4 ms·
Nothing about the article implies cURL is responsible for the exploit, only that it can be used to leverage the exploit. It's relevant and good to know, and sho
by TheAdamAndChe 5y ago
Nothing about the article implies cURL is responsible for the exploit, only that it can be used to leverage the exploit. It's relevant and good to know, and shouldn't be removed IMO.
- nkrisc 5y agoIt's strange to mention cURL specifically in this context. If the exploit only takes 5 HTTP requests, why not just say "5 HTTP requests"? Why does the article need to mention cURL at all if it's not relevant how those requests are sent? Unless cURL is relevant, but that's now how the article is written. If they're trying to get across to a non-technical audience how easy it is, then why mention cURL? They're not going to know what cURL is, as evidenced by the explainer following immediately. Why not just say, "5 HTTP requests sent by the command line"?
- TheAdamAndChe 5y agoHTTP exploit requests can be pretty complicated, and the use of cURL hints that it's a dirt simple exploit to leverage. This is an arstechnica article, their target demographic is more technically literate than the lowest common denominator.
- oasisbob 5y ago> HTTP exploit requests can be pretty complicated, and the use of cURL hints that it's a dirt simple exploit to leverage. Why would that be? Curl can perform incredibly complicated requests to the point where they're barely legible on the command line.
- nkrisc 5y agoRight, I understand. My point is that if they're going to mention cURL, but then describe it as "a command-line tool that transfers data using HTTP, HTTPS, IMAP, and other common Internet protocols." why not just say the attack can be executed directly from the command line? Any techincally literate audience will understand that implies cURL (or any other tool!) and an non-technical audience will understand its simplicity, if that is in fact the case. I still think it's strange to mention cURL specifically in the way they did and agree with the GP. Here's another terrible analogy for the HN archives, but it's kind of like saying, "the smash-and-grab on the jewel store can committed with a Stanley™ 16 oz Curved Claw Fiberglass Hammer" when of course any heavy, handheld object will do.
- TheAdamAndChe 5y agocURL has above-average name recognition. It's like mentioning a Dremel tool instead of a handheld rotary tool.
- ldarby 5y ago> cURL has above-average name recognition. It might to you and people in your circle, but that's not the entire audience of the article. I wouldn't assume everyone knows what a Dremel is either.
- thaumasiotes 5y ago> why not just say the attack can be executed directly from the command line? Any techincally literate audience will understand that implies cURL (or any other tool!) and an non-technical audience will understand its simplicity, if that is in fact the case. I mean, the normal way to use curl for this kind of thing is to define the request you want to send in a file and tell curl to read the file. There's no requirement -- or implication -- of simplicity in an attack that "you can execute from the command line"; that description refers to every possible attack. It's meaningless. There's nothing you can do that you can't do from the command line.
- nkrisc 5y agoYes, so why mention cURL at all?
- thaumasiotes 5y agoI'm not saying there's a reason to mention curl. I'm saying the explanation given makes no sense.
- codyb 5y agoIt might just be a common journalistic practice to briefly profile any name introduced into an article.
- reshlo 5y agoBut why did they need to introduce cURL into the article?
- vgaldikas 5y agoI understand that it's nothing to do with curl specifically, you understand it, good chunk of HN users do understand it. But general public doesn't really