Re: curl verification
bruce via curl-users <[email protected]> Tue, 26 May 2026 20:49:18 -0400
| Newsgroups | gmane.comp.web.curl.general |
|---|---|
| Message-ID | <CAP16ngq3VKHK4WRNZnz-Zyyoxi8kYH+KU-vErJY9z_2xcr3tNQ@mail.gmail.com> |
--===============0903578727814824082== Content-Type: multipart/alternative; boundary="000000000000fa60550652c1fb3b" --000000000000fa60550652c1fb3b Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable saw this thread. isn't the issue you're dealing with regarding the SBOM basically the same problem faced with any other piece of software? How does one know/trust that the app is built with trusted/validated components? thanks On Tue, May 26, 2026, 8:43=E2=80=AFPM Dick Brooks via curl-users < [email protected]> wrote: > Dan, > > Thanks for responding, but a "html listing of components" won't work for > our > particular needs. > > Business Cyber Guardian works almost exclusively with the Software Consum= er > side to determine trustworthiness of a product before installation. > We produce a "Trust Score" called a "SAGScore" that enables a consumer to > make a risk based decision to install/not install a product, based on a > statistically calculated > SAGSCore, trust score. > > Our risk assessment product, SAG-PM, "needs" an SBOM, and if no SBOM is > provided by the software supplier, then we create an extrapolated SBOM > based > on the distributed package contents. > > My customers want to know "What are you installing in my cyber ecosystem > that could lead to cyber risk". > > We created an SBOM of the curl distribution package (the zip file) as par= t > of a risk assessment where each leaf node in the zip file is represented = as > a component in the extrapolated SBOM file created by SAG-PM. > The curl distribution Package (zip file) contains 359 independent SBOM > components, based on zip file contents. > > These 359 components are then subjected to a "vulnerability search" using > NIST NVD to determine if there are any potential "known vulnerability > risks". > Any discovered risks will lower the trust score (SAGScore). > > An html file listing components is not sufficient for the risk assessment > we > perform. Only an SBOM that contains all of the components contained in a > "distribution package" will work for this risk assessment. > > I hope this helps to explain why we need an SBOM for the "distributed" > (built/distributed package) in order to perform a proper, comprehensive > risk > assessment before installation. > > Thanks, > > Dick Brooks > > Active Member of the CISA Critical Manufacturing Sector, > Sector Coordinating Council - A Public-Private Partnership > Lifetime IEEE Member > Never trust software, always verify and report! T > Risk always exists, but trust must be earned and awarded.T > https://businesscyberguardian.com/ > Email: [email protected] > Tel: +1 978-696-1788 > > > -----Original Message----- > From: curl-users <[email protected]> On Behalf Of Dan > Fandrich via curl-users > Sent: Tuesday, May 26, 2026 7:31 PM > To: [email protected] > Cc: Dan Fandrich <[email protected]> > Subject: Re: curl verification > > On Tue, May 26, 2026 at 02:08:06PM +0100, Jeremy Nicoll via curl-users > wrote: > > On Tue, 26 May 2026, at 13:30, Dick Brooks via curl-users wrote: > > > This SBOM is just an extrapolation based on the zip file contents > > > downloaded from here: > > > https://curl.se/windows/ > > > > Oh! That's confusing. > > > > If one's on the curl website & follows the obvious top-of-page-banner > > "download" option ... one ends up at: https://curl.se/download.html > > > > If you scroll that page down there's lots of other (3rd-party?) curl > > Windows binaries offered. How is someone supposed to find the page: > > > > https://curl.se/windows/ ? > > The curl-provided binaries are listed along with all the other binaries. > You'll see a link to that page in the Windows 32-bit and Windows 64-bit > sections with the label "the curl project". > -- > Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users > Etiquette: https://curl.se/mail/etiquette.html > > -- > Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users > Etiquette: https://curl.se/mail/etiquette.html > --000000000000fa60550652c1fb3b Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">saw this thread.<div dir=3D"auto"><br></div><div dir=3D"a= uto">isn't the issue you're dealing with regarding the SBOM basical= ly the same problem faced with any other piece of software?</div><div dir= =3D"auto"><br></div><div dir=3D"auto">How does one know/trust that the app = is built with trusted/validated components?</div><div dir=3D"auto"><br></di= v><div dir=3D"auto">thanks</div><div dir=3D"auto"><br></div></div><br><div = class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=3D"gmail= _attr">On Tue, May 26, 2026, 8:43=E2=80=AFPM Dick Brooks via curl-users <= ;<a href=3D"mailto:[email protected]">[email protected]</a>&g= t; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 = .8ex;border-left:1px #ccc solid;padding-left:1ex">Dan,<br> <br> Thanks for responding, but a "html listing of components" won'= ;t work for our<br> particular needs.<br> <br> Business Cyber Guardian works almost exclusively with the Software Consumer= <br> side to determine trustworthiness of a product before installation.<br> We produce a "Trust Score" called a "SAGScore" that ena= bles a consumer to<br> make a risk based decision to install/not install a product, based on a<br> statistically calculated <br> SAGSCore, trust score.<br> <br> Our risk assessment product, SAG-PM, "needs" an SBOM, and if no S= BOM is<br> provided by the software supplier, then we create an extrapolated SBOM base= d<br> on the distributed package contents.<br> <br> My customers want to know "What are you installing in my cyber ecosyst= em<br> that could lead to cyber risk".<br> <br> We created an SBOM of the curl distribution package (the zip file) as part<= br> of a risk assessment where each leaf node in the zip file is represented as= <br> a component in the extrapolated SBOM file created by SAG-PM. <br> The curl distribution=C2=A0 Package (zip file) contains 359 independent SBO= M<br> components, based on zip file contents.<br> <br> These 359 components are then subjected to a "vulnerability search&quo= t; using<br> NIST NVD to determine if there are any potential "known vulnerability<= br> risks".<br> Any discovered risks will lower the trust score (SAGScore).<br> <br> An html file listing components is not sufficient for the risk assessment w= e<br> perform. Only an SBOM that contains all of the components contained in a<br= > "distribution package"=C2=A0 will work for this risk assessment.<= br> <br> I hope this helps to explain why we need an SBOM for the "distributed&= quot;<br> (built/distributed package) in order to perform a proper, comprehensive ris= k<br> assessment before installation.<br> <br> Thanks,<br> <br> Dick Brooks<br> <br> Active Member of the CISA Critical Manufacturing Sector, <br> Sector Coordinating Council - A Public-Private Partnership<br> Lifetime IEEE Member<br> Never trust software, always verify and report! T<br> Risk always exists, but trust must be earned and awarded.T <br> <a href=3D"https://businesscyberguardian.com/" rel=3D"noreferrer noreferrer= " target=3D"_blank">https://businesscyberguardian.com/</a> <br> Email: <a href=3D"mailto:[email protected]" target=3D"_blank" = rel=3D"noreferrer">[email protected]</a><br> Tel: +1 978-696-1788<br> <br> <br> -----Original Message-----<br> From: curl-users <<a href=3D"mailto:[email protected]" ta= rget=3D"_blank" rel=3D"noreferrer">[email protected]</a>>= On Behalf Of Dan<br> Fandrich via curl-users<br> Sent: Tuesday, May 26, 2026 7:31 PM<br> To: <a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"no= referrer">[email protected]</a><br> Cc: Dan Fandrich <<a href=3D"mailto:[email protected]" target=3D"_b= lank" rel=3D"noreferrer">[email protected]</a>><br> Subject: Re: curl verification<br> <br> On Tue, May 26, 2026 at 02:08:06PM +0100, Jeremy Nicoll via curl-users<br> wrote:<br> > On Tue, 26 May 2026, at 13:30, Dick Brooks via curl-users wrote:<br> > > This SBOM is just an extrapolation based on the zip file contents= <br> > > downloaded from here:<br> > > <a href=3D"https://curl.se/windows/" rel=3D"noreferrer noreferrer= " target=3D"_blank">https://curl.se/windows/</a><br> > <br> > Oh!=C2=A0 That's confusing.<br> > <br> > If one's on the curl website & follows the obvious top-of-page= -banner <br> > "download" option ... one ends up at: <a href=3D"https://cur= l.se/download.html" rel=3D"noreferrer noreferrer" target=3D"_blank">https:/= /curl.se/download.html</a><br> > <br> > If you scroll that page down there's lots of other (3rd-party?) cu= rl <br> > Windows binaries offered.=C2=A0 How is someone supposed to find the pa= ge:<br> > <br> >=C2=A0 =C2=A0<a href=3D"https://curl.se/windows/" rel=3D"noreferrer nor= eferrer" target=3D"_blank">https://curl.se/windows/</a>=C2=A0 =C2=A0 ?<br> <br> The curl-provided binaries are listed along with all the other binaries.<br= > You'll see a link to that page in the Windows 32-bit and Windows 64-bit= <br> sections with the label "the curl project".<br> --<br> Unsubscribe: <a href=3D"https://lists.haxx.se/mailman/listinfo/curl-users" = rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.haxx.se/mailm= an/listinfo/curl-users</a><br> Etiquette:=C2=A0 =C2=A0<a href=3D"https://curl.se/mail/etiquette.html" rel= =3D"noreferrer noreferrer" target=3D"_blank">https://curl.se/mail/etiquette= .html</a><br> <br> -- <br> Unsubscribe: <a href=3D"https://lists.haxx.se/mailman/listinfo/curl-users" = rel=3D"noreferrer noreferrer" target=3D"_blank">https://lists.haxx.se/mailm= an/listinfo/curl-users</a><br> Etiquette:=C2=A0 =C2=A0<a href=3D"https://curl.se/mail/etiquette.html" rel= =3D"noreferrer noreferrer" target=3D"_blank">https://curl.se/mail/etiquette= .html</a><br> </blockquote></div> --000000000000fa60550652c1fb3b-- --===============0903578727814824082== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline -- Unsubscribe: https://lists.haxx.se/mailman/listinfo/curl-users Etiquette: https://curl.se/mail/etiquette.html --===============0903578727814824082==--