Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > Everyone with a paid support contracts will of course still get full and appropriate service even during this period.
  • >> The bad guys won’t rest > Probably not. But we will.

    This is Exceptional. Perfect EuroMaxxing

  • I read one sentence into this and knew directly that the developer must’ve been Swedish!
  • I knew instantly that it's him. No one is even remotely as hungry for attention as him.
  • Hahaha yeah same here! My $dayjob has offices in Sweden and their summer breaks are legendary. We also have offices in the US, and the culture shock with the Americans never gets old
    by nsbk
  • Yup, same thought in Norwegian. Norway basically shuts down during July.
  • For people who aren’t familiar, Sweden takes summer holidays seriously. 25-30 days + public holidays is a normal amount of annual vacation time, and if an employee requests it and has the time available, it’s basically legally required to allow them to take a four-week contiguous summer break.

    (See https://www.riksdagen.se/sv/dokument-och-lagar/dokument/sven...)

  • Here's your reminder that 20-30 days paid vacation plus unlimited sick days (3+ days needs a doctor's note) is normal in Europe (e.g. Germany).

    If you get sick during vacation, you get those vacation days "refunded" back. If you suddenly are called in to work, somehow, during vacation, that time cannot be vacation time.

    You can't (generally) be fired without a notice period, resulting in job security to such a degree that ~6k in an emergency fund is plenty to be VERY secure, as you also get unemployment support otherwise anyway. Does this result in incompetent people not getting fired? No. You still fire them, you just have to deal with them another month after that. It's not a big price to pay.

    How is this all possible? Who subsidizes it? We all simply pay some % of our income to support this system. That's it. A couple percent, a couple bucks, and we get to basically never worry about starving or becoming homeless.

    You can have this, too, if you vote and protest and use democracy to make life better, not worse, for everyone.

  • What this shows me (again) is that the whole system where vulnerabilities need to be constantly discovered, reported, analyzed, then patched, then the new version distributed to every singe user - again and again - is quite obviously unsustainable. The industry must come up with some alternative system for dealing with bugs and security issues. Currently the industry prefers to play dumb and turn its own failures into a profit (rent seeking) opportunity.
  • Yeah, pay the foss maintainers. Anyone, who uses these projects must pay a minimum fee. Companies expected to pay a lot more.
  • I think you're right, and the solution is security through compartmentalization. See: https://qubes-os.org.
  • What's the better solution?

    Also, what's an example of this rent seeking in open source you're talking about?

  • as much as I feel for the maintainers here, this sort of (again) puts the spotlight on our collective dependence on a handful of individuals basically working for free _with no backup_. Most normal organizations stagger vacations to avoid these things. Most normal organizations _have_ to do this, because their customers require it. Here, we're all customers of curl, but not really. It's a weird, IMO unhealthy, twilight zone that isn't good for anybody. And it surprises - and saddens - me that not even friggin curl has the financial muscles to have somebody on-call for one month...
  • I wonder how far we are from the agents just maintaining the packages
  • > And it surprises - and saddens - me that not even friggin curl has the financial muscles to have somebody on-call for one month...

    Is it that they can't or don't want to. I'm sure curl is popular enough that it could attract a co-maintainer if it wanted to. Of course there is a cost to that. Software projects done effectively by a single person are often more focused and designed more coherently. I'm not sure curl would be as good a product if there were multiple maintainers with potentially conflicting visions.

  • And I'm assuming you're not going to pay for them to have that someone on-call, even though you're worried about this scenario
  • It does. The article clearly says that if you have a paid support contract they will be on-call as per usual.
  • They do.

    > Everyone with a paid support contracts will of course still get full and appropriate service even during this period.

  • They do, he said at the end if you have a support contract then they will respond and deal with security issues.

    I guess the whole point of the article is to show that people should buy a support contract if they need support.

  • You'd be surprised to learn this about free and open source software, but if a maintainer is unavailable, you have both full rights and full source code to... wait for it... fix it yourself (or pay someone to)!

    There is something unhealthy in this relationship only if you project "no warranty" into unrealistic expectations.

  • For anyone who thinks this might matter for security:

    * curl is mature enough that the chance of an impactful bug is basically zero * if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co * if there is such a bug, it's more important that it gets patched in package managers and rolled out. Upstream releases can wait.

  • > curl is mature enough that the chance of an impactful bug is basically zero

    Curl is also something that should be thoroughly sandboxed to begin with, because even if there are no vulnerabilities in curl itself, its a tool for downloading arbitrary data over the internet, and you may well accidentally trigger vulnerabilities in every other part of your environment just by downloading arbitrary data to your shell...

  • > if there is such a bug, I'm sure someone will figure out how to get in touch with Daniel and co

    No, that is the point, they are not going to accept your vuln report. They are taking a holiday.

  • I can only applause this decision. Maintainers of FOSS project are constantly overwhelmed with close to 0 reward and with LLMs now the management of merge requests exploded even further. The fact that they actually keep providing support to paying users is enough.
  • Both libexpat ("Expat") and uriparser are following the curl security vacation and will not accept new vulnerability reports before 2026-08-01, starting today.

    [1] https://github.com/libexpat/libexpat/issues/1277

    [2] https://github.com/uriparser/uriparser/issues/323

    by spyc
  • For the people here who want to do the same when they are vacation (be completely detached from work): Make it impossible for you to work! Leave your work devices behind! Log out of all accounts, remove 2FA keys after backing them up on paper and tell your partner to not give them back to you for the duration of your vacation, etc. I actually went to a country from which I wasn't allowed to work remotely. Crazy but it was that bad for me.

    Signed: Former workaholic.

  • Kai Lentit just dropped a video on precisely this

    https://www.youtube.com/watch?v=5E7kBOH9owI

  • > Leave your work devices behind!

    Specifically, if your job offers (a) to pay for your personal phone line, or (b) a work mobile phone, choose (b).

    We have the choice at $WORK, and many teammates chose (a) as it allows them to save some money each month on their phone bill, but now you're basically constantly tethered.

  • This seems like a lot of extra work. If at all possible, just keep your work stuff on your work laptop/computer. And then keep that at home/at work. No need to sign in and out of 20 different accounts.
  • My company have accidentally forced this on me, and it is great.

    I used to have a desktop that I could VPN+RDC into from my personal laptop or desktop to work away from the office¹. I've now got a laptop, that refuses to let me authenticate remotely and they have no interest in fixing that as there are other priorities, so I simply can't work if I don't have that laptop with me and I'm not carting it around when I'm already carting my own around (and if I'm not carrying my own, it is because it isn't a suitable situation to be bringing any laptop).

    Not a workaholic, I don't think, but a 24/7 stress monkey when I think that I could be helping. Simply not being able to work away from the office actually helps with that: if there is literally nothing I can do, especially given it is work that has made that impossible, I don't stress the same way.

    --------

    [1] other than the VPN connector and the MFA doo-hicky on an old² phone, nothing work related, even Teams, even email, ever touches my personal devices

    [2] a small old thing, factory reset with a dummy google account and just the MFA apps installed