@harrysintonen@infosec.exchange were the other two not available when you opted out? What I meant was that they had not created a fourth AI training option where one would be opted in
It's still bad and not in the spirit of GDPR that any of the options are enabled by default
@harrysintonen@infosec.exchange at least they have not created a new category with a default opt in which is all too common, I just checked and I'm still opted out of all three
@harrysintonen@infosec.exchange nice find, I don't know how curl defines a vulnerability, but it definitely should have more warnings and preferably fail closed, although that might break quite a few systems which depend on this insecure behaviour
@harrysintonen@infosec.exchange uh what? That explanation makes it sound worse, not better.
even if it requires that the attacker MITM the connection so PR is high... looking at it, how can they claim a RCE has Low impact to CIA?
@harrysintonen@infosec.exchange were the other two not available when you opted out? What I meant was that they had not created a fourth AI training option where one would be opted in
It's still bad and not in the spirit of GDPR that any of the options are enabled by default
@harrysintonen@infosec.exchange at least they have not created a new category with a default opt in which is all too common, I just checked and I'm still opted out of all three
@harrysintonen@infosec.exchange nice find, I don't know how curl defines a vulnerability, but it definitely should have more warnings and preferably fail closed, although that might break quite a few systems which depend on this insecure behaviour