HNHacker News
TopNewBestAskShowJobs

bagder

861 karma · joined September 2, 2014

Daniel Stenberg.

Software and protocols for fun and profit. I run the curl project.

https://daniel.haxx.se/

submissionscomments
bagder··on Aisle Discovers 6 New CVEs in Curl, Including the Oldest Issue Ever Reported
I already offered the following comments on Aisle

"my experience from working with them on and off for many months now is nothing but good. Skilled, professional engineers without any bureaucracy. They know their stuff, and they've been very good at listening in and adjusting for our needs and wants."

Who am I? I'm Daniel, curl lead developer.

https://mastodon.social/@bagder/116807425534711479

bagder··on Curl is just the hobby
vodafone has been blocking my site daniel.haxx.se for several years.

Discussed on this very site for example back in 2022: https://news.ycombinator.com/item?id=31248250

bagder··on Deleting System32\curl.exe
Vodafone... https://daniel.haxx.se/blog/2022/05/02/considered-18/
bagder··on Increased CVE Activity in Curl?
I only record the introduction commit for security flaws as they are rare and important enough to give that level of attention. And that's not a mandatory or required step in our process, I do it mostly as a service for users and to satisfy my own curiosity.

Our process for handling security problems in curl is documented here: https://curl.se/dev/secprocess.html

bagder··on Increased CVE Activity in Curl?
The author (me) did get a visa, after a mere 937 days: https://daniel.haxx.se/blog/2020/11/09/a-us-visa-in-937-days...
bagder··on The QUIC API OpenSSL will not provide
That's fairly inaccurate. QuicTLS is pretty much exactly what we're all waiting for. That is OpenSSL + PR8797.
bagder··on “I will slaughter you”
Daniel here.

Thanks everyone for the positiveness and expression of appreciation I've sensed here. The threat has been reported to the police and I'll move on. I love you all. Now I'll go back and continue working on curl.

bagder··on Daniel Stenberg's (badger) Twitter account seems to have been compromised
Account restored!
bagder··on Daniel Stenberg's (badger) Twitter account seems to have been compromised
While I am disconnected from twitter, you can always reach me at:

Mastodon: @bagder@mastodon.social

Keybase: https://keybase.io/bagder

IRC: #curl on freenode

Email: daniel@haxx.se

website: https://daniel.haxx.se/

bagder··on Daniel Stenberg's (badger) Twitter account seems to have been compromised
I rather refrain from speculating as I truly have no idea! As I describe in my blog post, I just got an email saying "someone" had logged into my account from a new device and then I was kicked out (as that user then changed password and email presumably).
bagder··on Daniel Stenberg's (badger) Twitter account seems to have been compromised
can I just mention that my twitter handle is 'bagder' - as in a dyslexic animal! =)
bagder··on Memory safe ‘curl’ for a more secure internet
Tadaa: curl already supports --parallel to download many URLs simultaneously...
bagder··on Memory safe ‘curl’ for a more secure internet
"For some years" sure, but that's ancient history.

curl has verified the server certificates by default since version 7.10, shipped in October 2002.

bagder··on Curl is 21 years old
The twitter post just links to my blog post "Happy 21st, curl": https://daniel.haxx.se/blog/2019/03/20/happy-21st-curl/
bagder··on I’m leaving Mozilla
Thank you! I will certainly do what I can to not make this little change affect my curl commitment in a negative manner...
bagder··on Inside Firefox’s DNS-over-HTTPS engine
Thanks! Captive portals are indeed truly complicated beasts to handle and they offer challenging obstacles for browsers (and others). We keep working on trying to improve how Firefox detects and works with them.
bagder··on Inside Firefox’s DNS-over-HTTPS engine
... that's why the article you're commenting on mentions SNI and that we hope to address that too (but separately) going forward!
bagder··on Inside Firefox’s DNS-over-HTTPS engine
"I better speculate on the reason here because surely Daniel is part of a conspiracy meant destroy the browsing experience of millions"

or...

It could be prepared for when the user gets asked what they want and then Firefox can remember an explicit "no" as compared to not selection ever made.

/ Daniel (author of the blog post)

bagder··on Twenty years, 1998 – 2018
c-ares is not standard because making a drop-in replacement for the regular stock name resolver function is really hard and c-ares is not 100% there. A c-ares powered libcurl fails to resolve some host names in some setups that otherwise work with the stock resolver (and thus in other apps/libraries). That's why the threaded stock resolver is the most popular resolver backend of curl/libcurl these days...
bagder··on Twenty years, 1998 – 2018
Oh c'mon, give me your best early curl stories!

/ (curl author)

bagder··on Microsoft cURLs too
It probably isn't too obvious here, but yeah I know how it works =)

(I'm Daniel, who wrote the blog post discussed here and leads the curl development...)

bagder··on Microsoft cURLs too
If you invoke "curl http://example.com/a.htm http://example.com/b.htm", curl will only use a single connection.
bagder··on Creator of cURL wins Polhem Prize 2017
We were never able to get any answers as to why I was denied - in spite of some real efforts in finding out. It will remain an unanswered mystery.

I will make a renewed attempt to travel to the US at a later time. Hopefully it was just some mess-up, a human error or whatever.

/ Daniel

bagder··on A single byte write opened a root execution exploit
(I wrote the blog post)

ASLR was enabled. The attacker worked around it.

bagder··on gRPC: Internet-scale RPC framework is now 1.0
BTW, recent data shows that Firefox does (on median) about 8 requests per HTTP/2 connection, up from slightly more than 1 on HTTP/1.1

So, if we ever close a connection from having reached a billion streams we are in a very very good position.

bagder··on gRPC: Internet-scale RPC framework is now 1.0
Correct, something that was used already in SPDY and proved to be very handy and convenient so it was kept in HTTP/2.
bagder··on gRPC: Internet-scale RPC framework is now 1.0
It was not ignored, it was very much made on purpose because of a certain popular programming language not having unsigned 32 bit variables...
bagder··on A curl cheat sheet
-x is already in there, which is the short version of --proxy...
bagder··on HTTP/2 for TCP/IP Geeks
The usage share there referred to stats from Mozilla and Firefox 36, where HTTP/1.0 is seen in 1% of all HTTP responses compared to 10% for HTTP/2. / Daniel - author of those slides
bagder··on The state and rate of HTTP/2 adoption
That's excellent to hear, thanks! If you have a public URL with such a statement I'd link to it from the post... (hint hint) =)
Page 1 of 2Next →