Live data from Hacker News

About the “Security Issue” on VLC

twitter.com

151–160 of 174 posts

Re: About the “Security Issue” on VLC

#151
post #134
post #114

Earlier quoted context omitted.

I meant the LTS model such as Ubuntu 18.04 gives you old version software with the possibility of worse functionality and more security holes. Arch may be more up-to-date than Ubuntu, but it isn't in the same category; it is not LTS, and it is not as widespread.

I was mostly responding to the part about how "The distribution model has the advantage of single click install". What's the difference in how "single click" installation can be between rolling and LTS?

The point is classic distributions which support their product for a long time (Debian, Ubuntu,RHEL,Centos) are easier to use for basic users you can meet on street. With Arch or Gentoo, you are right that there is a package manager which makes installation of software easier, but the system is not easy to use for BFUs. When problems with installation/upgrades arise (which is more likely for Arch/Gentoo), you are expected to spend some time becoming proficient GNU/Linux user who resolves things in command line.

Re: About the “Security Issue” on VLC

#152
post #151
post #134

Earlier quoted context omitted.

I was mostly responding to the part about how "The distribution model has the advantage of single click install". What's the difference in how "single click" installation can be between rolling and LTS?

The point is classic distributions which support their product for a long time (Debian, Ubuntu,RHEL,Centos) are easier to use for basic users you can meet on street. With Arch or Gentoo, you are right that there is a package manager which makes installation of software easier, but the system is not easy to use for BFUs. When problems with installation/upgrades arise (which is more likely for Arch/Gentoo), you are exp…

Citation needed on the number of problems, assuming the classic system is actually being updated from release to release so it can continue to receive critical updates.

Re: About the “Security Issue” on VLC

#153
post #148

Earlier quoted context omitted.

Stretch is supposed to keep getting security fixes until June 2022 but this particular library doesn't have the fix backported yet: https://security-tracker.debian.org/tracker/CVE-2019-13615

Does anybody know why libebml wasn't fixed yet in Stretch?

There was never a CVE for it (until the CVE for VLC) so I'm guessing the Debian Security Team never found out about it.

Re: About the “Security Issue” on VLC

#154
post #10
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...

We all love VLC and know the hard work you put into it, and into keeping it secure. Don't stress too much. The media buzz will die down soon.

Re: About the “Security Issue” on VLC

#155
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

> I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second.

This problem has been around as long as more than one news outlet has been around... Getting the story first over getting the story right didn't get invented by online news.

Re: About the “Security Issue” on VLC

#156
I'm sorry but this is a shitty response from VLC:

>The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries.

18.04 is an LTS version, many people (myself included) will be using this until 20.04 comes out next year! It is not old - it gets regular updates for both security and features - clearly the library for whatever reason is excluded.

Re: About the “Security Issue” on VLC

#157
post #30

Earlier quoted context omitted.

If VLC was a commercial product, this would be a lawyer time for effectively damaging reputation based upon lies and would see many media outlet dragged over the coals. VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction. Maybe we need…

Isn't that what the Software Freedom Conservancy does?

https://sfconservancy.org/about/

I'm not sure, doesn't look like this would fall under their remit, but no definitive yes or no jumping out for me either.

https://en.wikipedia.org/wiki/Software_Freedom_Conservancy

Not a long litigation list either, so hard to see any comparable cases in the two instances listed.

So I'm going to lean against a no, but I'm not 100% sure upon this.

Re: About the “Security Issue” on VLC

#158
post #112
post #55

Earlier quoted context omitted.

Yes, hence they don't have a lawyer ontap, which was kinda the point I was making. The education (what I'm going to call it) that they could bestow upon these bismershing media outlets, would fund much Open Source work for VLC.

You say “they don’t have a lawyer” I don’t know if you realize you’re addressing the lead developer and president of VLC. I think he may be quite a bit more aware of his org’s ability and desire to retain legal counsel than all of us.

I was not, I am now blush. You're right of course.

Re: About the “Security Issue” on VLC

#159
post #10
post #2

So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.

> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...

I don't know if it matters at all, but after hearing the news, I still fired up VLC to watch a few videos because I feel you guys have built up enough credibility and credit that such an extraordinary claim would require extraordinary evidence (which I wasn't seeing) and if there was a problem, your team would fix it ASAP.

Please keep up the awesome work, VLC is a treasure.

Re: About the “Security Issue” on VLC

#160
post #21

libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe... I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end use…

It looks like the problem is that their is no stable version with any long term commitments to security fixes, at least I couldn't find any mention of one on the website or github page. I'm can't see any release branches on github.

So the problem is VLC using unstable dependencies without a mature release cycle.

Post reply on HN