Live data from Hacker News

FFmpeg to Google: Fund us or stop sending bugs

thenewstack.io

471–480 of 913 posts

Re: FFmpeg to Google: Fund us or stop sending bugs

#471
post #461

Earlier quoted context omitted.

From my time working at a Fortune 100 company, if I ever mentioned pushing even small patches to libraries we effing used , I'd just be met "try to focus on your tickets". Their OSS library and policies were also super byzantine, seemingly needing review of everything you'd release, but the few times I tried to do it the official way, I just never heard anything back from the black-hole mailing list you were supposed…

Those aren’t tech giants. They're just shit companies. I agree they greatly outnumber Big Tech, in employees if not talent.

Check again. The Optum unit of UnitedHealth Group has huge revenue from software and technical services. If just that part of the business was spun out it would be one of the top 20 US tech companies.

Re: FFmpeg to Google: Fund us or stop sending bugs

#472

Earlier quoted context omitted.

I would love to see Google contribute here, but I think that's a different issue. Are the bug reports accurate? If so, then they are contributing just as if I found them and sent a bug report, I'd be contributing. Of course a PR that fixes the bug is much better than just a report, but reports have value, too. The alternative is to leave it unfound, which is not a better alternative in my opinion. It's still there an…

But FFmpeg does not have the resources to fix these at the speed Google is finding them. It's just not possible. So Google is dedicating resources to finding these bugs and feeding them to bad actors. Bad actors who might, hypothetically have had the information before, but definitely do once Google publicizes them. You are talking about an ideal situation; we are talking about a real situation that is happening in t…

If widely deployed infrastructure software is so full of vulnerabilities that its maintainers can't fix them as fast as they're found, maybe it shouldn't be widely deployed, or they shouldn't be its maintainers. Disabling codecs in the default build that haven't been used in 30 years might be a good move, for example.

Either way, users need to know about the vulnerabilities. That way, they can make an informed tradeoff between, for example, disabling the LucasArts Smush codec in their copy of ffmpeg, and being vulnerable to this hole (and probably many others like it).

Re: FFmpeg to Google: Fund us or stop sending bugs

#473

I’m an open source maintainer, so I empathize with the sentiment that large companies appear to produce labor for unpaid maintainers by disclosing security issues. But appearance is operative: a security issue is something that I (as the maintainer) would need to fix regardless of who reports it, or would otherwise need to accept the reputational hit that comes with not triaging security reports. That’s sometimes per…

If google bears no role in fixing the issues it finds and nobody else is being paid to do it either, it functionally is just providing free security vulnerability research for malicious actors because almost nobody can take over or switch off of ffmpeg.

This is a weird argument. Basically condoning security through obscurity: If nobody reports the bug then we just pretend it doesn’t exist, right?

There are many groups searching for security vulnerabilities in popular open source software who deliberately do not disclose them. They do this to save them for their own use or even to sell them to bad actors.

It’s starting to feel silly to demonize Google for doing security research at this point.

Re: FFmpeg to Google: Fund us or stop sending bugs

#474

Never work for free. It's a complete market distortion and leads to bad actors taking advantage of you and your work.

I've grown a bit disillusioned with contributing to Github.

I've said this on here before, but a few months ago I wrote a simple patch for LMAX Disruptor, which was merged in. I like Disruptor, it's a very neat library, and at first I thought it was super cool to have my code merged.

But after a few minutes, I started thinking: I just donated my time to help a for-profit company make more money. LMAX isn't a charity, they're trading company, and I donated my time to improve their software. They wouldn't have merged my code in if they didn't think it had some amount of value, and if they think it has value then they should pay me.

I'm not very upset over this particular example since my change was extremely simple and didn't take much time at all to implement (just adding annotations to interfaces), so I didn't donate a lot of labor in the end, but it still made me think that maybe I shouldn't be contributing to every open source project I use.

Re: FFmpeg to Google: Fund us or stop sending bugs

#475

Earlier quoted context omitted.

Google is, at no cost to FFMPEG: 1) dedicating compute resources to continuously fuzzing the entire project 2) dedicating engineering resources to validating the results and creating accurate and well-informed bug reports (in this case, a seriously underestimated security issue) 3) additionally for codecs that Google likely does not even internally use or compile, purely for the greater good of FFMPEG's user base Nee…

Google is: - choosing to do this of their own volition - are effectively just using their resources to throw bug reports over the wall unprompted. - benefiting from the bugs getting fixed, but not contributing to them.

FFmpeg and a thousand fixes:

https://j00ru.vexillium.org/2014/01/ffmpeg-and-the-tale-of-a...

"While reading about the 4xm demuxer vulnerability, we thought that we could help FFmpeg eliminate many potential low-hanging problems from the code by making use of the Google fleet and fuzzing infrastructure we already had in place"

Re: FFmpeg to Google: Fund us or stop sending bugs

#476

A bunch of people who make era-defining software for free. A labor of love. Another bunch of people who make era-defining software where they extract everything they can. From customers, transactionally. From the first bunch, pure extraction (slavery, anyone?).

> (slavery, anyone?)

It’s hard to take any comment seriously that tries to use “slavery” for situations where nobody is forced to do anything for anyone.

Re: FFmpeg to Google: Fund us or stop sending bugs

#477
post #341

Earlier quoted context omitted.

From TFA: > The latest episode was sparked after a Google AI agent found an especially obscure bug in FFmpeg. How obscure? This “medium impact issue in ffmpeg,” which the FFmpeg developers did patch, is “an issue with decoding LucasArts Smush codec, specifically the first 10-20 frames of Rebel Assault 2, a game from 1995.” This doesn't feel like a medium-severity bug, and I think "Perhaps reconsider the severity" is…

The vulnerability in question is being severely underestimated. There are many other comments in this thread going into detail. UAF = RCE.

Use-after-free bugs (such as the vulnerability in question, https://issuetracker.google.com/issues/440183164) usually can be exploited to result in remote code execution, but not always. It wouldn't be prudent to bet that this case is one of the exceptions, of course.

Re: FFmpeg to Google: Fund us or stop sending bugs

#478

It'd be a silly license or condition, but, a license that says employees of companies in the S&P500 cant file bugs without an $X contribution, and cant expect a response in under Y days without a larger one, would be a funny way to combat it. Companies have no problem making software non-free or AGPL when it becomes inconvenient so maybe they can put up or shut up.

> cant file bugs without an $X contribution, and cant expect a response in under Y days

A license to define that nobody can expect a response? Or file bugs?

None of this has anything to do with the issue. They can just turn off Google’s access to the bug tracker. No license needed.

However Google is free to publish security research they find.

It would be most concerning if projects started including “Nobody is allowed to do security research on this project” licenses. Who would benefit from that?

Re: FFmpeg to Google: Fund us or stop sending bugs

#479
post #372

Earlier quoted context omitted.

> Valve is the only company I know of [upstreaming fixes for open source software] Sorry, that's ridiculous. Basically every major free software dependency of every major platform or application is maintained by people on the payroll of one or another tech giant (edit: or an entity like LF or Linaro funded by the giants, or in a smaller handful of cases a foundation like the FSF with reasonably deep industry funding)…

From my time working at a Fortune 100 company, if I ever mentioned pushing even small patches to libraries we effing used , I'd just be met "try to focus on your tickets". Their OSS library and policies were also super byzantine, seemingly needing review of everything you'd release, but the few times I tried to do it the official way, I just never heard anything back from the black-hole mailing list you were supposed…

I don't know about ExxonMobil but Walmart, UnitedHealth Group, and JPMorganChase employees do actively contribute to open source projects. Maybe just not the ones you used. They have also published some of their own.

https://github.com/walmartlabs

https://github.com/Optum

https://github.com/jpmorganchase

Re: FFmpeg to Google: Fund us or stop sending bugs

#480

Never work for free. It's a complete market distortion and leads to bad actors taking advantage of you and your work.

That's fine. Are they required to work for Google? I mean, they are independent and can decide on their own.

Nearly everyone here probably knows someone who has done free labor and "worked for exposure", and most people acknowledge that this is a scam, and we don't have a huge issue condemning the people running the scam. I've known people who have done free art commissions because of this stuff, and this "exposure" never translated to money.

Are the people who got scammed into "working for exposure" required to work for those people?

No, of course not, no one held a gun to their head, but it's still kind of crappy. The influencers that are "paying in exposure" are taking advantage of power dynamics and giving vague false promises of success in order to avoid paying for shit that they really should be paying for.

Post reply on HN