From HTTP Get to 29 Protocols
Daniel Stenberg wrote an IRC bot in 1996 and needed currency rates over HTTP. He found HTTP get, a 100-line tool. He patched it, became maintainer, and added Gopher support. Renamed it URL get in 1997, then added FTP and upload. Renamed again to curl in 1998. HTTPS came that same year. Over time, 27 more protocols joined, including Telnet, DICT, email suites, SFTP, and MQTT S in 2026. The codebase grew linearly to 172,000 lines. The number of command-line options rose from 0 to 278.
Billions of Installations
Curl runs on every mobile phone, in cars, game consoles, printers, and kitchen devices. Stenberg estimates 30 billion installations. Google Photos, YouTube, Spotify, Facebook, Roblox, and Fortnite all use it. The tool runs on any CPU with 32 bits or more and supports more operating systems than most people can name. Stenberg attributes adoption to reliable, cross-platform behavior (same command line and API everywhere), free MIT-like licensing, and 30 years of backward compatibility. Examples from 2006 still build and run today.
Security by Incremental Rigor
Stenberg enforces a rigid style guide so all code reads as written by one author. The project bans dangerous C functions like scanf and atoi, replacing them with wrappers. He reduces function complexity metrics year by year. Average age of a discovered security bug: 8 years. Three external code audits found no critical flaws. Curl fuzzes via Google OSS-Fuzz for 10 years, now finding nothing, confirming stability. AI-powered code analyzers run alongside traditional static analysis. CI has over 200 jobs on 10 platforms. After the XZ attack, Stenberg removed all binary blobs and even base64 encoded data. Commits are signed, releases are fully reproducible.
The Human Side of Open Source
Curl has 3,600 contributors; 600 have code left in production. About 60 to 80 people contribute per 8-week release cycle. A core team of 10 to 20 has been active for 10 to 15 years. Stenberg is the only full-time paid maintainer, logging 30,000 hours on curl. He does less feature development and more project management. Newcomers remain important: first-time authors appear monthly. Stenberg notes C is now a niche language, making recruitment harder. An 11-year-old once emailed him asking about the curl API, which he cites as hopeful for the future.
What Comes Next
Stenberg predicts more devices will gain internet connectivity – toothbrushes, coffee mugs, kitchen appliances. He remodeled his kitchen and found every appliance already networked. Curl will be there to handle transfers. Protocols evolve, version bumps happen, cryptos change. Curl keeps up because users need transfers the way browsers and the internet demand them. Open source survives product lifecycles. AI will not replace curl; curl will do the underlying transfers. Stenberg does not know where curl will be in 2 years, but he trusts close-to-ground decisions.
Notable Quotes
The average time a security problem has existed in curl when we find it is 8 years. Daniel Stenberg · ▶ Watch (28:55)
people are still more difficult than code Daniel Stenberg · ▶ Watch (43:43)
curl would never have become what it is if it hadn’t been open source. Daniel Stenberg · ▶ Watch (18:33)
Key Takeaways
- Curl grew from 100 lines to 172,000 lines over 30 years with 29 protocols.
- Security practices include function bans, fuzzing, and three external code audits.
- A small core team of volunteers maintains the tool with over 30,000 hours invested.
About the Speaker
Daniel Stenberg is a Swedish Internet protocol expert and developer who has participated in and worked with Open Source for thirty years. Perhaps most known for being the founder and lead developer of the curl project, one of the world’s most widely used software components. He participates in protocol development within the IETF and has authored books on curl, Open Source, HTTP/2, HTTP/3 and is a frequent public speaker. Daniel is the president of the European Open Source Academy and a two times gold medal receiver for his Open Source work. Employed by wolfSSL.