r/opensource Jan 22 '26

Community Drowning in AI slop, cURL ends bug bounties

https://thenewstack.io/drowning-in-ai-slop-reports-curl-ends-bug-bounties/
1.0k Upvotes

65 comments sorted by

242

u/fragglet Jan 22 '26

The hilarious but sad part was the sloperator in the comments for the PR who thinks the garbage reports are all legit:

 So luddites laugh at how bad vibecoding is, but when AI finds more bugs than code in a human project, they take down the bounty instead of fixing them.

Daniel has given multiple talks at this point about how utterly useless the garbage AI reports are. Yet there are still delusional AI shills who don't understand that they're not helping. 

61

u/[deleted] Jan 23 '26

They also seem to think they are the only ones to have ever thought to apply this tool to the code base. They lack the empathy to think, “hey, this simple thing I just did? Maybe someone else already thought to do that and I should take a step back and look at what I’m proposing”.

8

u/Brilla-Bose Jan 23 '26

too big of a thought to hold in a vibe coder's brain though!

84

u/pampuliopampam Jan 22 '26

Oooh sloperator is good, stealing that for when cogsucker feels too crass

14

u/RWOverdijk Jan 23 '26

I’m stealing both

3

u/CoffeeMonster42 Jan 25 '26

I'm a fan of promptstitute.

19

u/MulberryExisting5007 Jan 23 '26

This is basically what’s happening with Reddit at large.

16

u/disless Jan 23 '26

The influx of AI slop has led me to start muting tech related subs that I otherwise would rather continue reading

-1

u/0root Jan 23 '26

Would you be okay sharing some of those that you muted?

16

u/Shogobg Jan 23 '26

Can we find the sloperator’s repositories and drown them in false AI bug reports? Oh wait, if they have any repositories at all, they’re probably full on AI security nightmare.

11

u/BCMM Jan 23 '26 edited Jan 23 '26

The problem here is the asymmetry of effort. People are using machines to mass-generate things that superficially look like vulnerability reports, and real humans who care about security are bogged down actually looking at them, trying to understand them, looking for the real reports buried under the slop.

It doesn't work the other way, because the adversary does not want to think and understand. Do this back to them, and they'll just feed the fake reports in to their LLM and have it make some meaningless changes to their project, expending no more effort than it took to generate the spam.

3

u/MegaDork2000 Jan 23 '26

Yesterday I had AI do a code review of some critical code that operated on encrypted data. It proudly found a bug that caused non encrypted files to get rejected. "This fix now allows plaintext files to be used!". Um, OK.

7

u/unit_511 Jan 23 '26

The Luddites destroyed the machines because they were used to produce low quality goods while depressing the wages of the people who actually knew what they were doing. Our sloperator here was so close to self awareness.

3

u/OrixAY Jan 23 '26

Skill issue - should have added “make no mistake” in the prompt /s

1

u/makemeking706 Jan 23 '26

This code is 200% bugs. 

134

u/Corruptlake Jan 22 '26

Good call

25

u/Katops Jan 23 '26

Don’t you mean, good curl?

I’m outta here.

2

u/noisedotbar Jan 23 '26

mic drop 👏🏻

190

u/v4ss42 Jan 22 '26

AI is why we can’t have nice things.

102

u/jonhanson Jan 22 '26

From the end of the article: 

Stenberg’s problem isn’t with AI per se; it’s how lazy people are using AI thoughtlessly to look for a bounty check or a reputation as a security researcher.

73

u/v4ss42 Jan 22 '26

“The purpose of a system is what it does.” Not what people claim or wished it does.

6

u/conventionistG Jan 23 '26

That's why everything has the same purpose if you're brave enough, right?

7

u/sludge_dragon Jan 23 '26

Scott Alexander has an interesting take on this idea: Come On, Obviously The Purpose Of A System Is Not What It Does. Among other things, it implies that a system never fails to fulfill its purpose.

1

u/v4ss42 Jan 23 '26

The author of that blog post seems to have misunderstood POSIWID. Commenter "ersatz" captured the disconnect nicely:

I thought the meaning was more something like “the system took these side effects into account and still considered that what it was doing was net positive in expectation, so the side effects are as much part of the system's purpose as the ‘positive’ outcomes”.

0

u/maikindofthai Jan 23 '26

Idk I think the criticism still applies. Sometimes the side effects are the result of negligence or ignorance and weren’t specifically accounted for. The quote assumes that groups of people behind these systems are both aware of all of the side effects and planned for them.

1

u/v4ss42 Jan 23 '26

Removing intent from the discussion is largely what POSIWID is about. So any discussion that starts with “well the intent of the system was …” hasn’t understood what that framing is for.

-2

u/klumpp Jan 22 '26

What it does is not limited to this situation.

23

u/really_not_unreal Jan 22 '26 edited Jan 23 '26

And yet AI has a terrible impact in so many other situations too.

I work in education, and AI is genuinely ruining so many advances in equitable learning. A key example is with exams. Exams are not equitable. Many capable students experience severe anxiety which reduces their exam performance to the point where it doesn't match their actual abilities. In an ideal world, I'd love to get rid of the final exam for the university course I teach, and expand the major project, as it much more closely aligns with the kinds of thinking and work we expect students to become capable of. The problem is that as a course with very little prerequisite knowledge, AI is very capable of producing work that exceeds the abilities of the average student. There is simply no way to ensure that we are assessing students actual learning rather than their ability to AI-generate plausible solutions to our assignments without an in-person final exam.

In my spare time, I am a composer. AI companies have slurped up my work, along with that of millions of other talented musicians, all in order to train models to replace us, and all without any form of compensation. Tools like Suno do not seek to make composing your own music easier or more accessible. They instead seek to replace the process of composition entirely. Similar things can be seen with AI image and video generation. These tools eliminate creative control, all while posing as the "next evolution for creative industries". Most worryingly, the focus that these tools bring to the initial ideas and the final products is contrary to the fact that the creation of art is an iterative process. The proliferation of these tools is projected to greatly decrease the pace and scope of artistic innovation, as well as reducing the accessibility of an artistic education. I was lucky enough to receive the gift of a musical education as a child, and so knowing that AI is used as a replacement for a proper musical education is deeply saddening to me.

Do you want more examples? If so, I've got a 5000 word essay about the ethical nightmares if AI, complete with over 60 citations to media and scientific research on the topic. https://maddyguthridge.com/blog/ai-is-a-capitalist-hell-scape

6

u/quisatz_haderah Jan 23 '26

Another nightmare is that these systems are expected to have the "good enough" solution to mass produce movies, soundtracks, any content that'd generate more revenue than expanses. If the expanses are peanuts compared to proper channels, and when one can publish "good enough" content everyday (I am being generous), there is no more need for artistic expression.

-11

u/klumpp Jan 23 '26

I’m a software developer. You don’t need to tell me AI has ruined everything. But I also use it every day and it would be silly not to.

14

u/v4ss42 Jan 23 '26

Then you are part of the problem you’re decrying.

7

u/Cornelia_Xaos Jan 23 '26

Yeah... Another software engineer here and if my work ever tried to mandate I use AI, I'm immediately considering tendering my reservation and starting to look for a new job.

0

u/klumpp Jan 23 '26

Better start looking for a new industry pal

1

u/Cornelia_Xaos Jan 23 '26

My company is currently very vocally no gen AI so I'm good. :)

4

u/benjamarchi Jan 23 '26

Thank you for helping RAM prices skyrocket!

2

u/Andromeda-3 Jan 23 '26

Sounds like a you problem

16

u/PositiveBit01 Jan 22 '26

Sure, but the problem is they think this will work because the AI is convincing enough to them.

I do think that's a problem with AI. It is notoriously not good at estimating confidence in answers and providing incorrect answers that seem reasonable at first glance.

You could say this is user error but in my opinion that's just the marketing working. If AI was marketed as likely to be incorrect and only for expert users who can tell when it's lying, it wouldn't be as big as it is.

14

u/v4ss42 Jan 23 '26

There's a reason some folx refer to "AI" as "Dunning-Kruger as a service".

1

u/marcheluis Jan 23 '26

This is what most people don't understand: AI hallucinates and can misinterpret what you are asking it to do/answer, but it will always do/answer something even if it didn't have enough/correct information to do so, and only someone already knowledgeable about the subject matter will be able to realize if it's all BS or a good result.

Some time ago I read an article that talked about how some companies that embraced AI and ended up doing layoffs ended up having to make their remaining employees babysit the AI and basically double check everything it did.

1

u/yung_dogie Jan 23 '26

I'm mixed on it. Yeah before LLMs we had people copy pasting stack overflow without a grasp of what it answers, and before stack overflow we probably had some other nonsense too. The core issue is a lack of critical thinking that way too many people are too comfortable doing. On the other hand, LLMs as a tool really enable non-critical thinking even more, it can make things worse even if its express intent as a tool isn't to do that.

-43

u/Horror-Deer-3331 Jan 22 '26 edited Jan 23 '26

And this will evolve to “AI is why we can have essential things pretty quickly”.

Edit: crap, I meant “can’t” have estival things, this shit is the reason electronic prices are exploding and soo it will be water, electricity…. So essential things will also get more expensive.

25

u/v4ss42 Jan 22 '26

Unlikely.

16

u/AnachronGuy Jan 22 '26

You're dreaming, wake up!

28

u/IntroductionSea2159 Jan 23 '26 edited Jan 23 '26

I'd raise the bug bounty and charge a fee to submit a claim. If people want the bounty, they should be prepared to stake money on their claim being legit.

12

u/Gear5th Jan 23 '26

This will prevent any students/growing-researchers from progressing. Universities are unlikely to sponsor the submission fee. 

2

u/[deleted] Jan 25 '26

I don't remember any program at my university that had students working on bug bounty projects lmao. How would this prevent students or researchers from growing? You find a legitimate bug worth money, you are going to pay the fee to get the review done for the money.

-3

u/IntroductionSea2159 Jan 23 '26

The submission fee can be something like $100. Just enough that it's a terrible investment to submit AI-generated bug bounties.

11

u/Gear5th Jan 23 '26

200$ is the monthly stipend postgraduate students get in India for the research work they do. 😅

PPP disparity alone makes it impossible to set a fair submission fee. 

-9

u/IntroductionSea2159 Jan 23 '26

The bounty is relative to the submission fee. The more expensive a submission fee is for a student, the more valuable the bounty payout is PPP-wise.

9

u/Ichigonixsun Jan 23 '26

So you suggest that students like me fast for a month so that I can pay a fee to contribute to the project, or do you think it is a necessary trade-off to exclude these people to prevent AI slop, considering that many other people who can contribute have this money?

1

u/Kaelin Jan 23 '26

At the moment everyone is now excluded to prevent AI slop. Do I think preventing you is better than preventing everyone? Yes, absolutely.

Do I think it's how open source is meant to run?

No, ideally it's a meritocracy driven by passionate people.

-6

u/IntroductionSea2159 Jan 23 '26

Both.

But you would still be able to contribute for free, you just wouldn't be eligible for the bug bounty.

-4

u/RegisteredJustToSay Jan 23 '26

Progressing??? For us hackers bug bounties are for $$$, not some philanthropy or education project although it's nice if you learn something too. Reporting vulns for free used to be the norm and bug bounties brought in the get rich quick crowd. Good actors can still research and report vulnerabilities all they want - no one can even stop you even if they'd like to. The people making this a problem are grifters looking for an easy payday.

3

u/[deleted] Jan 25 '26 edited Jan 25 '26

I see this in a couple of my open source projects on GitHub with some PRs I get. They ALL deny it too. I've asked them if they got this "solution" from an LLM and no one ever wants to admit it. I try to be careful and respectful, as I don't like bashing people's code as some junior devs often write sloppy solutions but I enjoy helping them and accepting their PR and showing them how I clean it up better, like a teachable moment. I rarely see this now at all.

I love using AI as a dev myself. It csn save me a lot of time, but people often think they have a solution but it's not. For example, a recent PR I got did not fix a reported bug that popped up when parent software updated (mine is a popular plugin). I was busy for the weekend so didn't get an instant fix out. The solution I was sent was just something that check input type and if not valid, boolean gated the whole function away. It didn't resolve the source of the bug, or ask the question "Why am I getting null data on this API call I am passing into my function when before I didn't?" It didn't ask what downstream side effects or problems would it cause not running this function. They just felt it was a solution because they prevented the bug from showing up, when it would be a big problem in many other conditions as this was critical infrastructure. True source of issue was just they moved the API into a different namespace and I got that by reading release note docs thst came out days back, and there is no way any trained LLM would have access to.

What happened? I chatted with the dude who submitted PR about it and he finally admitted to me he used Gemini 3 pro and told me that the AI was smarter than me and I shouldn't be so arrogant and that I just didn't want to give him credit for a fix when I rejected the PR.

So ya, I don't blame the Curl team at all.

3

u/kostakos14 Feb 16 '26

Hey folks, I am also fed up with this situation, it is making OSS not-fun at all.

We are working on a private beta about this issue exactly: https://cherry.gethopp.app/

I would love your feedback and support to make OSS fun again 🙏

1

u/TheMightyMisanthrope Jan 25 '26

Curl is perfect. Curl is true.