden und Energienetze (follow up zur FrosCon Folge) Wikipedia: Grobe Struktur eines Stromnetzes Frische News Schuko für PV Maus: Pumpspeicherwerk DLF Forschung Aktuell — Podcast: Wasserstofferzeugung Wikipedia: Hochspannungs-Gleichstrom-Übertragung Wikipedia: Karte Offshore-Windparks in der Deutschen Bucht Wikipedia: Kleinwindkraftanlage 3D-Druck der Woche I Broke the Sound Barrier with a 3D Printed Rocket! (video) C-Hook Battery Cover Mimimi der Woche Anycubic Slicer Next für Linux nur mit “execute Shellscript from internet” welches CN schriftzeichen als Meldungen ausgibt die Installationsziele auf Ubuntu Only einschränkt im Endeffekt doch nur eine Paket-Source einträgt und via apt ein Paket installiert NixOS static ip let ext-if = "et0"; external-mac = "00:11:22:33:44:55"; external-ip6 = "2a01::2342"; external-netmask6 = "64"; in { services.udev.extraRules = '' SUBSYSTEM=="net", ATTR{address}=="${external-mac}", NAME="${ext-if}" ''; networking = { enableIPv6 = true; nat.enableIPv6 = true; interfaces."${ext-if}" = { useDHCP = true; ipv6.addresses = [{ address = external-ip6; prefixLength = external-netmask6; }]; }; defaultGateway6 = { address = external-gw6; interface = ext-if; }; nameservers = [ "1.1.1.1" ]; }; } Ab-er Finger macht kein Touch Lesefoo OpenSource Alternativen zu Cloudflare Picks thingino Severance S02 Kittysplit seized.fyi Tooling https://volta.sh/ https://github.com/Schniz/fnm https://mise.jdx.dev/ Fwupd 2.0.16 Released Mit OSS Termine buchen beim Arzt Bahnstationen in 3D-Karte

Chinchilla Squeaks
The European Open Source Academy with Lydia Pintscher and Daniel Stenberg

Chinchilla Squeaks

Play Episode Listen Later Nov 13, 2025 36:41


In this episode, I speak with Lydia Pintscher and Daniel Stenberg from the European Open Source Academy and their efforts to highlight excellence in European open source communities.100s of amazing Mac appsLooking to supercharge your Mac with 100s of apps to choose from and one low monthly price? Take a look at Setapp from MacPaw.go.chrischinchilla.com/setapp For show notes and an interactive transcript, visit chrischinchilla.com/podcast/To reach out and say hello, visit chrischinchilla.com/contact/To support the show for ad-free listening and extra content, visit chrischinchilla.com/support/ Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

OsProgramadores
E-122 (EN)-Daniel Stenberg - curl CEO

OsProgramadores

Play Episode Listen Later Oct 18, 2025 50:58


In this episode of OsProgramadores Podcast, Marcelo interviews Daniel Stenberg, the legendary creator of curl — one of the most widely used open-source tools in the world.Curl is embedded in billions of devices and powers much of the modern internet.Daniel shares his journey from his early programming days in Sweden to building and maintaining curl for over two decades, leading open-source projects like libcurl, libssh2, and c-ares. He discusses what it takes to sustain an open-source project at global scale and what motivates him to keep coding and contributing after so many years.

sweden curl daniel website daniel stenberg en daniel
Software Engineering Radio - The Podcast for Professional Software Developers
SE Radio 688: Daniel Stenberg on Removing Rust from Curl

Software Engineering Radio - The Podcast for Professional Software Developers

Play Episode Listen Later Oct 1, 2025 57:14


Daniel Stenberg, Swedish Internet protocol expert and founder and lead developer of the Curl project, speaks with SE Radio host Gavin Henry about removing Rust from Curl. They discuss why Hyper was removed from curl, why the last five percent of making it a success was difficult, what the project gained from the 5-year attempt to tackle bringing Rust into a C project, lessons learned for next time, why user support is critical, and the positive long-lasting impact this attempt had. Brought to you by IEEE Computer Society and IEEE Software magazine.

Packet Pushers - Full Podcast Feed
D2DO277: AI Security Submissions at Curl Dev

Packet Pushers - Full Podcast Feed

Play Episode Listen Later Jul 16, 2025 35:10


Curl is a widely used open source tool and library for transferring data. On today’s Day Two DevOps we talk with curl creator Daniel Stenberg. Daniel gives us a brief history of curl and where it’s used (practically everywhere). We also discuss the impact of AI on curl. Open source projects are often starved for... Read more »

Packet Pushers - Fat Pipe
D2DO277: AI Security Submissions at Curl Dev

Packet Pushers - Fat Pipe

Play Episode Listen Later Jul 16, 2025 35:10


Curl is a widely used open source tool and library for transferring data. On today’s Day Two DevOps we talk with curl creator Daniel Stenberg. Daniel gives us a brief history of curl and where it’s used (practically everywhere). We also discuss the impact of AI on curl. Open source projects are often starved for... Read more »

Day 2 Cloud
D2DO277: AI Security Submissions at Curl Dev

Day 2 Cloud

Play Episode Listen Later Jul 16, 2025 35:10


Curl is a widely used open source tool and library for transferring data. On today’s Day Two DevOps we talk with curl creator Daniel Stenberg. Daniel gives us a brief history of curl and where it’s used (practically everywhere). We also discuss the impact of AI on curl. Open source projects are often starved for... Read more »

Kodsnack
Kodsnack 651 - Klia CLI, med Patrik Svensson

Kodsnack

Play Episode Listen Later Jul 15, 2025 39:33


Fredrik snackar med Patrik Svensson om Opencli - Patriks nyskapade förslag till en standard för att beskriva kommandoradsapplikationers gränssnitt. Det borde inte vara en stor grej att publicera ett förslag till en spec för någonting. Faktum är att mycket fler borde göra det! Fler borde få hybris. Ett stort tack till Cloudnet som sponsrar vår VPS! Har du kommentarer, frågor eller tips? Vi är @kodsnack, @thieta, @krig, och @bjoreman på Mastodon, har en sida på Facebook och epostas på info@kodsnack.se om du vill skriva längre. Vi läser allt som skickas. Gillar du Kodsnack får du hemskt gärna recensera oss i iTunes! Du kan också stödja podden genom att ge oss en kaffe (eller två!) på Ko-fi, eller handla något i vår butik. Länkar Patrik Patriks röst hörs i podden Modermodemet Spectre.console Cake Opencli Spectre.console.cli Kathleen Dollard Openapi Chet Husk - PM för .net-CLI på Microsoft Typespec getopts Opencli på Github Man pages Stöd oss på Ko-fi! Aritet Podcasting 2.0-specen ID3-standarden - för att lägga metadata i mp3-filer Podcast chapters Daniel Stenberg och Curls kommandoradsflaggor Mitchell Hashimoto - grundare av Hashicorp Ghostty Titlar Om det fanns en spec Inte för mänsklig konsumtion Inte rädd för att göra bort mig Handknacka en spec Halvbakade tankar Klia CLI Det finns ju manpages Inga problem att göra bort mig En enorm, komplex best Tiotusen företag i ett företag Dialekter av CLI-applikationer -build Hela Jira-spektrat

ko ett inte mastodon fredrik fler vps curls cli gillar faktum id3 dialekter patrik svensson mitchell hashimoto daniel stenberg kodsnack cloudnet
Open Source Security Podcast
Curl vs AI with Daniel Stenberg

Open Source Security Podcast

Play Episode Listen Later May 26, 2025 34:23


Daniel Stenberg, the maintainer of Curl, discusses the increase in AI security reports that are wasting the time of maintainers. We discuss Curl's new policy of banning the bad actors while establishing some pretty sane AI usage guidelines. We chat about how this low-effort, high-impact abuse pattern is a denial-of-service attack on the curl project (and other open source projects too). The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-05-curl_vs_ai_with_daniel_stenberg/

Paul's Security Weekly
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320

Paul's Security Weekly

Play Episode Listen Later Mar 4, 2025 69:02


Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it's done that while being written in C. Daniel Stenberg talks about the challenges in dealing with appsec, the design philosophies that keep it secure, and fostering a community to create one of the most recognizable open source projects in the world. Segment Resources: https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/ https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/ https://thenewstack.io/curls-daniel-stenberg-on-securing-180000-lines-of-c-code/ Google replacing SMS with QR codes for authentication, MS pulls a VSCode extension due to red flags, threat modeling with TRAIL, threat modeling the Bybit hack, malicious models and malicious AMIs, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-320

Paul's Security Weekly TV
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320

Paul's Security Weekly TV

Play Episode Listen Later Mar 4, 2025 35:08


Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it's done that while being written in C. Daniel Stenberg talks about the challenges in dealing with appsec, the design philosophies that keep it secure, and fostering a community to create one of the most recognizable open source projects in the world. Segment Resources: https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/ https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/ https://thenewstack.io/curls-daniel-stenberg-on-securing-180000-lines-of-c-code/ Show Notes: https://securityweekly.com/asw-320

secure decades curl daniel stenberg segment resources
Application Security Weekly (Audio)
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320

Application Security Weekly (Audio)

Play Episode Listen Later Mar 4, 2025 69:02


Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it's done that while being written in C. Daniel Stenberg talks about the challenges in dealing with appsec, the design philosophies that keep it secure, and fostering a community to create one of the most recognizable open source projects in the world. Segment Resources: https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/ https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/ https://thenewstack.io/curls-daniel-stenberg-on-securing-180000-lines-of-c-code/ Google replacing SMS with QR codes for authentication, MS pulls a VSCode extension due to red flags, threat modeling with TRAIL, threat modeling the Bybit hack, malicious models and malicious AMIs, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-320

Application Security Weekly (Video)
Keeping Curl Successful and Secure Over the Decades - Daniel Stenberg - ASW #320

Application Security Weekly (Video)

Play Episode Listen Later Mar 4, 2025 35:08


Curl and libcurl are everywhere. Not only has the project maintained success for almost three decades now, but it's done that while being written in C. Daniel Stenberg talks about the challenges in dealing with appsec, the design philosophies that keep it secure, and fostering a community to create one of the most recognizable open source projects in the world. Segment Resources: https://daniel.haxx.se/blog/2025/01/23/cvss-is-dead-to-us/ https://daniel.haxx.se/blog/2024/01/02/the-i-in-llm-stands-for-intelligence/ https://thenewstack.io/curls-daniel-stenberg-on-securing-180000-lines-of-c-code/ Show Notes: https://securityweekly.com/asw-320

secure decades curl daniel stenberg segment resources
Kompilator
097 - 28 år av curl med Daniel Stenberg

Kompilator

Play Episode Listen Later Nov 6, 2024 52:24


Daniel Stenberg var en av Kompilators första gäster och gör ett återbesök för att berätta vad som har hänt under de 5 år som har hunnit förflyta. Bartek berättar om hur han reclaimade curl.se-domänen från domain squatters. Dessutom: lyssnarfrågor!The journey to a curl domain | daniel.haxx.seKodsnack 572 - Perfekt tillfälle att åka till Bryssel, med Daniel StenbergHostingen av Kompilator sponsras av Dekalfabriken

The Changelog
Where DOESN'T curl run (Friends)

The Changelog

Play Episode Listen Later Jun 21, 2024 101:27


Daniel Stenberg shares his guiding principles for BDFL'ing curl, gives us his perspective on the state of the internet, talks financial independence, ensuring curl won't be the next XZ & more!

friends curl daniel stenberg adam stacoviak bdfl jerod santo
Changelog Master Feed
Where DOESN'T curl run (Changelog & Friends #49)

Changelog Master Feed

Play Episode Listen Later Jun 21, 2024 101:27


Daniel Stenberg shares his guiding principles for BDFL'ing curl, gives us his perspective on the state of the internet, talks financial independence, ensuring curl won't be the next XZ & more!

friends curl changelog daniel stenberg adam stacoviak bdfl jerod santo
Rust in Production
Rust in Production Ep 8 - curl's Daniel Stenberg

Rust in Production

Play Episode Listen Later May 2, 2024 73:06 Transcription Available


In the season premier we talk to none other than Daniel Stenberg! We focus on integrating Rust modules in curl, their benefits, ways in which Rust and Rust crates helped improve curl, but also how curl helped those crates, and where curl is used in the official Rust toolchain. Along the way we also learn about the early history of curl and Rust, which section of your car's owner's-manual you should "re"-read, some weird HTTP edge-cases, and Daniel's experience in open-source maintainership.And don't forget: have fun!

CHAOSScast
Episode 82: The AI Conundrum: Implications for OSPOs

CHAOSScast

Play Episode Listen Later Apr 25, 2024 39:16


In this episode of CHAOSScast, host Dawn Foster brings together Matt Germonprez, Brian Proffitt, and Ashley Wolf to discuss the implications of Artificial Intelligence (AI) on Open Source Program Offices (OSPOs), including policy considerations, the potential for AI-driven contributions to create workload for maintainers, and the quality of contributions. They also touch on the use of AI internally within companies versus contributing back to the open source community, the importance of distinguishing between human and AI contributions, and the potential benefits and challenges AI introduces to open source project health and community metrics. The conversation strikes a balance between optimism for AI's benefits and caution for its governance, leaving us to ponder the future of open source in an AI-integrated world. Press download to hear more! [00:03:20] The discussion begins on the role of OSPOs in AI policy making, and Ashley emphasizes the importance of OSPOs in providing guidance on generative AI tools usage and contributions within their organizations. [00:05:17] Brian observes a conservative reflex towards AI in OSPOs, noting issues around copyright, trust, and the status of AI as not truly open source. [00:07:10] Matt inquires about aligning different policies from various organizations, like GitHub and Red Hat, with those from the Linux Foundation and Apache Software Foundation regarding generative AI. Brian speaks about Red Hat's approach to first figure out their policies before seeking alignment with others. [00:06:45] Ashley appreciates the publicly available AI policies from the Apache and Linux Foundations, noting that GitHub's policies have been informed by long-term thinking and community feedback. [00:10:34] Dawn asks about potential internal conflict for GitHub employees given different AI policies at GitHub and other organizations like CNCF and Apache. [00:12:32] Ashley and Brian talk about what they see as the benefits of AI for OSPOs, and how AI can help scale OSPO support and act as a sounding board for new ideas. [00:15:32] Matt proposes a scenario where generative AI might increase individual contributions to high-profile projects like Kubernetes for personal gain, potentially burdening maintainers. [00:18:45] Dawn mentions Daniel Stenberg of cURL who has seen an influx of low-quality issues from AI models, Ashley points out the problem of “drive-by-contributions” and spam, particularly during events like Hacktoberfest, and emphasizes the role of OSPOs in education about responsible contributions, and Brian discusses potential issues with AI contributions leading to homogenization and the increased risk of widespread security vulnerabilities. [00:22:33] Matt raises another scenario questioning if companies might use generative AI internally as an alternative to open source for smaller issues without contributing back to the community. Ashley states 92% of developers are using AI code generation tools and cautions against creating code in a vacuum, and Brian talks about Red Hat's approach. [00:27:18] Dawn discusses the impact of generative AI on companies that are primarily consumers of open source, rarely contributing back, questioning if they might start using AI to make changes instead of contributing. Brian suggests there might be a mixed impact and Ashley optimistically hopes the time saved using AI tools will be redirected to contribute back to open source. [00:29:49] Brian discusses the state of open source AI, highlighting the lack of a formal definition and ongoing efforts by the OSI and other groups to establish one, and recommends a fascinating article he read from Knowing Machines. Ashley emphasizes the importance of not misusing the term open source for AI until a formal definition is established. [00:32:42] Matt inquires how metrics can aid in adapting to AI trends in open source, like detecting AI-generated contributions. Brian talks about using signals like time zones to differentiate between corporate contributors and hobbyists, and the potential for tagging contributions from AI for clarity. [00:35:13] Ashley considers the human aspect of maintainers dealing with an influx of AI-generated contributions and what metrics could indicate a need for additional support, and she mentions the concept of the “Nebraska effect.” Value Adds (Picks) of the week: [00:36:59] Dawn's pick is seeing friends over the 4 day UK Easter holiday, playing board games, eating, and hanging out. [00:37:21] Brian's pick is traveling back home to Indiana to see his first ever total solar eclipse and bringing his NC friends along. [00:38:03] Matt's pick is reconnecting with colleagues this semester and doing talks at GSU and Syracuse. [00:38:40] Ashley's pick is going to the local nursery and acquiring some blueberry plants. Panelists: Dawn Foster Matt Germonprez Brian Proffitt Ashley Wolf Links: CHAOSS (https://chaoss.community/) CHAOSS Project X/Twitter (https://twitter.com/chaossproj?lang=en) CHAOSScast Podcast (https://podcast.chaoss.community/) podcast@chaoss.community (mailto:podcast@chaoss.community) Georg Link Website (https://georg.link/) Dawn Foster X/Twitter (https://twitter.com/geekygirldawn?lang=en) Matt Germonprez X/Twitter (https://twitter.com/germ) Brian Proffitt X/Twitter (https://twitter.com/TheTechScribe) Ashley Wolf X/Twitter (https://twitter.com/Meta_Ashley) Ashley Wolf LinkedIn (https://www.linkedin.com/in/ashleywolf/) AI-generated bug reports are becoming a big waste of time for developers (Techspot) (https://www.techspot.com/news/101440-ai-generated-bug-reports-waste-time-developers.html) Models All The Way Down- A Knowing Machines Project (https://knowingmachines.org/models-all-the-way) xkcd-Dependency (https://xkcd.com/2347/) Special Guest: Ashley Wolf.

Kodsnack
Kodsnack 572 - Perfekt tillfälle att åka till Bryssel, med Daniel Stenberg

Kodsnack

Play Episode Listen Later Mar 5, 2024 66:00


Fredrik snackar med Daniel Stenberg om konferensen FOSDEM och om utmaningarna med CVE-systemet för att dokumentera och publicera säkerhetsproblem. Fredrik har varit sugen på FOSDEM i ett par år. Daniel som är riktigt proffs berättar om hur konferensen är (skönt kaotisk, och biljettfri!), hur saker funkar, och kommer med lite tips som att kolla upp vad som händer dagarna intill konferensen och handla lunch kvart över tio på förmiddagen (eller ännu hellre bara följa med strömmen och se vad det blir). Har någon lyssnare koll på en stor samling FOSDEM-tröjor från konferensens olika år? Vi skulle jättegärna vilja se en bild på en sådan garderob! Kodsnacks spelsylt kommer tillbaka redan 9 mars, läs mer på https://itch.io/jam/spelsylt10, och häng med alla trevliga människor i kanalen #spelsylt i Kodsnacks Slack! Ett presentkort på 500 kronor och en hel massa ära står på spel! Sedan diskuterar CVE-systemet - ett system som är byggt för en värld som såg lite annorlunda ut än idag. Daniel berättar om de CVE-bekymmer som drabbat Curl och många andra projekt, och vilka problem som finns med systemet. Ett stort tack till Cloudnet som sponsrar vår VPS! Har du kommentarer, frågor eller tips? Vi är @kodsnack, @thieta, @krig, och @bjoreman på Mastodon, har en sida på Facebook och epostas på info@kodsnack.se om du vill skriva längre. Vi läser allt som skickas. Gillar du Kodsnack får du hemskt gärna recensera oss i iTunes! Du kan också stödja podden genom att ge oss en kaffe (eller två!) på Ko-fi, eller handla något i vår butik. Länkar Daniel Tidigare avsnitt med Daniel FOSDEM FOSDEM 2024 ULB MAC-adresser FOSDEM-appar SReview - FOSDEMs videosystem CCC GDB Valgrind Wolfssl - där Daniel jobbar Johan Thelin Fringe-events kring FOSDEM Homebrew Debian So you think you know git - snack från huvudspåret, av Scott Chacon Curl Software bill of materials Kodsnacks tionde spelsylt Kodsnacks Slack CVE:er Mitre CVE numbering authoroties NVD - National vulnerability database NIST - National institute of standards and technology Daniels bloggtexter om CVE-problemen Titlar Ska vi börja med åkandet? Alla fysiska FOSDEM När Bryssel är som absolut sämst Grött Grått, blött, fuktigt, och ganska kallt Perfekt tillfälle att åka till Bryssel Det finns inga biljetter Man bara dyker upp Alla byter MAC-adresser 30 separata spår Ta in en öl till Väldigt stort och ganska kaotiskt Det finns inga slipsar där Bara hänga i cafeterian Det stora spåret Större möjligheter att bara hänga En klistermärkesintensiv konferens Notoriskt dåligt med eluttag Här börjar mitt snack Man är inte helt unik när man pratar på FOSDEM FOSDEM-lådan En FOSDEM-svit Om man hittar ett säkerhetsproblem Man behöver inte bevisa att det finns en bugg Här får du en CVE Den här icke-buggen Himlen ramlar, världen brinner En 9,8-CVE “Disputed” Rejected, inte disputed Om jag bara gnäller tillräckligt högt En anonym person som har missuppfattat Knak i hela CVE-systemet

The Changelog
The I in LLM stands for intelligence

The Changelog

Play Episode Listen Later Jan 8, 2024 8:19 Transcription Available


Daniel Stenberg is frustrated with the state of AI tooling for finding security bugs, Brian Birtles is surprised by weird things engineers believe about web dev, Feross Aboukhadijeh details the fallout from a nasty npm prank, Rob Pike shares what he thinks they got right and wrong with Go & Gavin Howard writes up why he believes “all code is tech debt” is all wrong.

ai intelligence stands daniel stenberg rob pike feross aboukhadijeh jerod santo
Changelog News
The I in LLM stands for intelligence

Changelog News

Play Episode Listen Later Jan 8, 2024 8:19 Transcription Available


Daniel Stenberg is frustrated with the state of AI tooling for finding security bugs, Brian Birtles is surprised by weird things engineers believe about web dev, Feross Aboukhadijeh details the fallout from a nasty npm prank, Rob Pike shares what he thinks they got right and wrong with Go & Gavin Howard writes up why he believes “all code is tech debt” is all wrong.

ai intelligence stands daniel stenberg rob pike feross aboukhadijeh jerod santo
Changelog Master Feed
The I in LLM stands for intelligence (Changelog News #76)

Changelog Master Feed

Play Episode Listen Later Jan 8, 2024 8:19 Transcription Available


Daniel Stenberg is frustrated with the state of AI tooling for finding security bugs, Brian Birtles is surprised by weird things engineers believe about web dev, Feross Aboukhadijeh details the fallout from a nasty npm prank, Rob Pike shares what he thinks they got right and wrong with Go & Gavin Howard writes up why he believes “all code is tech debt” is all wrong.

ai intelligence stands changelog daniel stenberg rob pike feross aboukhadijeh jerod santo
Open Source Security Podcast
Episode 399 - Curl, Security, and Daniel Stenberg

Open Source Security Podcast

Play Episode Listen Later Oct 30, 2023 37:53


Josh and Kurt talk to Daniel Stenberg about curl. Daniel is the creator of curl, we chat with him about the security of curl. Daniel tells us how curl is kept secure, we learn about some of the historical reasons curl works the way it does. We hear the story about the curl CVE situation firsthand. We also touch on the importance of curating the community of a popular open source project. Show Notes Daniel's Mastodon account Curl The curl CVE blog Broken curl on PowerShell wolfSSL

Sustain
Episode 203: What's wrong with CVEs? Daniel Stenberg of cURL wants you to know

Sustain

Play Episode Listen Later Oct 13, 2023 27:43


Guests Daniel Stenberg | Dan Lorenc Panelist Richard Littauer Show Notes Today, we are switching things up and doing something new for this episode of Sustain, where we'll be talking about current events, specifically security challenges. Richard welcomes guest, Daniel Stenberg, founder, and lead developer of the cURL project. Richard and Daniel dive into the complexities of Common Vulnerabilities and Exposures (CVEs), discussing issues with how they are reported, scored, and the potential impact on open source maintainers. They also explore the difficulty of fixing the CVE system, propose short-term solutions, and address concerns about CVE-related DDOS attacks. Dan Lorenc, co-founder, and CEO of Chainguard, also joins us and offers insights into the National Vulnerability Database (NVD) and suggests ways to improve CVE quality. NDS's response is examined, and Daniel shares his frustrations and uncertainties regarding the CVE system's future. Hit download now to hear more! [00:01:00] Richard explains that they will discuss Common Vulnerabilities and Exposures (CVEs) and mentions that CVEs were launched in September 1999, briefly highlighting their purpose. He mentions receiving an email about a CVE related to the cURL project, which wasn't acknowledged by the cURL team. [00:01:50] Daniel explains that the email about the CVE was sent to the cURL library mailing list by a contributor who noticed the issue. He describes the confusion about the old bug being registered as a new CVE. discusses the process of requesting a CVE. He also mentions the National Vulnerability Database (NVD) and how it consumes and assigns severity scores to CVEs. [00:03:54] Daniel discusses the process of requesting a CVE which involves organizations like MITRE, and he mentions the National Vulnerability Database (NVD) and how it consumes and assigns severity scores to CVEs. [00:06:21] Richard asks about how NVD assigns severity scores to CVEs and specifically in the case of CVE 2020, and Daniel describes the actual bug in curl, which was a minor issue involving retry delays and not a severe security threat. [00:09:57] Richard questions who at NVD determines these scores and whether they are policy makers or coders, to which Daniel admits he has no idea and discusses his efforts to address the issue. He expresses frustration with NVD's scoring system and their lack of communication. [00:11:18] Daniel and Richard discuss their concerns about the accuracy and relevance of CVE ratings, especially in cases where those assigning scores may not fully understand the technical details of vulnerabilities. [00:14:37] We now welcome Dan Lorenc to get his point of view on this issue. Dan introduces himself and talks about his experience with the NVD, highlighting some of the issues with CVE scoring and the varying quality of CVE reports. [00:16:11] Dan mentions the problems with the CVSS scoring and the incentives for individuals to report vulnerabilities with higher scores for personal gain, leading to score inflation. Dan suggests that NVD could improve the quality of CVEs by applying more scrutiny to high-severity and widely used libraries like cURL, which could reduce the noise and waste of resources in the industry. [00:18:23] Richard presents NVD's response to their inquiry. Then, Daniel and Richard discuss NVD's response and the discrepancy between their assessment and that of open source maintainers like Daniel who believe that some CVEs are not valid security issues. [00:20:44] Richard asks if anyone offered to fund the work to fix vulnerabilities in important open source projects like cURL when a CVE is reported. Daniel replies that no such offers have been made, as most involved in the project recognize that some CVEs are not actual security problems, but rather meta problems caused by the CVE rating system. [00:21:40] Daniel explains his short-term solution of registering his own CNA (CVE Numbering Authority) to manage CVEs for his products and prevent anonymous users from filing CVEs. [00:23:04] Richard raises concerns about the potential for a CVE DDOS attack on open source, overwhelming them with a flood of CVE reports. [00:24:20] Daniel comments on the growing problem of both legitimate and invalid CVEs being reported, as security scanners increasingly scan for them. Richard reflects on the global nature of the problem, and Daniel emphasizes the importance of having a unique ID for security problems like CVEs. Links SustainOSS (https://sustainoss.org/) SustainOSS Twitter (https://twitter.com/SustainOSS?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor) SustainOSS Discourse (https://discourse.sustainoss.org/) podcast@sustainoss.org (mailto:podcast@sustainoss.org) SustainOSS Mastodon (https://mastodon.social/tags/sustainoss) Open Collective-SustainOSS (Contribute) (https://opencollective.com/sustainoss) Richard Littauer Twitter (https://twitter.com/richlitt?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor) Richard Littauer Mastodon (https://mastodon.social/@richlitt) Daniel Stenberg Twitter (https://twitter.com/bagder?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor) Daniel Stenberg Mastodon (https://mastodon.social/@bagder) Daniel Stenberg Website (https://daniel.haxx.se/) Dan Lorenc Twitter (https://twitter.com/lorenc_dan?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor) National Vulnerability Database (https://nvd.nist.gov/) CVE (https://www.cve.org/) cURL (https://curl.se/) Chainguard (https://www.chainguard.dev/) Sustain Podcast-Episode 185: Daniel Stenberg on the cURL project (https://podcast.sustainoss.org/guests/stenberg) Sustain Podcast-Episode 93: Dan Lorenc and OSS Supply Chain Security at Google (https://podcast.sustainoss.org/93) Credits Produced by Justin Dorfman (https://www.justindorfman.com) & Richard Littauer (https://www.burntfen.com/) Edited by Paul M. Bahr at Peachtree Sound (https://www.peachtreesound.com/) Show notes by DeAnn Bahr Peachtree Sound (https://www.peachtreesound.com/) Special Guests: Daniel Stenberg and Dan Lorenc.

ceo google id edited sustain ddos curl mitre cve nds cves cvss chainguard daniel stenberg nvd common vulnerabilities dan lorenc
The CLB Forge Podcast
157 | Leading a Bible Study Series Part 2

The CLB Forge Podcast

Play Episode Listen Later Aug 15, 2023 48:49


WMCLB Special Episode Karen Stenberg  interviews Michael Natale and Daniel Stenberg to talk about law and gospel in preparing a Bible Study.

Sustain
Episode 185: Daniel Stenberg on the cURL project

Sustain

Play Episode Listen Later Jun 16, 2023 37:25


Guest Daniel Stenberg Panelists Richard Littauer | Leslie Hawthorne Show Notes Hello and welcome to Sustain! The podcast where we talk about sustaining open source for the long haul. On this episode, Richard and Leslie are super excited to have as their guest, Daniel Stenberg, Lead Developer of the cURL project. Today, Daniel shares his journey of how he got involved with cURL, its development over the years, the community behind it, and funding the development. Our conversation also touches on the upcoming release of cURL, the future of cURL, Daniel's desire to grow the project, the benefits of people to collaborate with and provide support, and the role of cURL in the broader landscape of internet protocols and digital infrastructure. Press download to hear more! [00:01:24] Daniel shares the story of how he became involved with the cURL project. [00:03:55] We hear about the community behind cURL and the number of maintainers involved. He mentions having over 1,100 commit authors in the current repository. [00:05:29] The discussion shifts to funding cURL's development. He tells us for the first twenty one years he had it as a spare time project while having a separate job. [00:06:28] He explains the challenge monetizing a free software project but emphasizes the value he provides to customers in terms of support and expertise. [00:08:40] Leslie raises the topic of Daniel's positive and generous attitude despite giving away free software and not always receiving equal support in return. He explains as long as he has enough customers to sustain his work, he remains calm and relaxed. [00:11:46] Daniel discusses the development of his mindset and how he acquired a positive outlook over the past 25 years. He attributes his confidence to proven success, test cases that validate code functionality, and feedback form the large install base of cURL. [00:12:45] Richard asks Daniel about his plans for the future of cURL, and Daniel expresses a desire to expand the team and highlights the benefits of having additional people to collaborate with and provide support. [00:13:56] Leslie takes the opportunity to promote wolfSSL, the company Daniel collaborates with to support cURLS's growth and provide services to more users, and he explains why he's working with wolfSSL. [00:17:02] Richard raises the topic funding individual maintainers with the broader open source ecosystem, and Daniel acknowledges that his support contract model might not work for all projects, as it requires a certain project size, importance, and ecosystem. [00:19:04] Security issues, particularly zero-day exploit is brought up, and Daniel emphasizes the significance of security and mentions that maintaining cURL involves devoting a considerable amount of time to fixing bugs, addressing support questions, and handling security concerns. [00:20:32] We hear how cURL fits into the wider landscape of internet protocols and digital infrastructure. Daniel talks about the importance of maintaining backward compatibility in cURL, and how he sees cURL as a tool that enables users to transfer data over the internet effectively. [00:22:53] We hear about Uncurled, which is a book by Daniel. [00:24:32] Daniel tells us what many companies would rather not say, such as companies that choose not to disclose their support or donations to cURL. They prefer to remain anonymous and keep their contributions private. [00:28:02] He acknowledges that extracting significant value solely from donations can be challenging and offering support contracts provides a way to generate more revenue and provide additional value to companies. [00:29:19] What's hard for Daniel? He attributes his optimistic and positive mindset to his personality and outlook on life, but he also mentions facing struggles. [00:34:24] Find out where you can follow Daniel on the web. Quotes [00:07:35] “My biggest way in is when my customers run into a bug. So, I have this weird incentive to not do it too good.” [00:10:32] “When you've been around for a long time and you know if things go well, I can be around for a long time further as well.” [00:21:24] “We haven't done a breaking change in 16 years.” [00:30:09] “The hard part is the humans, the community, interacting with others, all the cultures, languages, and people.” Spotlight [00:35:03] Leslie's spotlight is The Swedish Internet Foundation. [00:35:47] Richard's spotlight is WC and Cat. [00:36:10] Daniel's spotlight is Valgrind. Links SustainOSS (https://sustainoss.org/) SustainOSS Twitter (https://twitter.com/SustainOSS?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor) SustainOSS Discourse (https://discourse.sustainoss.org/) podcast@sustainoss.org (mailto:podcast@sustainoss.org) SustainOSS Mastodon (https://mastodon.social/tags/sustainoss) Richard Littauer Twitter (https://twitter.com/richlitt?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor) Leslie Hawthorne Twitter (https://twitter.com/lhawthorn) Daniel Stenberg Website (https://daniel.haxx.se/) Daniel Stenberg Twitter (https://twitter.com/bagder?ref_src=twsrc%5Egoogle%7Ctwcamp%5Eserp%7Ctwgr%5Eauthor) Daniel Stenberg Mastodon (https://mastodon.social/@bagder) cURL (https://curl.se/) wolfSSL (https://www.wolfssl.com/) Uncurled (https://un.curl.dev/) Everything curl (https://everything.curl.dev/) The Swedish Internet Foundation (https://internetstiftelsen.se/en/) wc (Unix) (https://en.wikipedia.org/wiki/Wc_(Unix)) Valgrind (https://valgrind.org/) Credits Produced by Richard Littauer (https://www.burntfen.com/) Edited by Paul M. Bahr at Peachtree Sound (https://www.peachtreesound.com/) Show notes by DeAnn Bahr Peachtree Sound (https://www.peachtreesound.com/) Special Guest: Daniel Stenberg.

BSD Now
509: Dot File Naming

BSD Now

Play Episode Listen Later Jun 1, 2023 41:14


Leveraging OpenZFS to Build Your Own Storage Appliance, Install OpenBSD as a VM, Set up your own CalDAV and CardDAV servers on OpenBSD, display basic computer information using DMI table decoder, Gpart CheatSheet, Rob Pike on the Origin of Unix Dot File Names, and more NOTES This episode of BSDNow is brought to you by Tarsnap (https://www.tarsnap.com/bsdnow) and the BSDNow Patreon (https://www.patreon.com/bsdnow) Headlines OpenZFS – Leveraging OpenZFS to Build Your Own Storage Appliance (https://klarasystems.com/articles/openzfs-leveraging-openzfs-to-build-your-own-storage-appliance/) Install OpenBSD as a VM (https://byte-sized.de/linux-unix/openbsd-als-vm-installieren/#english) News Roundup Set up your own CalDAV and CardDAV servers on OpenBSD (https://dataswamp.org/~solene/2023-04-23-calendar-and-contacts-with-radicale.html) How to display basic computer information using DMI table decoder (https://sleeplessbeastie.eu/2023/03/31/how-to-display-basic-computer-information-using-dmi-table-decoder/) Gpart CheatSheet - wiping drives, partitioning, & formating (https://forums.FreeBSD.org/threads/gpart-cheatsheet-wiping-drives-partitioning-formating.45411) Rob Pike on the Origin of Unix Dot File Names (http://xahlee.info/UnixResource_dir/writ/unix_origin_of_dot_filename.html) Beastie Bits Hackerstations Mike McQuaid's clean, ergonomic setup in Edinburgh, Scotland (https://hackerstations.com/setups/mike_mcquaid/) Daniel Stenberg and the home of curl in Stockholm, Sweden (https://hackerstations.com/setups/daniel_stenberg/) viogpu(4), a VirtIO GPU driver, added to -current (http://undeadly.org/cgi?action=article;sid=20230421124221) OpenBGPD 8.0 released (http://undeadly.org/cgi?action=article;sid=20230505054214) cron(8) now supports random ranges with steps (http://undeadly.org/cgi?action=article;sid=20230507122935) malloc leak detection available in -current (http://undeadly.org/cgi?action=article;sid=20230417074903) vmd(8) moves to a multi-process model (https://www.undeadly.org/cgi?action=article;sid=20230430051250) Tarsnap This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups. Send questions, comments, show ideas/topics, or stories you want mentioned on the show to feedback@bsdnow.tv (mailto:feedback@bsdnow.tv)

Linux Action News
Linux Action News 285

Linux Action News

Play Episode Listen Later Mar 22, 2023 19:24


Nextcloud moves to the front of the pack with their new release, a moment to appreciate curl, and Amazon goes all in with Fedora. Special Guest: Brent Gervais.

The Changelog
News: New OpenAI APIs, self-hosting all the things, the Dart Frog project, curl's NuGet story & Hacker Stations

The Changelog

Play Episode Listen Later Mar 6, 2023 7:06 Transcription Available


Reorx lists awesome apps & tools using the new ChatGPT API, Ernie Smith ranks self-hosted app alternatives, Very Good Ventures brings Dart to the server, Daniel Stenberg tells curl's NuGet story & Hacker Stations showcases tech workspace setups from all over the world.

Changelog News
New OpenAI APIs, self-hosting all the things, the Dart Frog project, curl's NuGet story & Hacker Stations

Changelog News

Play Episode Listen Later Mar 6, 2023 7:06 Transcription Available


Reorx lists awesome apps & tools using the new ChatGPT API, Ernie Smith ranks self-hosted app alternatives, Very Good Ventures brings Dart to the server, Daniel Stenberg tells curl's NuGet story & Hacker Stations showcases tech workspace setups from all over the world.

project frogs hackers hosting openai apis dart stations curl nuget daniel stenberg chatgpt api ernie smith jerod santo
The Sourcegraph Podcast
Daniel Stenberg, Founder & Lead Developer of cURL

The Sourcegraph Podcast

Play Episode Listen Later Feb 14, 2023 58:51 Transcription Available


In this episode, we are honored to have Daniel Stenberg, the founder and lead developer of cURL, as our guest. cURL is a ubiquitous data transfer utility that grew into a robust library used in billions of applications worldwide. Daniel is a Swedish developer who has been involved in open source for decades. He is also the recipient of the Polhem Prize 2017 for his work on cURL. Join us as we talk to Daniel about his journey with cURL, his passion for open source, and everything in between.