Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

131–140 of 174 posts

Re: About the “Security Issue” on VLC

#131
post #116

Earlier quoted context omitted.

Oh this trope again. I am no vendor and I fully support the idea that security researchers coordinate their publication activities with affected parties.

Great, me too. But I also fully support the idea that people should be allowed to do whatever the fuck they want with their work product. (within the limits of the law, of course) Charity is nice, but I’m not going to insist that you donate your whole paycheck!

> I also fully support the idea that people should be allowed to do whatever the fuck they want with their work product. (within the limits of the law, of course)

Do you want ham-fisted regulations? Because that's how you get ham-fisted regulations.

Lawmakers analogize. All it takes is for some bright representative to think that "vulnerability disclosures" are more akin to "burglary tools" than to public service announcements to justify criminalizing third-party security research (or the resulting disclosures).

Re: About the “Security Issue” on VLC

#132

Except if I missed something in my quick research, there doesn't seem to have been a CVE for libebml when it was fixed 16 months ago. So it's really not surprising that LTS distros don't have the fix...

LTS depends on CVEs. And we see here that the CVE database is not entirely trust worthy. The chain is a bit broken.

But the press and slow moving organizations love it.

Re: About the “Security Issue” on VLC

#133
post #125
post #111

Completely OT: does anyone else find this style of posting stuff on a very long twitter thread hard to read, and somewhat worrying in terms of dependency on a proprietary platform? Why can't this be upfront on the videolan.org homepage and just linked from a single tweet?

Change the twitter domain: https://twitter.com/videolan/status/1153963312981389312 to: https://threadreaderapp.com/videolan/status/1153963312981389...

I know about that, I was more interested in the political point of being beholden to a proprietary platform. I think that is especially important for one of the most widely installed open source apps (on non-geeks computers).

Re: About the “Security Issue” on VLC

#134
post #114
post #98

Earlier quoted context omitted.

What do you mean? Arch works the same way as Ubuntu; there's a package manager, you use it to install software from the system repositories. `apt-get install vlc` is no easier or more user friendly than `pacman -S vlc`. I imagine gnome-software even works it does in Ubuntu, though I haven't tried using it. The only difference is that Arch updates their repos' packages as soon as a new version is available upstream (a…

I meant the LTS model such as Ubuntu 18.04 gives you old version software with the possibility of worse functionality and more security holes. Arch may be more up-to-date than Ubuntu, but it isn't in the same category; it is not LTS, and it is not as widespread.

I was mostly responding to the part about how "The distribution model has the advantage of single click install". What's the difference in how "single click" installation can be between rolling and LTS?

Re: About the “Security Issue” on VLC

#135
post #76

Gizmodo posts the headline on their front page, "You Might Want to Uninstall VLC. Immediately" Following the debunking of the story, what does Gizmodo do? Leave it on the front page and change the headline to "You Might Want to Uninstall VLC. Immediately [Updated]"

Lifehacker (which is part of the same blog network) posted "Wait Before Uninstalling VLC from Your Computer." They're trying to get all the clicks from every angle.

Re: About the “Security Issue” on VLC

#136
post #111

Completely OT: does anyone else find this style of posting stuff on a very long twitter thread hard to read, and somewhat worrying in terms of dependency on a proprietary platform? Why can't this be upfront on the videolan.org homepage and just linked from a single tweet?

For more publicity.

Re: About the “Security Issue” on VLC

#138
post #111

Completely OT: does anyone else find this style of posting stuff on a very long twitter thread hard to read, and somewhat worrying in terms of dependency on a proprietary platform? Why can't this be upfront on the videolan.org homepage and just linked from a single tweet?

For more publicity.

This is, unfortunately, the answer. Whenever we post something, unless it is on Twitter, noone reads it.

Re: About the “Security Issue” on VLC

#139
post #101
post #76

Gizmodo posts the headline on their front page, "You Might Want to Uninstall VLC. Immediately" Following the debunking of the story, what does Gizmodo do? Leave it on the front page and change the headline to "You Might Want to Uninstall VLC. Immediately [Updated]"

They actually did. >You Might Want to Uninstall VLC. Immediately. [Updated: Maybe Not] Is the current title...

"Maybe not." These journalists...

Re: About the “Security Issue” on VLC

#140
post #30
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

If VLC was a commercial product, this would be a lawyer time for effectively damaging reputation based upon lies and would see many media outlet dragged over the coals. VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction. Maybe we need…

Isn't that what the Software Freedom Conservancy does?
Post reply on HN