Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

111–120 of 174 posts

Re: About the “Security Issue” on VLC

#111
Completely OT: does anyone else find this style of posting stuff on a very long twitter thread hard to read, and somewhat worrying in terms of dependency on a proprietary platform? Why can't this be upfront on the videolan.org homepage and just linked from a single tweet?

Re: About the “Security Issue” on VLC

#112
post #55
post #34

Earlier quoted context omitted.

VLC is open source, distributed by VideoLAN non-profit and is totally non-commercial. The only money received by the non-profit is through donations.

Yes, hence they don't have a lawyer ontap, which was kinda the point I was making. The education (what I'm going to call it) that they could bestow upon these bismershing media outlets, would fund much Open Source work for VLC.

You say “they don’t have a lawyer” I don’t know if you realize you’re addressing the lead developer and president of VLC. I think he may be quite a bit more aware of his org’s ability and desire to retain legal counsel than all of us.

Re: About the “Security Issue” on VLC

#113
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

Suggest everyone here pick a couple of news agencies who propagated this crap and write to the editors admonishing their shoddy fact-checking. I emailed two this morning.

Re: About the “Security Issue” on VLC

#114
post #98
post #78

Earlier quoted context omitted.

Canonical probably does care less than in their desktop golden years, now they are perhaps focusing on the server os market (cloud). The distribution model has the advantage of single click install. Great for basic users, but you run outdated software, sometimes with well known security holes. For power users who can take some work in maintaining their system, it seems to me that your way - keeping up with the latest…

What do you mean? Arch works the same way as Ubuntu; there's a package manager, you use it to install software from the system repositories. `apt-get install vlc` is no easier or more user friendly than `pacman -S vlc`. I imagine gnome-software even works it does in Ubuntu, though I haven't tried using it. The only difference is that Arch updates their repos' packages as soon as a new version is available upstream (a…

I meant the LTS model such as Ubuntu 18.04 gives you old version software with the possibility of worse functionality and more security holes. Arch may be more up-to-date than Ubuntu, but it isn't in the same category; it is not LTS, and it is not as widespread.

Re: About the “Security Issue” on VLC

#115
post #96

Earlier quoted context omitted.

Everybody, including researchers, has a duty to publish things responsibly and if necessary, withhold the publication. Despite the economical incentives, the moral responsibility is to research and harden systems, not to publish whatever and build a resume. You can't just publish information harmful to public and say "well I'm a researcher, so I can do anything I want". Publishing instructions to bypass important sec…

Does this universal duty to work for free only concern security research? >You can't just publish information harmful to public It’s simply ridiculous to describe full disclosure like that.

I did not say duty to work for free, but duty to observe some restrictions and weighing positive/negative impacts of your publications on society if you choose to work in that domain.

Re: About the “Security Issue” on VLC

#116

Earlier quoted context omitted.

No, it's called Responsible disclosure. https://security.stackexchange.com/questions/52/how-to-discl... By not contacting the developer first, you're acting in bad faith. This opens you up to all kinds of legal liabilities, not to mention the social exclusion that will occur.

Nonsense. “Responsible disclosure” is a term coined by vendors to shame researchers who don’t play ball. There’s no implicit “bad faith” in full disclosure or even the sale of weaponized 0day exploits.

Oh this trope again. I am no vendor and I fully support the idea that security researchers coordinate their publication activities with affected parties.

Re: About the “Security Issue” on VLC

#117
post #34

Earlier quoted context omitted.

[Edit, see below.]

VLC is open source, distributed by VideoLAN non-profit and is totally non-commercial. The only money received by the non-profit is through donations.

Thanks for your hard work on VLC. I love it. Throwing you a quick donation so you have something good happening during an otherwise rough time.

@ you and any lawyers

I know you probably don't want to go to some long-term battle in the courts with any of these groups. What about a libel suit in small claims court against each one? I wonder if that's even possible. If so, start with one to keep time/costs down, then (if victorious) hit the others either one at a time or simultaneously. At the least, the wins raise you some funding while providing some small deterrence from them doing it again.

Re: About the “Security Issue” on VLC

#118
post #101
post #76

Gizmodo posts the headline on their front page, "You Might Want to Uninstall VLC. Immediately" Following the debunking of the story, what does Gizmodo do? Leave it on the front page and change the headline to "You Might Want to Uninstall VLC. Immediately [Updated]"

They actually did. >You Might Want to Uninstall VLC. Immediately. [Updated: Maybe Not] Is the current title...

Its amazing how a title can have two entirely contradictory, non committal claims telling you to do a thing, and yet tell me absolutely nothing useful.

Re: About the “Security Issue” on VLC

#119
post #115

Earlier quoted context omitted.

Does this universal duty to work for free only concern security research? >You can't just publish information harmful to public It’s simply ridiculous to describe full disclosure like that.

I did not say duty to work for free, but duty to observe some restrictions and weighing positive/negative impacts of your publications on society if you choose to work in that domain.

Publicly dropping a bug is still better for the public than keeping it secret. Full disclosure is charity.

Re: About the “Security Issue” on VLC

#120
post #116

Earlier quoted context omitted.

Nonsense. “Responsible disclosure” is a term coined by vendors to shame researchers who don’t play ball. There’s no implicit “bad faith” in full disclosure or even the sale of weaponized 0day exploits.

Oh this trope again. I am no vendor and I fully support the idea that security researchers coordinate their publication activities with affected parties.

Great, me too. But I also fully support the idea that people should be allowed to do whatever the fuck they want with their work product. (within the limits of the law, of course)

Charity is nice, but I’m not going to insist that you donate your whole paycheck!

Post reply on HN