Jeremy Stanley writes: >Now the vast majority of bug reports we receive are from disconnected >"researchers" looking to make a name for themselves, pad their resumés/CVs, >or promote their LLM-oriented code auditing services.
Bit of an aside, I've been working on a presentation "The Cost of Stunt Cryptography" that looks at the real-world cost to open-source project maintainers of stunt cryptography / CVEnhancement "vulnerabilities" that present no practical attack or weakness but can result in months of remediation work and thousands to tens of thousands of dollars in costs to projects with a lot of downstreams. I've got several examples already but if anyone has any particularly egregious examples with accompanying data (time spent, cost) that they'd like to share I'm always looking for more. Peter.
