Three decades of curl - Daniel Stenberg - NDC Security 2026

Three decades of curl - Daniel Stenberg - NDC Security 2026

🎙 Daniel Stenberg 👥 227K 📅 March 24, 2026 ⏱ 48 min 👁 12K 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

curlopen sourcesecurityC89protocols

Summary

Daniel Stenberg, the creator and lead developer of curl, delivers a keynote at NDC Security 2026 reflecting on three decades of the project. He traces curl’s origins from a small IRC bot helper in 1996 to its current status as a ubiquitous internet transfer tool used in an estimated 30 billion installations. The talk covers the evolution of the codebase, the addition of numerous protocols, and the growth of the contributor community. Stenberg emphasizes the importance of open source, reliability, and backward compatibility, highlighting curl’s commitment to not breaking existing users. He discusses the project’s security practices, including code style enforcement, banning unsafe functions, and reducing function complexity. He also shares anecdotes about encountering curl in unexpected places, from TV shows to car dashboards, and the challenges of being a widely used open source project. The talk concludes with reflections on the future, including the upcoming release with MQTT support, and the importance of transparency and community in sustaining a successful open source project.

164 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights into the long-term maintenance of a critical open source project. Stenberg’s argumentation is grounded in his personal experience and concrete examples, such as the project’s growth metrics and security practices. He effectively communicates the importance of reliability, backward compatibility, and community involvement. The narrative is compelling and well-structured, moving from historical context to technical decisions and security considerations.

Scientific Rigor, Source Quality, Title Accuracy

The talk is based on the speaker’s direct involvement in curl, making it a primary source. While no external sources are cited, the information aligns with publicly available documentation and the project’s history. The title accurately reflects the content. The talk does not include formal citations, but the speaker’s authority and the project’s transparency lend credibility. The audience’s questions or comments are not provided, so no analysis of public reception is possible.

150 words

Title / Content Match

The title accurately reflects the content: a retrospective of curl's 30-year history, presented by its creator.

Quality & Reliability

8/10

The talk is given by the founder and lead developer of curl, providing first-hand, authoritative insights into the project's history, technical decisions, and security practices. The information is consistent with publicly known facts about curl and open source development. However, some claims (e.g., 30 billion installations) are estimates and not independently verified.

Key Moments

Cited Sources

  • NDC Security Conference — The conference where the talk was recorded.
  • NDC Conferences — The organizer of the conference.

Concurring Sources

Contribution & Novelties

The talk offers a unique first-hand account of the history and development of curl, providing insights into the challenges and successes of maintaining a widely used open source project. It emphasizes practical lessons on reliability, backward compatibility, and security practices that are applicable to other projects.

Pour aller plus loin :

88 words

Radar Profile

The radar profile shows high scores in quantity and quality of information, reflecting the speaker's deep expertise and the talk's comprehensive coverage. The technical level is moderate, making it accessible to a broad audience. The overall reliability is high due to the speaker's authoritative position.

Reliability 8/10