Earlier quoted context omitted.
Then they should mark it as low priority and put it in their backlog. I trust that the maintainers are good judges of what deserves their time.
Publicizing vulnerabilities is the problem though. Google is ensuring obscure or unknown vulnerabilities will now be very well known and very public. This is significant when they represent one of the few entities on the planet likely able to find bugs at that scale due to their wealth. So funding a swarm of bug reports, for software they benefit from, using a scale of resources not commonly available, while not cont…
FFmpeg to Google: Fund us or stop sending bugs
661–670 of 913 posts
Re: FFmpeg to Google: Fund us or stop sending bugs
#662Earlier quoted context omitted.
Where do you draw the line? Do you want Google to just not inspect any projects that it can't fully commit to maintaining? Providing a real CVE is a contribution, not a burden. The ffmpeg folks can ignore it, since by all indications it's pretty minor.
> Providing a real CVE is a contribution, not a burden. Isn't a real CVE (like any bug report) both a contribution and a burden?
Re: FFmpeg to Google: Fund us or stop sending bugs
#663this is why you should release your opensource project with the license of being free only for individual, not for enterprises. enterprise must pay.
If it's not free for enterprises then it's not open source, according to the commonly accepted definition.
You can view, read the code = open source.
The latter is about money.
Re: FFmpeg to Google: Fund us or stop sending bugs
#664Earlier quoted context omitted.
You are welcome to view the report however you like, but a world where an easily reproducible OOB read and UAF in the default configuration is an "unexploitable non-issue" is not reality.
For a codec that isn't configured by default, and only used and maintained by a hobbyist video game content preservation group. Yeah it's a non-issue.
Where did you get that idea?
Re: FFmpeg to Google: Fund us or stop sending bugs
#665Earlier quoted context omitted.
Please don’t use “CVE” as a stand-in for “vulnerability”, you know much better than this :) Most vulnerabilities never get CVEs even when they’re patched.
Only using it because the comment I replied to is, of course I agree that most vulnerabilities are patched without one
The way many (perhaps most) people think of CVEs is badly broken. The CVE system is deeply unreliable, resulting in CVEs being issued for things that are neither bugs nor vulnerabilities while at the same time most things that probably should have CVEs assigned do not have them. Not to even mention the ridiculous mess that is CVSS.
I’m just ranting though. You know all this, almost certainly much better than me.
Re: FFmpeg to Google: Fund us or stop sending bugs
#666Earlier quoted context omitted.
Is this sarcasm? While it may be true that my mother does not know what ffmpeg is I'm almost positive she interacts with stuff that uses it literally every single day.
...every media post on IG/FB/X/YT/news sites/AI.
Why there's such a weird toxic empathy around ffmpeg?
Re: FFmpeg to Google: Fund us or stop sending bugs
#667FFmpeg is a great project but their twitter is embarrassing and should not be news
Why, their Twitter seems reasonable and combative towards companies who want to exploit their results without contribution ?
So...your entire premise is patently false and wrong.
Re: FFmpeg to Google: Fund us or stop sending bugs
#668Honestly, I kind of think that ffmpeg should just document that it's not secure and that you're expected to run it in a sandbox if you plan to use it on possibly-malicious input. All the big cloud users and browsers are doing this already, so it would hardly even change anything. ffmpeg is complaining that security bugs are such a drag that it's driving people away from their hobby/passion projects. Well, if fixing s…
Re: FFmpeg to Google: Fund us or stop sending bugs
#669Earlier quoted context omitted.
And then the argument for refusing to just pay ffmpeg developers gets even more flimsy. The entire point here is to pay for the fixes/features you keep demanding, else the project is just going to do as it desires and ignore you. More and more OSS projects are getting to this point as large enterprises (especially in the SaaS/PaaS spheres) continue to take advantage of those projects and treat them like unpaid worker…
Not really. Their whole reason for not funding open source is it essentially funds their competitors who use the same projects. That's why they'd rather build a closed fork in-house than just hand money to ffmpeg. It's a dumb reason, especially when there are CVE bugs like this one, but that's how executives think.
Re: FFmpeg to Google: Fund us or stop sending bugs
#670Similar event happened 2-years ago, but with Microsoft https://news.ycombinator.com/item?id=39912916