Live data from Hacker News

FFmpeg to Google: Fund us or stop sending bugs

thenewstack.io

561–570 of 913 posts

Re: FFmpeg to Google: Fund us or stop sending bugs

#563

Never work for free. It's a complete market distortion and leads to bad actors taking advantage of you and your work.

I love the spirit of working for free on a project of passion. But yes it only takes a few bad actors to totally exploit it.

use GPL

Re: FFmpeg to Google: Fund us or stop sending bugs

#564
post #42

Earlier quoted context omitted.

That is standard practice. It is considered irresponsible to not publicly disclose any vulnerability. The X days is a concession to the developers that the public disclosure will be delayed to give them an opportunity to address the issue.

Here's the question: Why is Google deliberately running an AI process to find these bugs if they're just going to dump them all on the FFmpeg team to fix? They have the option to pay someone to fix them. They also have the option to not spend resources finding the bugs in the first place. If they think these are so damn important to find that it's worth devoting those resources to, then they can damn well pay for fix…

> They also have the option to not spend resources finding the bugs in the first place.

The Copenhagen interpretation of security bugs: if you don’t look for it, it doesn’t exist and is not a problem.

Re: FFmpeg to Google: Fund us or stop sending bugs

#565

Earlier quoted context omitted.

The difference is that Google does use it, though. They use it heavily. All of us in the video industry do - Google, Amazon, Disney, Sony, Viacom, or whoever. Companies you may have never heard of build it into their solutions that are used by big networks and other streaming services, too.

Right, Google absolutely should fund ffmpeg. But opening security issues here is not related to that in any way. It's an obscure file format Google definitely doesn't use, the security issue is irrelevant to Google's usages of it. The critique would make sense if Google was asking for ffmpeg to implement something that Google wanted, instead of sending a patch. But they don't actually care about this one, they aren't…

Google absolutely does fund ffmpeg via SPI.

"and Google provided substantial donations to SPI's general fund".

The amounts don't appear to be public (and what is enough!?)

Re: FFmpeg to Google: Fund us or stop sending bugs

#566

I’m an open source maintainer, so I empathize with the sentiment that large companies appear to produce labor for unpaid maintainers by disclosing security issues. But appearance is operative: a security issue is something that I (as the maintainer) would need to fix regardless of who reports it, or would otherwise need to accept the reputational hit that comes with not triaging security reports. That’s sometimes per…

Sure, but this is about Google funding FFmpeg not providing bug fixes.

Re: FFmpeg to Google: Fund us or stop sending bugs

#568
post #444

Earlier quoted context omitted.

Did you see how the FFMPEG project patched a bug for a 1995 console? That's not a good use for the limited amount of volunteers on the project. It actively makes it less secure by taking away from more pertinent bugs.

Then they should mark it as low priority and put it in their backlog. I trust that the maintainers are good judges of what deserves their time.

Publicizing vulnerabilities is the problem though. Google is ensuring obscure or unknown vulnerabilities will now be very well known and very public.

This is significant when they represent one of the few entities on the planet likely able to find bugs at that scale due to their wealth.

So funding a swarm of bug reports, for software they benefit from, using a scale of resources not commonly available, while not contributing fixes and instead demanding timelines for disclosure, seems a lot more like they'd just like to drive people out of open source.

Re: FFmpeg to Google: Fund us or stop sending bugs

#569
post #324

Earlier quoted context omitted.

They could, but there is really no requirement on them to do so. The security flaw was discovered by Google, but it was not created by them. Equally there is no requirement on ffmpeg to fix these CVEs nor any other. And, of course, there is no requirement on end-users to run software from projects which do not consider untrusted-input-validation bugs to be high priority.

> They could, but there is really no requirement on them to do so. I see this sort of sentiment daily. The sentiment that only what is strictly legal or required is what matters. Sometimes, you know, you have to recognise that there are social norms and being a good person matters and has intrinsic value. A society only governed by what the written law of the land explicitly states is a dystopia worse than hell.

Justice is more than just following laws.

Re: FFmpeg to Google: Fund us or stop sending bugs

#570

Earlier quoted context omitted.

I'm glad you threw in "I know of", because that part is true. Feel free to read lore.kernel.org, and sort out where the people contributing many patches actually work.

I'd say as a counterpoint that just because someone works at, say, Meta or Oracle, and also contributes to OSS projects, that doesn't equate to the company they work at funding upstream projects (at least not by itself). I don't even have to link the xkcd comic because everyone already knows which one goes here.

Well, if they use their work email, doesn't that mean their kernel work is endorsed by their employer?
Post reply on HN