About the “Security Issue” on VLC
111–120 of 174 posts
Re: About the “Security Issue” on VLC
#112Earlier quoted context omitted.
VLC is open source, distributed by VideoLAN non-profit and is totally non-commercial. The only money received by the non-profit is through donations.
Yes, hence they don't have a lawyer ontap, which was kinda the point I was making. The education (what I'm going to call it) that they could bestow upon these bismershing media outlets, would fund much Open Source work for VLC.
Re: About the “Security Issue” on VLC
#113So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
Re: About the “Security Issue” on VLC
#114Earlier quoted context omitted.
Canonical probably does care less than in their desktop golden years, now they are perhaps focusing on the server os market (cloud). The distribution model has the advantage of single click install. Great for basic users, but you run outdated software, sometimes with well known security holes. For power users who can take some work in maintaining their system, it seems to me that your way - keeping up with the latest…
What do you mean? Arch works the same way as Ubuntu; there's a package manager, you use it to install software from the system repositories. `apt-get install vlc` is no easier or more user friendly than `pacman -S vlc`. I imagine gnome-software even works it does in Ubuntu, though I haven't tried using it. The only difference is that Arch updates their repos' packages as soon as a new version is available upstream (a…
Re: About the “Security Issue” on VLC
#115Earlier quoted context omitted.
Everybody, including researchers, has a duty to publish things responsibly and if necessary, withhold the publication. Despite the economical incentives, the moral responsibility is to research and harden systems, not to publish whatever and build a resume. You can't just publish information harmful to public and say "well I'm a researcher, so I can do anything I want". Publishing instructions to bypass important sec…
Does this universal duty to work for free only concern security research? >You can't just publish information harmful to public It’s simply ridiculous to describe full disclosure like that.
Re: About the “Security Issue” on VLC
#116Earlier quoted context omitted.
No, it's called Responsible disclosure. https://security.stackexchange.com/questions/52/how-to-discl... By not contacting the developer first, you're acting in bad faith. This opens you up to all kinds of legal liabilities, not to mention the social exclusion that will occur.
Nonsense. “Responsible disclosure” is a term coined by vendors to shame researchers who don’t play ball. There’s no implicit “bad faith” in full disclosure or even the sale of weaponized 0day exploits.
Re: About the “Security Issue” on VLC
#117Earlier quoted context omitted.
[Edit, see below.]
VLC is open source, distributed by VideoLAN non-profit and is totally non-commercial. The only money received by the non-profit is through donations.
@ you and any lawyers
I know you probably don't want to go to some long-term battle in the courts with any of these groups. What about a libel suit in small claims court against each one? I wonder if that's even possible. If so, start with one to keep time/costs down, then (if victorious) hit the others either one at a time or simultaneously. At the least, the wins raise you some funding while providing some small deterrence from them doing it again.
Re: About the “Security Issue” on VLC
#118Gizmodo posts the headline on their front page, "You Might Want to Uninstall VLC. Immediately" Following the debunking of the story, what does Gizmodo do? Leave it on the front page and change the headline to "You Might Want to Uninstall VLC. Immediately [Updated]"
They actually did. >You Might Want to Uninstall VLC. Immediately. [Updated: Maybe Not] Is the current title...
Re: About the “Security Issue” on VLC
#119Earlier quoted context omitted.
Does this universal duty to work for free only concern security research? >You can't just publish information harmful to public It’s simply ridiculous to describe full disclosure like that.
I did not say duty to work for free, but duty to observe some restrictions and weighing positive/negative impacts of your publications on society if you choose to work in that domain.
Re: About the “Security Issue” on VLC
#120Earlier quoted context omitted.
Nonsense. “Responsible disclosure” is a term coined by vendors to shame researchers who don’t play ball. There’s no implicit “bad faith” in full disclosure or even the sale of weaponized 0day exploits.
Oh this trope again. I am no vendor and I fully support the idea that security researchers coordinate their publication activities with affected parties.
Charity is nice, but I’m not going to insist that you donate your whole paycheck!