Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

161–170 of 174 posts

Re: About the “Security Issue” on VLC

#161

Earlier quoted context omitted.

> I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users. I'm there with you. I use a rolling distro (Arch) and I update all packages to the latest versions whenever I'm bored. I do this because I can't remember the last time something broke this way. I've been doing that for ~6 years on 3 different machines. On the other hand, a…

> at least for desktop use-cases, what exactly is gained No surprise there. Those aren't really for desktop use. Most "stable" distros users are servers. If you are a desktop user you probably want your new shiny Firefox or LibreOffice as soon as possible, so you run either a six month cadence (Ubuntu, Fedora) or rolling (Debian testing, SuSE Tumbleweed, Gentoo). The latter can have a bit of light breakage for time t…

> If you are a desktop user you probably want your new shiny Firefox or LibreOffice as soon as possible

If you're an enthusiast you want that (and most linux users are probably enthusiasts), but most people just want something to work and remain static and aren't remotely interested in whatever new experiment firefox is unleashing on users.

Re: About the “Security Issue” on VLC

#162
post #21

libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe... I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end use…

> I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users. I'm there with you. I use a rolling distro (Arch) and I update all packages to the latest versions whenever I'm bored. I do this because I can't remember the last time something broke this way. I've been doing that for ~6 years on 3 different machines. On the other hand, a…

I'd agree with you there. I run Arch on my home computer and update fully pretty much every time I use it (because it's so fast to update everything) and I think I've only had 1 breaking change in ~5 years.

Re: About the “Security Issue” on VLC

#163
gizmodo.com.au still shows "You Might Want To Uninstall VLC. Right Now. Immediately." in their title. This highlights the untrustworthiness of most "news" today, be it software, politics or business related. It's unbelievable how poorly researched articles can damage people and businesses alike. I think is this is one of the biggest pain points of today's world, and it needs solving fast.

Re: About the “Security Issue” on VLC

#164
post #10
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...

Thank you for VLC. It has literally been the only software that I've ever donated towards.

Re: About the “Security Issue” on VLC

#165
post #161

Earlier quoted context omitted.

> at least for desktop use-cases, what exactly is gained No surprise there. Those aren't really for desktop use. Most "stable" distros users are servers. If you are a desktop user you probably want your new shiny Firefox or LibreOffice as soon as possible, so you run either a six month cadence (Ubuntu, Fedora) or rolling (Debian testing, SuSE Tumbleweed, Gentoo). The latter can have a bit of light breakage for time t…

> If you are a desktop user you probably want your new shiny Firefox or LibreOffice as soon as possible If you're an enthusiast you want that (and most linux users are probably enthusiasts), but most people just want something to work and remain static and aren't remotely interested in whatever new experiment firefox is unleashing on users.

As much as I hate to say it, that ship has probably sailed. If you surf the web in 2019 you're likely using javascript and you need an updated web browser. The attack surface on those things are enormous.

Re: About the “Security Issue” on VLC

#166
post #21

libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe... I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end use…

> I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users. I'm there with you. I use a rolling distro (Arch) and I update all packages to the latest versions whenever I'm bored. I do this because I can't remember the last time something broke this way. I've been doing that for ~6 years on 3 different machines. On the other hand, a…

> I run a lot of machines on Ubuntu LTS

If you don't like frozen packages, why are you using Ubuntu LTS? Ubuntu provides an updated stable release every six months if you want something closer to rolling. But most Ubuntu users, not even desktop users, use that. The market is speaking, and it wants stable releases frozen for years at a time.

It is a contradiction to demand both.

Re: About the “Security Issue” on VLC

#167
post #10
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...

[deleted]

Re: About the “Security Issue” on VLC

#168
post #166

Earlier quoted context omitted.

> I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users. I'm there with you. I use a rolling distro (Arch) and I update all packages to the latest versions whenever I'm bored. I do this because I can't remember the last time something broke this way. I've been doing that for ~6 years on 3 different machines. On the other hand, a…

> I run a lot of machines on Ubuntu LTS If you don't like frozen packages, why are you using Ubuntu LTS? Ubuntu provides an updated stable release every six months if you want something closer to rolling. But most Ubuntu users, not even desktop users, use that. The market is speaking, and it wants stable releases frozen for years at a time. It is a contradiction to demand both.

I run servers on Ubuntu LTS, my personal machines on Arch. Frozen packages are great for servers but for desktops I just don't see the benefit. Hence my comment.

Re: About the “Security Issue” on VLC

#169
post #156

I'm sorry but this is a shitty response from VLC: >The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries. 18.04 is an LTS version, many people (myself included) will be using this until 20.04 comes out next year! It is not old - it gets regular updates for both security and features - clearly the library for whatever reason is excluded.

They aren't blaming you for using the LTS version, and they aren't blaming Ubuntu for having an LTS version. The blame is (implicitly) on Ubuntu for not making sure the libraries their LTS version ships are up to date with the latest security patches. VLC itself isn't vulnerable - the problem is that some distributions are compiling it themselves with old libraries, which is 100% their own fault.

Re: About the “Security Issue” on VLC

#170
post #27

Earlier quoted context omitted.

Just that Ubuntu apparently forgot about the "S" part of "LTS", or they could have updated that package. Alternatively (because libebml is "universe", that is, unsupported), stop ripping out maintained components from projects to "use system packages instead" which are not maintained. It's stuff like this that makes Firefox and Pale Moon play hardball with distros that mess up their software. (nevermind that the Pale…

The actual packages are from Debian, and Debian keeps them updated. Debian stretch (2017) is vulnerable, buster is not. Ubuntu 18.04 LTS is based on buster ( https://askubuntu.com/questions/445487/what-debian-version-a... ) so compatibility isn't the problem. Judging from bugs like https://bugs.launchpad.net/ubuntu/+source/libebml/+bug/14120... the problem is just that nobody at Ubuntu is responsible for keeping it u…

The package in Debian was updated four days before Ubuntu 18.04 was released. That's why the update didn't make 18.04 "automatically".

Since then, both Debian and Ubuntu have acted the same: not knowing about the vulnerability, neither updated their [release] packages. Buster happened to have been updated before it was frozen for release. Stretch was not, and neither was 18.04.

> tl;dr Avoid Ubuntu LTS because they don't maintain their packages properly.

By your logic, you should also avoid Debian then, since they followed the same process here. What got updated and what didn't was merely an accident of calendar freeze dates.

At the time I write this, Debian stretch is still on 1.3.4-1 and hasn't been updated. Ubuntu 18.04 has now been updated.

Post reply on HN