Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

121–130 of 174 posts

Re: About the “Security Issue” on VLC

#121
post #17

Earlier quoted context omitted.

By that token, is there ANY application where the attack vector is not 'network' and 'remote' is 'no'? Because I fail to think of any minimally-useful app that doesn't open external files.

Calculator?

True dat. And Solitaire, I guess :)

Re: About the “Security Issue” on VLC

#122
post #21

libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe... I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end use…

> I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end users. I'm there with you. I use a rolling distro (Arch) and I update all packages to the latest versions whenever I'm bored. I do this because I can't remember the last time something broke this way. I've been doing that for ~6 years on 3 different machines. On the other hand, a…

> at least for desktop use-cases, what exactly is gained

No surprise there. Those aren't really for desktop use. Most "stable" distros users are servers.

If you are a desktop user you probably want your new shiny Firefox or LibreOffice as soon as possible, so you run either a six month cadence (Ubuntu, Fedora) or rolling (Debian testing, SuSE Tumbleweed, Gentoo). The latter can have a bit of light breakage for time to time so the six month cadence is probably a better fit for most casual users.

Re: About the “Security Issue” on VLC

#123
post #30
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

If VLC was a commercial product, this would be a lawyer time for effectively damaging reputation based upon lies and would see many media outlet dragged over the coals. VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction. Maybe we need…

Remember the Bloomberg Supermicro story? If a billion-dollar company cannot get Bloomberg to retract their stories, what chance does an open source project have?

Has any American newspaper or person or politician on twitter been forced to retract exaggerated claims?

Re: About the “Security Issue” on VLC

#124
post #10
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...

Thank you for your contributions on VLC.

It shines bad light on the official institutions that they haven't checked back with you.

Re: About the “Security Issue” on VLC

#125
post #111

Completely OT: does anyone else find this style of posting stuff on a very long twitter thread hard to read, and somewhat worrying in terms of dependency on a proprietary platform? Why can't this be upfront on the videolan.org homepage and just linked from a single tweet?

Change the twitter domain:

https://twitter.com/videolan/status/1153963312981389312

to:

https://threadreaderapp.com/videolan/status/1153963312981389...

Re: About the “Security Issue” on VLC

#126
post #116

Earlier quoted context omitted.

Nonsense. “Responsible disclosure” is a term coined by vendors to shame researchers who don’t play ball. There’s no implicit “bad faith” in full disclosure or even the sale of weaponized 0day exploits.

Oh this trope again. I am no vendor and I fully support the idea that security researchers coordinate their publication activities with affected parties.

[deleted]

Re: About the “Security Issue” on VLC

#127
post #101

Earlier quoted context omitted.

They actually did. >You Might Want to Uninstall VLC. Immediately. [Updated: Maybe Not] Is the current title...

Its amazing how a title can have two entirely contradictory, non committal claims telling you to do a thing, and yet tell me absolutely nothing useful.

Will you still read Gizmodo or consider it a trustable source?

Re: About the “Security Issue” on VLC

#128
post #80
post #44

Earlier quoted context omitted.

I'd argue that, in a dynamically linked system, the onus in on the system maintainer, not the application developer, to fix these issues.

And in this case, it was apparently the system maintainer that introduced the bugs. (By patching VLC to use a shared, outdated, and insecure library instead of the one the developers shipped it with). This puts a very bad taste in my mouth re the GNU+Linux ecosystem. Being able to specify “use this version at minimum” is a critical feature of any dependency management system, and it seems like distributions don’t rea…

[deleted]

Re: About the “Security Issue” on VLC

#129
post #80
post #44

Earlier quoted context omitted.

I'd argue that, in a dynamically linked system, the onus in on the system maintainer, not the application developer, to fix these issues.

And in this case, it was apparently the system maintainer that introduced the bugs. (By patching VLC to use a shared, outdated, and insecure library instead of the one the developers shipped it with). This puts a very bad taste in my mouth re the GNU+Linux ecosystem. Being able to specify “use this version at minimum” is a critical feature of any dependency management system, and it seems like distributions don’t rea…

[deleted]

Re: About the “Security Issue” on VLC

#130
post #127

Earlier quoted context omitted.

Its amazing how a title can have two entirely contradictory, non committal claims telling you to do a thing, and yet tell me absolutely nothing useful.

Will you still read Gizmodo or consider it a trustable source?

I read gizmodo every once in a while for mild entertainment. I have never considered it, or anything related to Kinja, to be trustworthy in any shape or form.
Post reply on HN