Live data from Hacker News

FFmpeg to Google: Fund us or stop sending bugs

thenewstack.io

601–610 of 913 posts

Re: FFmpeg to Google: Fund us or stop sending bugs

#601

So what if ffmpeg has open CVEs? What is Google going to do? Swap it? Leave them open, let Google ship products with CVE'd dependencies, and then they'll be forced to act. Why would Google act if they got smart guys working for them for free? Stop fixing Google-reported bugs.

> So what if ffmpeg has open CVEs?

Part of the issue is that FFmpeg is almost a meta-project. It contains so many possible optional dependencies. Which is great for features, nit so great if you quickly want to know if you're exposed to the latest CVE.

Re: FFmpeg to Google: Fund us or stop sending bugs

#602

A bunch of people who make era-defining software for free. A labor of love. Another bunch of people who make era-defining software where they extract everything they can. From customers, transactionally. From the first bunch, pure extraction (slavery, anyone?).

It's hard to find an easier good vs evil distinction than between Google and literally anybody else.

What is happening to hacker news? I'm not a fan of Google but this discourse is so tribal and reductive.

Re: FFmpeg to Google: Fund us or stop sending bugs

#604

Earlier quoted context omitted.

TFA is about Project Zero getting uppity about an unexploitable non-issue in ffmpeg. Project Zero hasn't reported any vulnerabilities in any software I maintain. Lots of other security groups have, some well respected as well, but to my knowledge none of these "outside" reports were actual vulnerabilities when analyzed in context.

You are welcome to view the report however you like, but a world where an easily reproducible OOB read and UAF in the default configuration is an "unexploitable non-issue" is not reality.

For a codec that isn't configured by default, and only used and maintained by a hobbyist video game content preservation group. Yeah it's a non-issue.

Re: FFmpeg to Google: Fund us or stop sending bugs

#605

Earlier quoted context omitted.

If google bears no role in fixing the issues it finds and nobody else is being paid to do it either, it functionally is just providing free security vulnerability research for malicious actors because almost nobody can take over or switch off of ffmpeg.

I guess the question that a person at Google who discovers a bug they don’t personally have time to fix is, should they report the bug at all? They don’t necessarily know if someone else will be able to pick it up. So the current “always report” rule makes sense since you don’t have to figure out if someone can fix it. The same question applies if they have time to fix it in six months, since that presumably still gi…

This was not a case of stumbling across a bug. This was dedicated security research taking days if not weeks of high paid employees to find.

And after all that, they just drop an issue, instead of spending a little extra time on producing a patch.

Re: FFmpeg to Google: Fund us or stop sending bugs

#606

Earlier quoted context omitted.

How could ffmpeg maintainers kill three major AWS product lines with an email?

Open up an Amazon media app and navigate around enough, and you'll encounter a page with all their "Third Party Software Licenses." For instance, here's one for the Amazon Music apps, which includes an FFMpeg license: https://www.amazon.com/gp/help/customer/display.html?nodeId=...

Is the idea that ffmpeg could change its license and wreak havoc?

Re: FFmpeg to Google: Fund us or stop sending bugs

#607

Earlier quoted context omitted.

This is a weird argument. Basically condoning security through obscurity: If nobody reports the bug then we just pretend it doesn’t exist, right? There are many groups searching for security vulnerabilities in popular open source software who deliberately do not disclose them. They do this to save them for their own use or even to sell them to bad actors. It’s starting to feel silly to demonize Google for doing secur…

> It’s starting to feel silly to demonize Google for doing security research at this point. Aren't most people here demonizing Google for dedicating the resources to find bugs, but not to fix them?

And not giving the maintainners reasonable amount of time to fix. This was triggered by recent change of policy on google side.

Re: FFmpeg to Google: Fund us or stop sending bugs

#608

Earlier quoted context omitted.

> That does not impact their business or their operations in any way whatsoever. I don't know what tools and backends they use exactly, but working purely by statistics, I'm sure some place in Google's massive cloud compute empire is relying on ffmpeg to process data from the internet.

And they're processing old LucasArts codec videos with it? Which is the specific bug report in question.

They're probably not manually selecting which codecs and codec parameters to accept and sticking to the default ones instead.

Plus, this bug was reported by AI, so it was as much a proof of concept/experiment/demonstration of their AI security scanner as it was an attempt to help secure ffmpeg

Re: FFmpeg to Google: Fund us or stop sending bugs

#610

Earlier quoted context omitted.

> But "everyone else down stream of us should compile out our security hole" is a terrible way to go about things. Is that somehow _less_ of a terrible way to think than "someone who's contributed their time as a volunteer to an open source software project that we have come to rely on, now has some sort of an obligation to drop everything and do more unpaid work for a trillion dollar company"? > it really needs to b…

> someone who's contributed their time as a volunteer to an open source software project that we have come to rely on, now has some sort of an obligation to drop everything and do more unpaid work for a trillion dollar company If you could highlight the relevant part of the bug report that demanded the developers "drop everything" and do "unpaid work for a trillion dollar company", that would be great because I'm hav…

Publicly posting an exploitable bug IS asking for someone to drop everything and come fix the issue NOW.
Post reply on HN