Live data from Hacker News

FFmpeg to Google: Fund us or stop sending bugs

thenewstack.io

661–670 of 913 posts

Re: FFmpeg to Google: Fund us or stop sending bugs

#661
post #568

Earlier quoted context omitted.

Then they should mark it as low priority and put it in their backlog. I trust that the maintainers are good judges of what deserves their time.

Publicizing vulnerabilities is the problem though. Google is ensuring obscure or unknown vulnerabilities will now be very well known and very public. This is significant when they represent one of the few entities on the planet likely able to find bugs at that scale due to their wealth. So funding a swarm of bug reports, for software they benefit from, using a scale of resources not commonly available, while not cont…

I think most people learned about this bug from FFmpeg's actions, not Google's. Also, you are underestimating adversaries: Google spends quite a bit of money on this, but not a lot given their revenue, because their primary purpose is not finding security bugs. There are entities that are smaller than Google but derive almost all their money from finding exploits. Their results are broadly comparable but they are only publicized when they mess up.

Re: FFmpeg to Google: Fund us or stop sending bugs

#662
post #185

Earlier quoted context omitted.

Where do you draw the line? Do you want Google to just not inspect any projects that it can't fully commit to maintaining? Providing a real CVE is a contribution, not a burden. The ffmpeg folks can ignore it, since by all indications it's pretty minor.

> Providing a real CVE is a contribution, not a burden. Isn't a real CVE (like any bug report) both a contribution and a burden?

It's not fair to classify it as a burden; it existed anyways, but now you have the work/issue identified.

Re: FFmpeg to Google: Fund us or stop sending bugs

#663
post #66
post #46

this is why you should release your opensource project with the license of being free only for individual, not for enterprises. enterprise must pay.

If it's not free for enterprises then it's not open source, according to the commonly accepted definition.

Being open source and being free are entirely different things though.

You can view, read the code = open source.

The latter is about money.

Re: FFmpeg to Google: Fund us or stop sending bugs

#664

Earlier quoted context omitted.

You are welcome to view the report however you like, but a world where an easily reproducible OOB read and UAF in the default configuration is an "unexploitable non-issue" is not reality.

For a codec that isn't configured by default, and only used and maintained by a hobbyist video game content preservation group. Yeah it's a non-issue.

> a codec that isn't configured by default

Where did you get that idea?

Re: FFmpeg to Google: Fund us or stop sending bugs

#665

Earlier quoted context omitted.

Please don’t use “CVE” as a stand-in for “vulnerability”, you know much better than this :) Most vulnerabilities never get CVEs even when they’re patched.

Only using it because the comment I replied to is, of course I agree that most vulnerabilities are patched without one

While this feels like it’s perhaps bordering on somewhat silly nitpicking, the trend of conflating vulnerabilities with CVEs is probably at least mildly harmful. It’s probably good to at least try not to let people get away with this all the time.

The way many (perhaps most) people think of CVEs is badly broken. The CVE system is deeply unreliable, resulting in CVEs being issued for things that are neither bugs nor vulnerabilities while at the same time most things that probably should have CVEs assigned do not have them. Not to even mention the ridiculous mess that is CVSS.

I’m just ranting though. You know all this, almost certainly much better than me.

Re: FFmpeg to Google: Fund us or stop sending bugs

#666

Earlier quoted context omitted.

Is this sarcasm? While it may be true that my mother does not know what ffmpeg is I'm almost positive she interacts with stuff that uses it literally every single day.

...every media post on IG/FB/X/YT/news sites/AI.

So does a Siemens transformer, but it's era defining.

Why there's such a weird toxic empathy around ffmpeg?

Re: FFmpeg to Google: Fund us or stop sending bugs

#667
post #621
post #603

FFmpeg is a great project but their twitter is embarrassing and should not be news

Why, their Twitter seems reasonable and combative towards companies who want to exploit their results without contribution ?

This take sounds great until you realize this is literally Google using their resources to help an open source project (by reporting issues in it that ALREADY EXIST and NEED to be fixed OR users made aware if not fixed) AND they also help them by upstreaming patches (just not for this specific issue) regularly AND with monetary support.

So...your entire premise is patently false and wrong.

Re: FFmpeg to Google: Fund us or stop sending bugs

#668

Honestly, I kind of think that ffmpeg should just document that it's not secure and that you're expected to run it in a sandbox if you plan to use it on possibly-malicious input. All the big cloud users and browsers are doing this already, so it would hardly even change anything. ffmpeg is complaining that security bugs are such a drag that it's driving people away from their hobby/passion projects. Well, if fixing s…

Why be reasonable when you can just grandstand (about people that do actually provide you with funding) on Twitter? Surely that's more fun, right?

Re: FFmpeg to Google: Fund us or stop sending bugs

#669

Earlier quoted context omitted.

And then the argument for refusing to just pay ffmpeg developers gets even more flimsy. The entire point here is to pay for the fixes/features you keep demanding, else the project is just going to do as it desires and ignore you. More and more OSS projects are getting to this point as large enterprises (especially in the SaaS/PaaS spheres) continue to take advantage of those projects and treat them like unpaid worker…

Not really. Their whole reason for not funding open source is it essentially funds their competitors who use the same projects. That's why they'd rather build a closed fork in-house than just hand money to ffmpeg. It's a dumb reason, especially when there are CVE bugs like this one, but that's how executives think.

ffmpeg is LGPL, so they can't make a proprietary fork anyways

Re: FFmpeg to Google: Fund us or stop sending bugs

#670

Similar event happened 2-years ago, but with Microsoft https://news.ycombinator.com/item?id=39912916

That was not similar. The Microsoft dev was demanding things and rightfully shamed over it. Everyone giving Google the same shame over reporting an exploitable bug with no expectations is being ridiculous.
Post reply on HN