Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

101–110 of 174 posts

Re: About the “Security Issue” on VLC

#101
post #76

Gizmodo posts the headline on their front page, "You Might Want to Uninstall VLC. Immediately" Following the debunking of the story, what does Gizmodo do? Leave it on the front page and change the headline to "You Might Want to Uninstall VLC. Immediately [Updated]"

They actually did.

>You Might Want to Uninstall VLC. Immediately. [Updated: Maybe Not]

Is the current title...

Re: About the “Security Issue” on VLC

#103
post #96
post #70

Earlier quoted context omitted.

>Not doing so is an asshole move. Dictating how researchers should choose to publish their work product is an asshole move. If someone chooses to share their work product with you privately, that's very charitable of them. It's not reasonable to expect charity.

Everybody, including researchers, has a duty to publish things responsibly and if necessary, withhold the publication. Despite the economical incentives, the moral responsibility is to research and harden systems, not to publish whatever and build a resume. You can't just publish information harmful to public and say "well I'm a researcher, so I can do anything I want". Publishing instructions to bypass important sec…

Does this universal duty to work for free only concern security research?

>You can't just publish information harmful to public

It’s simply ridiculous to describe full disclosure like that.

Re: About the “Security Issue” on VLC

#104
post #79

>Yes, so your issue is your distribution is not up-to-date, not VLC. I've always found it odd that many of the packages on certain linux distributions were old . Like how one time the latest openvpn version on the latest Ubuntu release was a year old.

Debian 8 is still on php 5.6 which is EOL, even if you upgrade to debian 9 you would be on php 7.0 which is also EOL.

Debian 10 is running 7.3, thankfully. But their LTS runs for 5 years and 7.3 will be EOL about 7 months before Buster and active support dropped about 17 months before. And PHP 7.4 is due out in November/December. So Buster will be outdated with its PHP release 6 months after release.

Re: About the “Security Issue” on VLC

#105
post #70

Earlier quoted context omitted.

Most / all software has a disclosure policy, send your vulns privately and provide/negotiate a public disclosure date. Not doing so is an asshole move. In this case, the solution would be to track down distributions which did not package the software and (privately) disclose to them that the relevant lib needs updating.

>Not doing so is an asshole move. Dictating how researchers should choose to publish their work product is an asshole move. If someone chooses to share their work product with you privately, that's very charitable of them. It's not reasonable to expect charity.

No, it's called Responsible disclosure. https://security.stackexchange.com/questions/52/how-to-discl...

By not contacting the developer first, you're acting in bad faith. This opens you up to all kinds of legal liabilities, not to mention the social exclusion that will occur.

Re: About the “Security Issue” on VLC

#106
post #70

Earlier quoted context omitted.

>Not doing so is an asshole move. Dictating how researchers should choose to publish their work product is an asshole move. If someone chooses to share their work product with you privately, that's very charitable of them. It's not reasonable to expect charity.

No, it's called Responsible disclosure. https://security.stackexchange.com/questions/52/how-to-discl... By not contacting the developer first, you're acting in bad faith. This opens you up to all kinds of legal liabilities, not to mention the social exclusion that will occur.

Nonsense. “Responsible disclosure” is a term coined by vendors to shame researchers who don’t play ball.

There’s no implicit “bad faith” in full disclosure or even the sale of weaponized 0day exploits.

Re: About the “Security Issue” on VLC

#108
post #101
post #76

Gizmodo posts the headline on their front page, "You Might Want to Uninstall VLC. Immediately" Following the debunking of the story, what does Gizmodo do? Leave it on the front page and change the headline to "You Might Want to Uninstall VLC. Immediately [Updated]"

They actually did. >You Might Want to Uninstall VLC. Immediately. [Updated: Maybe Not] Is the current title...

We have reached out to both companies for more info on what happened regarding the initial CVE

Should have done that from the very beginning, as should have MITRE before publishing a CVE ID.

Failures all around on this one. Sorry you’re having such a shit morning, jbk, because of other people’s laziness.

Re: About the “Security Issue” on VLC

#109
post #30
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

If VLC was a commercial product, this would be a lawyer time for effectively damaging reputation based upon lies and would see many media outlet dragged over the coals. VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction. Maybe we need…

'Exactly what i wanted to write. Thx. So i didn't had to type so much on a glass-surface :)

Re: About the “Security Issue” on VLC

#110
post #11

Earlier quoted context omitted.

> To boot https://www.securityfocus.com/bid/109304 claims all versions are vulnerable and the vendor reported it Of course, we never reported such a thing: a security issue in a 3rd party library, fixed more than 16months ago. And VLC binaries were updated 16months ago too... The issue is that MITRE is not doing its job when assigning the CVE or even checking the validity of the claim. But they refuse to talk to us.…

>But they refuse to talk to us. Why? Because stonewalling is SOP for government bureaucracies when they screw up. When you're the government the various systems the people you screwed have for recourse work slightly differently so stonewalling works better than spewing out a ton of deny and distract PR like corporations do.

> Because stonewalling is SOP for big orgs when they screw up.

FTFY

A lot of people seem to be under the impression that when you just privatize a government agency, it magically becomes better. It doesn't.

Post reply on HN