Live data from Hacker News

FFmpeg to Google: Fund us or stop sending bugs

thenewstack.io

51–60 of 913 posts

Re: FFmpeg to Google: Fund us or stop sending bugs

#51
post #32
post #15

"They could shut down three product lines with an email" If you (Amazon, in this case) can put it that way, it seems like throwing them 10 or 20 thousand a year would simply be a good insurance policy! Any benefits you might get in goodwill and influence are a bonus.

How do you think Jeff got a 500 million dollars yacht? Not by writing checks. But on a more serious note, it is crazy that between Google and Amazon they can not fund them with 50k each per year, so that they can pay people to work on this. Specially Google, with Youtube, they can very easily pay them more. 100k~200k easily.

What's wild is the importance and impact of the work/tool. And for google and Amazon, $50k-$100k/yr isn't even a single engineer salary to them ...

And they get the tool + community good will, all for a rounding error on any part of their budgets...

Re: FFmpeg to Google: Fund us or stop sending bugs

#52
post #31

Earlier quoted context omitted.

It’s not bug reports. It’s CVE. There is a convergence of very annoying trends happening: more and more are garbage found and written using AI and with an impact which is questionable at best, the way CVE are published and classified is idiotic and platform founding vulnerability research like Google are more and more hostile to projects leaving very little time to actually work on fixes before publishing. This is le…

The lowered lead times are because devs have an entitled additude that others fix their code when they discover bugs in it. The 90 day period is the grace period for the dev, not a demand. If they don't want to fix it then it goes public.

It is super strange to say that who devoted their time and effort and then gives away their work for free is somehow entitled.

If this keeps up, there won't be anyone willing to maintain the software due to burn out.

In today's situation, free software is keeping many companies honest. Losing that kind of leverage would be a loss to the society overall.

And the public disclosure is going to hurt the users which could include defense, banks and other critical institutions.

Re: FFmpeg to Google: Fund us or stop sending bugs

#53
post #20

A bunch of people who make era-defining software for free. A labor of love. Another bunch of people who make era-defining software where they extract everything they can. From customers, transactionally. From the first bunch, pure extraction (slavery, anyone?).

Irrespective of what Google does, security research is still useful for all of us. They could adopt a more flexible policy for FOSS though.

Or they could contribute solutions to said bugs? Its not like they would distract that much from their bottom line

Re: FFmpeg to Google: Fund us or stop sending bugs

#54
From TFA this was telling:

Thus, as Mark Atwood, an open source policy expert, pointed out on Twitter, he had to keep telling Amazon to not do things that would mess up FFmpeg because, he had to keep explaining to his bosses that “They are not a vendor, there is no NDA, we have no leverage, your VP has refused to help fund them, and they could kill three major product lines tomorrow with an email. So, stop, and listen to me … ”

I agree with the headline here. If Google can pay someone to find bugs, they can pay someone to fix them. How many time have managers said "Don't come to me with problems, come with solutions"

Re: FFmpeg to Google: Fund us or stop sending bugs

#56

Earlier quoted context omitted.

It’s not bug reports. It’s CVE. There is a convergence of very annoying trends happening: more and more are garbage found and written using AI and with an impact which is questionable at best, the way CVE are published and classified is idiotic and platform founding vulnerability research like Google are more and more hostile to projects leaving very little time to actually work on fixes before publishing. This is le…

CVEs aren't caused by bugs?

You could argue that, but I think that a bug is the software failing to do what it was specified, or what it promised to do. If security wasn't promised, it's not a bug.

Re: FFmpeg to Google: Fund us or stop sending bugs

#57
post #32

Earlier quoted context omitted.

How do you think Jeff got a 500 million dollars yacht? Not by writing checks. But on a more serious note, it is crazy that between Google and Amazon they can not fund them with 50k each per year, so that they can pay people to work on this. Specially Google, with Youtube, they can very easily pay them more. 100k~200k easily.

What's wild is the importance and impact of the work/tool. And for google and Amazon, $50k-$100k/yr isn't even a single engineer salary to them ... And they get the tool + community good will, all for a rounding error on any part of their budgets...

Exactly.

That is why I said easily 100~200k. It will be a rounding error for them.

It is actually crazy that Google is not already hiring the main dev to work on ffmpeg with all the use they give it on Youtube.

I also wonder if it is maybe used by Netflix also.

Re: FFmpeg to Google: Fund us or stop sending bugs

#58
post #42
post #24

Earlier quoted context omitted.

My takeaway from the article was not that the report was a problem, but a change in approach from Google that they’d disclose publicly after X days, regardless of if the project had a chance to fix it. To me its okay to “demand” from a for profit company (eg google) to fix an issue fast. Because they have ressources. But to “demand” that an oss project fix something with a certain (possibly tight) timeframe.. well I’…

That is standard practice. It is considered irresponsible to not publicly disclose any vulnerability. The X days is a concession to the developers that the public disclosure will be delayed to give them an opportunity to address the issue.

The entire conflict here is that norms about what's considered responsible were developed in a different context, where vulnerability reports were generated at a much lower rate and dedicated CVE-searching teams were much less common. FFmpeg says this was "AI generated bug reports on an obscure 1990s hobby codec"; if that's accurate (I have no reason to doubt it, just no time to go check), I tend to agree that it doesn't make sense to apply the standards that were developed for vulnerabilities like "malicious PNG file crashes the computer when loaded".

Re: FFmpeg to Google: Fund us or stop sending bugs

#59
post #49
post #32

Earlier quoted context omitted.

How do you think Jeff got a 500 million dollars yacht? Not by writing checks. But on a more serious note, it is crazy that between Google and Amazon they can not fund them with 50k each per year, so that they can pay people to work on this. Specially Google, with Youtube, they can very easily pay them more. 100k~200k easily.

Double funny considering new-grads who may polish up some UI features or rewrite components for the 10th time will get paid 200-400K TC at these same companies. Evidently these companies value something other than straight labor.

Yeah, sadly crazy.

Re: FFmpeg to Google: Fund us or stop sending bugs

#60
post #24

I’m an open source maintainer, so I empathize with the sentiment that large companies appear to produce labor for unpaid maintainers by disclosing security issues. But appearance is operative: a security issue is something that I (as the maintainer) would need to fix regardless of who reports it, or would otherwise need to accept the reputational hit that comes with not triaging security reports. That’s sometimes per…

My takeaway from the article was not that the report was a problem, but a change in approach from Google that they’d disclose publicly after X days, regardless of if the project had a chance to fix it. To me its okay to “demand” from a for profit company (eg google) to fix an issue fast. Because they have ressources. But to “demand” that an oss project fix something with a certain (possibly tight) timeframe.. well I’…

> My takeaway from the article was not that the report was a problem, but a change in approach from Google that they’d disclose publicly after X days, regardless of if the project had a chance to fix it.

That is not an accurate description? Project Zero was using a 90 day disclosure policy from the start, so for over a decade.

What changed[0] in 2025 is that they disclose earlier than 90 days that there is an issue, but not what the issue is. And actually, from [1] it does not look like that trial policy was applied to ffmpeg.

> To me its okay to “demand” from a for profit company (eg google) to fix an issue fast. Because they have ressources. But to “demand” that an oss project fix something with a certain (possibly tight) timeframe.. well I’m sure you better than me, that that’s not who volunteering works

You clearly know that no actual demands or even requests for a fix were made, hence the scare quotes. But given you know it, why call it a "demand"?

[0] https://googleprojectzero.blogspot.com/2025/07/reporting-tra..., discussed at https://news.ycombinator.com/item?id=44724287

[1] https://googleprojectzero.blogspot.com/p/reporting-transpare...

Post reply on HN