Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The code footprint is small, the surface area for vulnerabilities is small.

I disagree. Their NIH-syndrome and ancient practices seem to be a constant source of new CVE:s [1].

1: https://curl.se/docs/security.html



I'm not sure I'm convinced. This is over the course of 22 years in what's arguably one of the most widely used pieces of software in the world. Keep in mind that Curl is not a tool that's ever truly "ready" so long as standards keep getting updated and new ones emerge.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: