Jeremy Stanley writes:

>Now the vast majority of bug reports we receive are from disconnected
>"researchers" looking to make a name for themselves, pad their resumés/CVs,
>or promote their LLM-oriented code auditing services.

Bit of an aside, I've been working on a presentation "The Cost of Stunt
Cryptography" that looks at the real-world cost to open-source project
maintainers of stunt cryptography / CVEnhancement "vulnerabilities" that
present no practical attack or weakness but can result in months of
remediation work and thousands to tens of thousands of dollars in costs to
projects with a lot of downstreams.  I've got several examples already but if
anyone has any particularly egregious examples with accompanying data (time
spent, cost) that they'd like to share I'm always looking for more.

Peter.

Reply via email to