“I will slaughter you”
daniel.haxx.se
daniel.haxx.se
I'm not sure whether this person is actually responsible for a multi-million dollar defense project, but if he really was, it's probably a good thing he lost the deal because I definitely don't want that kind of person managing such a project.
> I lost my family, my country my friends, my home and 6 years of work trying to build a better place for posterity.
I get loosing your family / home / friends, but a country? Where did that go?
A mundane class is offered with impractical advice and they're left with no money, little skills, and spamming the internet trying to get "their contract" - and if it doesn't materialize and they go back to the boot camp to complain the scammers blame it on "curl" - see the haxx.se domain? Clearly a hax0r ruined your chance at a better life.
Not sure what caused the original email, but the reply is just a copy/paste of various unrelated things and security incidents that the person Googled without even understanding enough about them to form a comprehensible narrative.
Which tells me they are simply trying to get a rise out of someone.
The way the grammar is constructed I would not be surprised if this came from a pre-teen.
Suggests he doesn't even comprehend that curl amounts to 'instructions to copy data'
So the ad is from this Al guy.
Gov contracting is an ecosystem on its own and those that figure out the bureaucratic hoops can survive a long time without needed much technical knowledge. Some of those individuals lose touch with what is going on outside of the defense industrial base.
I think its the opposite, I think its an unqualified contractor writing code he doesn't understand for complex systems and was subsequently hacked. I see this a lot with people bidding on contracts then hiring staff/developers after it's awarded to duct tape a system together that barely works and is full of holes.
An article was shared here a while ago that went into that as well: https://tim.blog/2020/02/02/reasons-to-not-become-famous/
(Discussion: https://news.ycombinator.com/item?id=22280753)
I would take this threat very seriously.
Two words went through my head reading the response. "Crystal Meth".
Likely not, really, but having more-or-less lost an old friend to meth I can't help but compare the similarities (... the "identicalities" actually):
- the desperation and paranoia
- a solid (but wildly misplaced) basis in reality
- the overwhelming externalization of blame
- the need to lash out and draw someone else in
- the completely nonsensical evidence
Bottom line is regardless of the reason, "Al" is extremely unstable. I agree that the lesson here is to not engage these types.
can you explain this more ? I recognize some traits of these in me and siblings but we're not on meth at all.. so I find the psychological flaws interesting.
sorry about your friend too
The pattern is that in these scenarios, usually the people are quite intelligent and often accomplished. This gives them a repository of valid phrases and concepts to draw upon to breath legitimacy into their boogeymen. The evidence they present, however, is completely benign. That person, however, has quite the story they think is proven. It's literally as if they're showing you a basic electronic device w/ the cover removed and that proves all sorts of maliciousness.
Attempting to argue back is completely ineffective and even if you "win" one point, they'll quickly shift to another and nothing sticks, especially not the next time you talk to them.
I wouldn't even remotely compare this to more commonly contested topics like differing religious/political/social views, even at the extreme. This involves a visceral fear that >you< are actively being attacked, not some nefarious, shadow with a grand plan.
I have a very clear idea of what spectrum we're talking about here, but maybe it's better left unspecified to not influence too much (:
Seem like the average person to me :)
I assure you, you will quickly understand the difference.
Especially if that someone is your previously un-diagnosed friend and business partner.
His name often shows up in the licensing disclosures/attributions of applications that include curl.
The general opaqueness of modern software leads people to latch onto him and his email for all manner of things, and for non developers to attribute to him all sorts of bad motives ("You hacked me!").
This is especially unfortunate as Daniel has been such a genuinely positive and helpful face to a popular open source project. I feel awful that his generosity gets repaid with this kind of crap.
Weird that people spend each day on Facebook and Reddit among unhinged bozos, and still fail to realize how it might not be the best idea to spam their name and location on the web for all to see.
I can't agree more, Daniel is one of the friendliest approachable maintainers out there. Several times he takes time to answer menial questions and is friendly about it. I recommend the curl mailing list if you work with it in any manner as for you will learn a lot from other people.
It's really best to not reply to the mentally ill people (and you can be pretty sure anyone sending something like the first is at least temporarily mentally ill).
It can sometimes be extremely tempting, I know-- especially when they've managed to say something almost perfectly constructed for pithy comeback. But it will not help you and it will not help them. If it does anything it will just encourage the behavior.
If it is any consolation lots of other people receive nasty kookmail messages -- I know first hand, in addition to the ones I get directly some of the kooks like to send massive carbon copy blasts-- as a result I have a bunch of very strange mail rules, like discarding any email that copies both a whitehouse.gov email address and Jeff Bezos, or another if both George Soros and Noam Chomsky are copied.
It was pretty close to: https://web.archive.org/web/20150506055228/http://www.timecu...
Another good time was when I was running a crypto meetup and we had to call the cops because someone came in naked, the CIA had put chips in their clothes and they had to burn their house down so they weren't homeless but on the run.
Then there was the time I was on the board of a hacker space: https://shitnoisebridgesays.tumblr.com/page/3 it wasn't noise bridge but it had the same vibe.
This is not directed at you specifically, but your comment got me wondering how many people contact individuals like Daniel who are behind Open Source projects like this to share positive feedback, or even just to say "Thank you." I know I've not done it anywhere near as much as I should, and I suspect that doing so would help take the edge of what can often feel like a thankless task.
I imagine it's a bit like reviews: people with a bad experience are more likely to leave a review. Perhaps the best way to help people like David is to stop once in a while and thank them for the things they've done.
Open-source developers occasionally express dislike of "thank you" messages. They may have written that software mainly to scratch their own itch, and dealing with messages that don't say anything but thanks takes precious time out of their day. Donating money, however, is usually more welcome.
No open source maintainer is so busy that they don't have the time to respond to a ever so rare genuine thank you with a "Thanks, glad you appreciate it!".
One can send thanks along with "No response expected or required!" :)
I also happen to maintain a little "Secret Santa" website, hosted on a GitHub page. Nothing too fancy, just a static app that lets you manage a Secret Santa without creating accounts. Well, every year, I receive 3-4 emails thanking me for creating it, which is even more surprising considering they often come from people that aren't from the tech world at all.
Perhaps for my happiness I should invest more in this side project than in a package manager used across the globe :)
This IMO is the best way to deal with a lot of emails. I have some public software that is literally innocuous, and yet occasionally I get some very angry emails. An example: a small game where people think the game/computer is cheating (it's not).
If someone fires off an angry, irrational email to you, they aren't looking for a rational response - they are looking for a debate, or a fight, or an outlet. It's best to let them move on.
Thanks everyone for the positiveness and expression of appreciation I've sensed here. The threat has been reported to the police and I'll move on. I love you all. Now I'll go back and continue working on curl.
Indeed. But one shouldn't underestimate the chance that this wouldn't be the first report about this person. Lots of similar reports like this may actually cause them to do something.
It ended up with a broken back wheel (she kicked it) and a damaged phone (she took it out of my hand when I wanted to take a picture of the license plate and threw it on the ground).
She was clearly unhinged, but I was stupid as well. I should of just let it go; no one who starts a social interaction with "pissy little cunt" is likely to be calmed down by reason. You have nothing to gain from trying, and much to potentially lose.
That said, I think the real lesson for you is: don't make yourself more vulnerable (e.g. letting her touch you or your stuff) if you decide to try to start a conversation!
It also points to a theory I've been considering about personhood, and how people like your driver lady is in a mindstate where, in her mind, you're not a person. It's a very, very dangerous situation, because if they don't think you're a person, then there is nothing immoral about saying or doing anything to you, including violence.
I didn't "let" her, she just did it.
I know you mean well and that you probably didn't intend it like this, but this comment comes off as victim blaming quite a bit.
As for the rest: thus far I've never managed to talk random strangers down from these kind of rages; but maybe I just don't have the charm shrug Last time I tried was with my neighbour and he ended up calling the police three times over a four-day period on me. My crime? I kindly asked him to not play his music so loudly all day long at the start of the lockdown (especially at 7am) and not backing down when he tried to shout me away. I had "invaded his home" by knocking on his front door... This isn't a fit of anger, some people are just like this.
Because the earlier interaction I mentioned went sideways (including, among other things, her literally getting within 4 inches of my face while she was not wearing a mask), I decided to video record this most recent interaction on my phone so I would have evidence if anything went wrong that I could take to the landlord. I knew this would create an inherently more antagonistic vibe, but I felt like I had no choice after the prior incident.
Let's just say this interaction also went bad, culminating in a very minor physical assault (I was not injured -- she slapped the hand I was holding my phone in, because she did not like the fact I was recording), and a restraining order.
End of story, right?
Wrong. That restraining order, it was taken out by her against me. Her petition filing is literally nothing but gaslighting trying to paint me as the aggressor when I literally have video evidence to the contrary.
Unfortunately, due to COVID shenanigans, the court date was delayed a couple of times, and I ended up not being served notice of the actual hearing, which means I lost in a default judgement. I filed a motion to terminate her restraining order and a counter petition of my own, both of which I am currently waiting on a hearing for.
And, like your situation, because it was a neighbor, and because I have to walk past her door to get to and from my apartment, I simply don't have the choice to not interact with this person. Basically anything I could have done would be a lose / lose. Rock, meet hard place, I guess. Le sigh.
As for your neighbor, yes, it sounds like he's a crazy person. And the lockdown has taken even moderately crazy people and pushed them over the edge!
There are some people who will try to bully their way through life. They will apply violent behavior (e.g. breaking your phone) to get their way. The way to stop that is to make it clear that you can apply violence, too.
Most of society works by peacefully interacting with each other. But it is crucial that everyone knows that there is a threat of violence (e.g. the police) to keep everyday life peaceful.
I wonder if I am just imagining it, but I took martial arts lessons as a kid. I've always felt like just the knowledge that I could fight has caused others to deescalate and be respectful.
Please do not give terrible advice that will kill people.
So, yes, I agree with you somewhat, but I think the balance of consequences tends to favor not acting in cases like this rather than attempting to do anything.
There's a name for this incident - "road rage". Very real and dangerous indeed.
People get completely irrational and agitated. Probably due to effect of being locked up, in a way, non-free inside their cars.
When I'm biking, at times I too get mad at some careless and obnoxious drivers encroaching my freedom, I guess they may be finding me just as annoying for simply missing the fatter wheels and a comparable scale on the shared road. Irrational!
As cyclists we are literally more exposed on the road. So whenever such inevitable bout of irrational fury pops, I find the safest option for myself is to steam-off using similar vocabulary. It's more efficient than reasoning with the unreasonable.
Just to be even safer, I'd let the offending four-wheeled furia be gone before naming the whole piece of that motorized content in precisely spoken choice of words...
It takes practice though. Be safe!
The $15k figure implies that's either a bill the hackers ran up on an AWS instance or what they valued their development at
Edit: The blackmail line sounds like a ransomware attack
If you read the follow-up emails - and apologies for the armchair psychiatry - I think this person is very likely in a psychotic state. Their messages sound very similar to what you find in the "BadBIOS" and other "gangstalking" communities. It's not really tethered to reality.
I think it's extremely likely the author is not a troll and possesses a sincere and high-confidence belief that powerful entities are tracking and persecuting him and that backdoors in lots of software, including curl, were placed by sinister organizations and used to facilitate spying on and attacking him. The software is perceived as a WMD or pathogen partly responsible for this incursion into his life and the damage he thinks has resulted. He's mad because he thinks Daniel is like the mayor of Flint, MI: the water is poisoning people and he's doing absolutely nothing about it. Of course you'd be angry!
This is why it's generally best to not reply to messages as extreme as these. Daniel will never be able to convince him he isn't actually the metaphorical Flint mayor. You just get sucked into a world that's very real to them and not real to you or almost anyone else. It's not possible and not a good idea to try to reason with someone like that.
Although in that case the city was not actually hacked. It looks like this person actually got hacked by someone using curl and he is complaining that curl made it possible. I wonder if he knows anything about the people who wrote the actual exploit(s).
Health issues are a thing that happens to people, and they don't have control over it, which absolves them from responsibility for it. OTOH if the guy making these threats is just pissed off due to his own failures, or even is just a troll making it all up, he should be held responsible for his actions.
I've interacted with a few people with psychotic illness over the years (both in-real-life and online) and the distinctive language style is rather hard to miss.
I'm not implying we shouldn't hold trolls responsible when they know better. From an outside perspective it would suck to have a brain that releases dopamine when causing others to suffer.
From the letter, it sounds like this guy had his life ruined, and upon investigating the hacker tools used to ruin his project and life, he jumped on the name that appeared the most in the source code.
The screenshots would have been an "I know it's you" message to him, which the sender would assume is more than enough to let him know the meaning of his email. And indeed, if Daniel had been writing haxx0r tools, the message and intent would have been crystal clear.
At this point the sender would be assuming that Daniel is just playing games with him and playing dumb, so he's pouring out his story to shame Daniel over the damage that his hacker tool has done.
If someone were to write tools specifically for evil purposes, and your life were ruined by use of said tools, you'd be screaming mad, too. And probably seeking revenge.
Except that his investigation was sloppy and incomplete; Daniel doesn't write hacker tools, he writes a HTTP client library. He's no more guilty of facilitating hacking than the writer of any runtime library's HTTP client code.
Normally, this would be a matter of setting the facts straight, but in this case a criminal investigation would probably be in order.
And anytime such unrealistic threats are made, this always makes it seem like maybe it's not so bad:
(One of these days I'm going to cut you into little pieces, by Pink Floyd)
Encryption has a sort of brutal effectiveness at doing this if you distribute copies of your data, but it is hard to maintain and has exposure in extreme events with your health.
Encryption + distributed data + legal protections from counsel could be an offering. It might be a "big fish" service though.
Though the domain probably doesn’t help with the association. If you got hacked and the first clear string you find is “haxx.se” it’s not a big leap to interpret it as a taunt.
Not picking on you specifically, just musing, btw
Either it's scary and get law enforcement involved or it's not and we're gawking and laughing at someone at their worst moment.
In an attempt to take this post at its most charitable I agree, it fucking sucks there's not enough focus on mental health in the world.
I agree, there was no need to include names in the article.
[0] https://tim.blog/2020/02/02/reasons-to-not-become-famous/
But, quite frankly, I'd go to the police immediately.
Daniel is clearly smart, but he's not thinking big enough. This is practically inter-galactic.
That comment made me think and I realized the following.
Open-source code like curl is inevitable when a society gains internet [1]. It's not Daniel's fault. If anything is to blame, blame the internet and human nature on a grand scale [2].
[1] If he wouldn't have made it, someone else would. If no one else would, then people would've done it privately. Some of that code would've been leaked and popularized as an open source project (it's basic probability: many people would need to do it privately, since they have to if they want their CLI to interact with the web).
[2] There was an interview I read/heard somewhere where some Twitter employee said: if there is a 1 in a 500 million chance that something could happen based on a small piece of text, it means that at Twitter, it happens every day.
On the matter of "inevitability of progress": yep, I even think it applies to much bigger extent. I just don't see how is this connected to the troubles of the-victim-of-curl guy.
> but I struggle to think of situation where curl would have been an actual culrprit.
I agree, I think it's much more likely that there was a 2 stage type of exploit where curl was used to download the second stage locally on the machine. That's at least how curl (or wget) is used on hackthebox.eu (where everyone hacks boxes for fun).
> if there is a 1 in a 500 million chance that something could happen based on a small piece of text, it means that at Twitter, it happens every day.
really interesting, do you remember what interview/who the employee was or anything?
> You built a formula 1 race car and tossed the keys to kids with ego problems.
He may have been ran over by a formula 1 race car, but for some reason he ended up writing to and blaming the guy that's building the seats. Or the tires.
Curl is an ubiquitous tool used for pretty much anything. Assuming the grievance is real, blaming it for anything is clearly a misunderstanding of the situation.
Maybe, but there's maybe an alternate universe that doesn't begin with such a dumbass implementation of the web.
"Excuse me everybody, how about we not make it common for clients to describe themselves with a simple plaintext string and not have servers expect to blithely log that same string as if the invention of packet switching predates the invention of lying."
Perhaps ours is the only universe where the grad student who was supposed to utter that missed the bus that day.
Thank you, Daniel, for creating it and all the volunteers who maintain and improve it.
I donated some time ago to the project here: https://curl.haxx.se/donation.html
I encourage everyone who used it to do the same.
Don't let the crazies get to you.
Either the person is just a crank and in that case no harm done, or the person has legitimately been affected by an exploit and at the very least it will inform them of what actually happened and how Curl isn't to blame at all.
Of course this has nothing to do with curl or any other software, one can only get hacked because of their ineptitude.
What does any of the listed software have to do with curl? You might as well attack GET and POST.
And in the middle of a violent rant, he also gives a backhanded compliment - "Formula 1 racecar" - that's the part I agree with.
We already have wget by the way.
A lot of love to you Daniel if you read this and thanks for Curl!
* In this case there is no way to comfirm if the sender/s are mentally ill because all you have is inference to play against the words written and the images sent to Daniel.
I use free and open source software everyday in my products and I am fully aware that all of them have licenses specifically telling me that there is no warranty or liability of damages. If something goes wrong, it's on me, I made a wrong choice and I have to deal with the consequences.
And threats are not okay and should be reported to the authorities.
For example, in this case, I would minimally identify and locate the individual responsible for the email. I think that is doable.
But oh god, it's not exactly a technical argument.
But that bears no obvious relation whatsoever to "multi-million dollar defense project".
Right there, we know this is stream-of-consciousness fiction generated by someone who is mentally ill.
Although I condemn Al Nocai's method, I feel for him and I am inclined to adopt the contrarian opinion that he probably got screwed because of the bad quality of curl.
Curl had some remote exploit last year, and curl is used everywhere as the author reminds (often as libcurl). https://daniel.haxx.se/blog/2020/02/03/remote-exploiting-cur...
The deeper underlying systemic problem is that open-source is a way to disclaim all responsibilities. When some open-source project has some level of reach there needs to be quality requirements and regular security audits. (like they (last?) did in 2016, https://daniel.haxx.se/blog/2016/11/23/curl-security-audit/)
Otherwise it's like the OpenSSL's heartbleed story where a few unpaid project maintainers hold the keys to the world.
In today's interdependent world, when trying to build something, we are more and more reliant on the quality of the library we use. As a product builder facing the client you get to bear the responsibility when your client has a problem because of a library you use. But when open-source software removed the possibility of competing solutions by providing free "as is" software, you can't realistically chose not to use it, and you are the one left holding the bag and paying the price for others mistakes.
I think the key question with that is: It all sounds nice, but who is realistically going to pay for it. _especially_ repeatedly.
If no one wants to pay for it to have the required quality, why not make it a public utility properly funded by tax, as a public service ; instead of later paying the costs in various form of the consequences of the vulnerabilities.
The code is available to anyone to look for such bugs, even the kids with ego problems (aka the hackers). Hackers like curl because it's a nice tool that indeed help them a lot.
Everyone uses curl, willingly or not, embedded by another library which needs some network protocol. Pass a filename that starts with "protocol://... " to any buggy program that will try to open it, and then one branch somewhere inside libcurl will get called. If you give the right magic string, you get a remote shell.
I laughed. Curl: The Formula 1 race car of command line tools!
Aside from that, I am surprised that the harasser followed up in a mostly non-violent way. I expected an absolute troll. Sadly in fact it seems the harasser is in need of psychiatric attention.
But, yeah, the domain itself obviously doesn't help the matter.
Sounds like a mental health crisis or a sick joke. Either way, whoever was behind it didn't accomplish anything.
There can be situations where tools get inappropriately placed as critical infrastructure that are developed as hobbies by people with hobbyist-shrug attitudes, but this wouldn't be a constructive way to address it. Blame or personal attacks don't make improvements.
> JS Stochastic templating utilizing comparison expressions to write to data registers
This has zero meaning? I can't even guess what it might be?
> I lost over $15k in prototyping alone from bullshit rooting to the charge arbitrators.
"charge arbitrators" is not a thing. It's normally verb, noun. Not adjective, noun.
I'd almost go a nasty GPT-2/GPT-3. There's complexity but no links, this is 3 unrelated things - "Multiple Sigover attack vectors utilizing favicon XML injection"
Posting this is just an open invitation for people to send you more threats.
The person saw some exploit with curl headers, which damaged their life. That's upsetting, even if the email is misdirected, because Daniel just provided the infrastructure, and did not cause the specific abuse. What is wrong is the threat to life.
The second thing that is wrong is to respond to the second email by doxxing the author to the public. The second email showed that the threat was likely not specific and immanent, but venting. A reasonable response would be to notify the police. Or to reveal this case to the public explaining why this is misdirected, but without the author's name.
What evidence do you have for this?
This liability could've been mitigated to some degree by having a more innocuous sounding domain name. Having it as is, given enough time and thanks to the tremendous popularity of libcurl/curl someone somewhere is going to jump to conclusions that Daniel is responsible for making this "race car" hacking tool that script kiddies are now using to wreck his life.
Stalman has failed culturally, distance yourself from the "hacking" culture of the past if you care about your marketability and reputation.