Live data from Hacker News

We found a division by zero bug in FFmpeg with a vibecoded fuzzer

code.ffmpeg.org

211–220 of 274 posts

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#212

Earlier quoted context omitted.

It crashes because of input that should have been rejected for being invalid. How could that be construed as being benign?

Because an attacker would not gain anything he not already has. This is basically local self-DOS.

That's not a quality of ffmpeg or this bug, but of the application you use it for. If you only expose your ffmpeg-based application to your own input then yes, of course it's a self-DOS. But if you, say, expose it as a web service passing arbitrary user input to ffmpeg, that no longer holds.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#213

Earlier quoted context omitted.

It's puzzling how mild the reactions are to Anubis compared to the people reacting to seeing one singular Cloudflare captcha checkbox. I'd much rather a checkbox than a brief CPU-intensive hashing session.

Anubis is usually less obtrusive than that, though. This is the longest anubis challenge I've ever had, to the point of being absurd. Hopefully they have a genuine reason for having set the difficulty so high.

I wonder if it's a bug/issue with specific browsers.

It's near instant on desktop (Windows/FF/7950X3D) and I wouldn't expect the delta to be that large against a modern mobile device.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#214

Earlier quoted context omitted.

Oddly enough I can’t access that site, it just heats up my phone solving hashes. Gave up after about a minute and anubis had only made it less than halfway through. I doubt the real bots have any trouble bypassing it.

It's puzzling how mild the reactions are to Anubis compared to the people reacting to seeing one singular Cloudflare captcha checkbox. I'd much rather a checkbox than a brief CPU-intensive hashing session.

Cloudflare checkboxes don't come with pictures of underage girls

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#215

Earlier quoted context omitted.

It's puzzling how mild the reactions are to Anubis compared to the people reacting to seeing one singular Cloudflare captcha checkbox. I'd much rather a checkbox than a brief CPU-intensive hashing session.

Cloudflare checkboxes don't come with pictures of underage girls

Why do you have a problem with this?

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#216
IDK seems like a bug that could've taken a human a few minutes at best to find. I found a bug in SystemD that would crash the daemon because a bad SystemD unit file configuration. That took me like 5 minutes to actually track down in the actual source code.

I understand the utility of this though, I just don't see this particular bug and something that would be particularly difficult o find pre LLM era.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#217

Earlier quoted context omitted.

Anubis is usually less obtrusive than that, though. This is the longest anubis challenge I've ever had, to the point of being absurd. Hopefully they have a genuine reason for having set the difficulty so high.

I wonder if it's a bug/issue with specific browsers. It's near instant on desktop (Windows/FF/7950X3D) and I wouldn't expect the delta to be that large against a modern mobile device.

> I wonder if it's a bug/issue with specific browsers.

Seems like it. It loaded near instantly as well from my Android smartphone using Firefox.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#218

Earlier quoted context omitted.

It's puzzling how mild the reactions are to Anubis compared to the people reacting to seeing one singular Cloudflare captcha checkbox. I'd much rather a checkbox than a brief CPU-intensive hashing session.

A zero-interaction screen is better. If I can open it in a new tab and then come back and it's fully loaded, it's good.

Unfortunately, those tools are there specifically to detect and block "zero-interaction activity".

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#219

Earlier quoted context omitted.

Oddly enough I can’t access that site, it just heats up my phone solving hashes. Gave up after about a minute and anubis had only made it less than halfway through. I doubt the real bots have any trouble bypassing it.

It's puzzling how mild the reactions are to Anubis compared to the people reacting to seeing one singular Cloudflare captcha checkbox. I'd much rather a checkbox than a brief CPU-intensive hashing session.

Solving one captcha is mildly annoying. Being trapped in an infinite captcha loop will really grind your gears and eat away at your spirit.

Having my CPU go up for a while is nearly frictionless on the other hand. Worst case I'm stuck in a loop and the site isn't loaded when I get back to it, which is better than being stuck in a captcha loop and then not getting to the site.

Of course, not having to do any of that would be even better. I wish the concept of ZeroNet had caught on, where everything is hosted and served peer-to-peer. This gives you basically zero hosting costs and you are immune to DDOS.

Re: We found a division by zero bug in FFmpeg with a vibecoded fuzzer

#220
post #193

Earlier quoted context omitted.

Oddly enough I can’t access that site, it just heats up my phone solving hashes. Gave up after about a minute and anubis had only made it less than halfway through. I doubt the real bots have any trouble bypassing it.

It took around 15kJ to access the site... that's a proper waste and somewhat sad, even though I understand.

So, about $0.001 of electricity. The nerve!
Post reply on HN