Earlier quoted context omitted.
I meant the LTS model such as Ubuntu 18.04 gives you old version software with the possibility of worse functionality and more security holes. Arch may be more up-to-date than Ubuntu, but it isn't in the same category; it is not LTS, and it is not as widespread.
I was mostly responding to the part about how "The distribution model has the advantage of single click install". What's the difference in how "single click" installation can be between rolling and LTS?
About the “Security Issue” on VLC
151–160 of 174 posts
Re: About the “Security Issue” on VLC
#152Earlier quoted context omitted.
I was mostly responding to the part about how "The distribution model has the advantage of single click install". What's the difference in how "single click" installation can be between rolling and LTS?
The point is classic distributions which support their product for a long time (Debian, Ubuntu,RHEL,Centos) are easier to use for basic users you can meet on street. With Arch or Gentoo, you are right that there is a package manager which makes installation of software easier, but the system is not easy to use for BFUs. When problems with installation/upgrades arise (which is more likely for Arch/Gentoo), you are exp…
Re: About the “Security Issue” on VLC
#153Earlier quoted context omitted.
Stretch is supposed to keep getting security fixes until June 2022 but this particular library doesn't have the fix backported yet: https://security-tracker.debian.org/tracker/CVE-2019-13615
Does anybody know why libebml wasn't fixed yet in Stretch?
Re: About the “Security Issue” on VLC
#154So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...
Re: About the “Security Issue” on VLC
#155So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
This problem has been around as long as more than one news outlet has been around... Getting the story first over getting the story right didn't get invented by online news.
Re: About the “Security Issue” on VLC
#156>The reporter is using Ubuntu 18.04, which is an old version of Ubuntu, and clearly has not all the updated libraries.
18.04 is an LTS version, many people (myself included) will be using this until 20.04 comes out next year! It is not old - it gets regular updates for both security and features - clearly the library for whatever reason is excluded.
Re: About the “Security Issue” on VLC
#157Earlier quoted context omitted.
If VLC was a commercial product, this would be a lawyer time for effectively damaging reputation based upon lies and would see many media outlet dragged over the coals. VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction. Maybe we need…
Isn't that what the Software Freedom Conservancy does?
I'm not sure, doesn't look like this would fall under their remit, but no definitive yes or no jumping out for me either.
https://en.wikipedia.org/wiki/Software_Freedom_Conservancy
Not a long litigation list either, so hard to see any comparable cases in the two instances listed.
So I'm going to lean against a no, but I'm not 100% sure upon this.
Re: About the “Security Issue” on VLC
#158Earlier quoted context omitted.
Yes, hence they don't have a lawyer ontap, which was kinda the point I was making. The education (what I'm going to call it) that they could bestow upon these bismershing media outlets, would fund much Open Source work for VLC.
You say “they don’t have a lawyer” I don’t know if you realize you’re addressing the lead developer and president of VLC. I think he may be quite a bit more aware of his org’s ability and desire to retain legal counsel than all of us.
Re: About the “Security Issue” on VLC
#159So none of the tech news websites contacted VideoLAN and published their articles without checking their source. I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second. I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
> So none of the tech news websites contacted VideoLAN and published their articles without checking their source. Actually, one did: numerama. That's all. > I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago. My night and morning have been difficult, as you can imagine...
Please keep up the awesome work, VLC is a treasure.
Re: About the “Security Issue” on VLC
#160libebml is in the Ubuntu universe repository which means that it is not supported by Canonical. And in the Debian changelog for this package I don't see any mentions of a security issue that was fixed 16 months ago: https://metadata.ftp-master.debian.org/changelogs//main/libe... I am loosing more and more confidence that these "package the world and freeze everything in place" distros are the right choice for end use…
So the problem is VLC using unstable dependencies without a mature release cycle.