Live data from Hacker News

FFmpeg to Google: Fund us or stop sending bugs

thenewstack.io

591–600 of 913 posts

Re: FFmpeg to Google: Fund us or stop sending bugs

#591
post #354

Earlier quoted context omitted.

I can tell you with 100% certainty that there are undiscovered vulnerabilities in the Linux kernel right now. Does that mean they should stop shipping? I do think that contributing fuzzing and quality bug reports can be beneficial to a project, but it's just human nature that when someone says "you go ahead and do the work, I'll stand here and criticize", people get angry. Rather than going off and digging up ten tim…

You will note the Linux kernel is not crying on Twitter when Google submits bugs to them. They did long ago, then realized that the bugs that Google reported often showed up exploited in the wild when they didn’t fix them, and mostly decided that the continuous fuzzing was actually a good thing. This is despite not all the bugs being fixed on time (there are always new OSSFuzz bugs in the queue for fixing).

The Linux kernel instead decided to become a CVE authority, so that they have control over what is officially reported as a CVE.

Re: FFmpeg to Google: Fund us or stop sending bugs

#592

FFmpeg should just dual license at this point. If you're wanting shit fixed. You pay for it (based on usage) or GTFO. Should solve all of the current issues around this.

You mean, Google reports a bug, and ffmpeg devs say "GTFO"? Let's assume this is a real bug: is that what you would the ffmpeg developers to say to Google? I absolutely understand the issue that a filthy-rich company tries to leech off of real unpaid humans. I don't understand how that issue leads to "GTFO, we won't fix these bugs". That makes no sense to me.

People would rather spitefully stub their toe after being warned of the table's location by someone they don't like rather than take heed.

Re: FFmpeg to Google: Fund us or stop sending bugs

#593

Earlier quoted context omitted.

> Are you okay not being told a tool you're using has a vulnerability in it because the devs don't have time to fix it? Yes? It's in the license > NO WARRANTY > 15. BECAUSE THE LIBRARY IS LICENSED FREE OF CHARGE, THERE IS NO WARRANTY FOR THE LIBRARY, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE LIBRARY "AS IS" WITHOUT WARRANT…

All the license means is that I can’t sue them. It doesn’t mean I have to like it. Just because software makes no guarantees about being safe doesn’t mean I want it to be unsafe.

Sorry to put it this bluntly, but you are not going to get what you want unless you do it yourself or you can convince, pay, browbeat, or threaten somebody to provide it for you.

Re: FFmpeg to Google: Fund us or stop sending bugs

#594
post #269

Earlier quoted context omitted.

Google is a multi-billion dollar company, which is paying people to find these bugs in the first place. That's a pretty core difference.

Great, so Google is actively spending money on making open source projects better and more secure. And for some reason everyone is now mad at them for it because they didn't also spend additional money making patches themselves. We can absolutely wish and ask that they spend some money and resources on making those patches, but this whole thing feels like the message most corporations are going to take is "don't do a…

> so Google is actively spending money on making open source projects better and more secure

It looks like they are now starting to flood OSS with issues because "our AI tools are great", but don't want to spend a dime helping to fix those issues.

xkcd 2347

Re: FFmpeg to Google: Fund us or stop sending bugs

#596

Earlier quoted context omitted.

I'm glad you threw in "I know of", because that part is true. Feel free to read lore.kernel.org, and sort out where the people contributing many patches actually work.

Can't you just give the information you are hinting at? Other people than OP read this. You basically tell me to go read thousands of messages on a mailing list just solve your rhetorical question. (answer: Intel, Redhat, Meta, Google, Suse, Arm and Oracle. There are much more efficient ways to find this.) Yes, they are the main kernel contributors and have been for many years. I'm still not sure I understand the com…

https://lwn.net/Articles/1038358/

Re: FFmpeg to Google: Fund us or stop sending bugs

#597
post #406

Earlier quoted context omitted.

I upstreamed a 1-line fix, plus tests, at my previous company. I had to go through a multi-month process of red tape and legal reviews to make it happen. That was a discouraging experience to say the least.

In this scenario does your employer have strong controls around what whether you can write hobby code on your own time?

One of my past employers in the UK added to the policy all the software the employee writes during the employment (eg. during the weekend, on the personal hardware), is owned by the company.

Several software engineers left, several didn't sign it.

Yes, company was very toxic apart of that. Yeah, I should name and shame but I won't be doxxing myself.

Re: FFmpeg to Google: Fund us or stop sending bugs

#598
post #269

Earlier quoted context omitted.

Google is a multi-billion dollar company, which is paying people to find these bugs in the first place. That's a pretty core difference.

Great, so Google is actively spending money on making open source projects better and more secure. And for some reason everyone is now mad at them for it because they didn't also spend additional money making patches themselves. We can absolutely wish and ask that they spend some money and resources on making those patches, but this whole thing feels like the message most corporations are going to take is "don't do a…

Why should Google not be expected to also contribute fixes to a core dependency of their browser, or to help funding the developers? Just publishing bug reports by themselves does not make open source projects secure!

Re: FFmpeg to Google: Fund us or stop sending bugs

#599

Earlier quoted context omitted.

More fantasy. Presumes the bug only exists in some part of ffmpeg that can be disabled at all, and that you don't need, and that you are even in control over your use of ffmpeg in the first place. Sure, in maybe 1 special lucky case you might be empowered. And in 99 other cases you are subject to a bug without being in the remotest control over it since it's buried away within something you use and don't even have th…

It's a heck of a lot better than being unaware of it. (To put this in context: I assume that on average a published security vulnerability is known about to at least some malicious actors before it's published. If it's published, it's me finding out about it, not the bad actors suddenly getting a new tool)

it's only better if you can act on it equal to the bad guys. If the bad guys get to act on it before you, or before some other good guys do on your behalf, then no it's not better

remember we're not talking about keeping a bug secret, we're talking about using a power tool to generate a fire hose of bugs and only doing that, not fixing them

Re: FFmpeg to Google: Fund us or stop sending bugs

#600

Earlier quoted context omitted.

How could ffmpeg maintainers kill three major AWS product lines with an email?

Open up an Amazon media app and navigate around enough, and you'll encounter a page with all their "Third Party Software Licenses." For instance, here's one for the Amazon Music apps, which includes an FFMpeg license: https://www.amazon.com/gp/help/customer/display.html?nodeId=...

And? How does that give the ffmpeg authors a power over Amazon? (Hint: it doesn’t and the guy we’re discussing is spewing nonsense for maximum retweets)
Post reply on HN