Paying out money to people who send in bug reports is probably the main problem because it incentivizes them to use AI and send in as many as possible throwing everything against the wall and hoping that something sticks and they get a payout. While this was a good method before AI, now with AI being able to produce reasonable sounding text he needs to stop the money transfer, otherwise they will drown in reports and this number of 5% will get way lower.
Still this seems like a HackerOne problem, they’re acting as the middleman and I assume are taking part of the payout. What are they doing to earn the money they’re taking? The reason to go with HackerOne is to facilitate the interactions with people and pass the reports. It shouldn’t be a Curl maintainers responsibility to spot obvious AI slop. Maybe this is just the tier they’re on with HackerOne, but considering this is HackerOne’s business model, I would imagine that if huge companies are also dealing with this, then HackerOne will loose a lot of clients.
Ninja Edit: Obviously the problem is the people creating AI Slop, but HackerOne should be the ones dealing with it, not OpenSource Maintainers.
Paying out money to people who send in bug reports is probably the main problem because it incentivizes them to use AI and send in as many as possible throwing everything against the wall and hoping that something sticks and they get a payout. While this was a good method before AI, now with AI being able to produce reasonable sounding text he needs to stop the money transfer, otherwise they will drown in reports and this number of 5% will get way lower.
Still this seems like a HackerOne problem, they’re acting as the middleman and I assume are taking part of the payout. What are they doing to earn the money they’re taking? The reason to go with HackerOne is to facilitate the interactions with people and pass the reports. It shouldn’t be a Curl maintainers responsibility to spot obvious AI slop. Maybe this is just the tier they’re on with HackerOne, but considering this is HackerOne’s business model, I would imagine that if huge companies are also dealing with this, then HackerOne will loose a lot of clients.
Ninja Edit: Obviously the problem is the people creating AI Slop, but HackerOne should be the ones dealing with it, not OpenSource Maintainers.