FFmpeg to Google: Fund us or stop sending bugs
731–740 of 913 posts
Re: FFmpeg to Google: Fund us or stop sending bugs
#732Earlier quoted context omitted.
Google did more than what is "strictly legal or required", and what they did was submit a good and valid bug report. But for some reason we're mad because they didn't do even more. Why? The Copenhagen Interpetation of Ethics is annoyingly prevalent ( https://forum.effectivealtruism.org/posts/QXpxioWSQcNuNnNTy/... )
"I noticed your window was broken, so I took the liberty of helping you, working for free, by posting a sign that says UNLOCKED WINDOW HERE with exact details on how it was broken. I did lots of gratis work for you which you do not need to do yourself now. The world is safer now. Why are you not grateful?"
Re: FFmpeg to Google: Fund us or stop sending bugs
#733Earlier quoted context omitted.
> Software owes it to its users to be secure. There is no such obligation. There is no warranty and software is provided AS-IS explicitly by the license.
I disagree, as software engineers we owe it to the craft to create correct software especially when we intend to distribute. Anything less is poor taste. You bring up licensing. I’m not talking about legally I’m talking about a social contract.
The social contract is “here is something I’ve worked on for free, and it is a gift. Take it or leave it.”
You want me to work on something for it? FYPM
Re: FFmpeg to Google: Fund us or stop sending bugs
#734I’m only half joking by the way.
Re: FFmpeg to Google: Fund us or stop sending bugs
#735As much as I hate to be on Google's side I think they're doing a reasonable thing here. Valid bug reports are valuable contributions on their own, and disclosing security issues is standard practice. Not disclosing them doesn't help anyone. Security through obscurity is not security. If neither FFMPEG nor Google dedicate resources to fixing the issue in 90 days, making it public at least ensures that it gets visibili…
Re: FFmpeg to Google: Fund us or stop sending bugs
#736Earlier quoted context omitted.
Easy: ffmpeg discontinues or relicenses some ffmpeg functionality that AWS depends on for those product alines and AWS is screwed. I've seen that happen in other open source projects.
But if it gets relicensed, they would still be able to use the current version. Amazon definitely would be able to fund an independent fork.
Re: FFmpeg to Google: Fund us or stop sending bugs
#737Re: FFmpeg to Google: Fund us or stop sending bugs
#738Earlier quoted context omitted.
As yet, Valve is the only company I know of doing this, and it's paying off in dividends both for Linux and for Valve. In just 5ish years of Valve investing people and money into Linux- specifically mesa and WINE, Linux has gone from a product that is kind of shaky with Windows, to "I can throw a windows program or game at it and it usually works". Imagine how further the OSS ecosystem would be if Open Source hadn't…
Valve is so successful because it is a private company, and the CEO is the CTO and he is essentially the corporate equivalent of a religious monk. How else can you get 20+ years to slowly build a software business? As a side note YC and tech startups themselves have become reality TV. Your goal should be Valve! You should be Gabe Newell! You don’t need to be famous! Just build something valuable and be patient
It used to be normal to build a business slowly over 20 years. Now everyone grabs for the venture capital, grows so fast they almost burst, and the venture capital inevitably ends in enshittification as companies are forced by shareholders to go against their business model and shit over their customers in order to generate exponential profit margins.
Re: FFmpeg to Google: Fund us or stop sending bugs
#739Earlier quoted context omitted.
This was not a case of stumbling across a bug. This was dedicated security research taking days if not weeks of high paid employees to find. And after all that, they just drop an issue, instead of spending a little extra time on producing a patch.
It’s possible that this is a more efficient use of their time when it comes to open source security as a whole, most projects do not have a problem with reports like this. If not pumping out patches allows them to get more security issues fixed, that’s fine!
Making open source code more secure and at the same time less prevalent seems like a net loss for society. And if those researchers could spare some time to write patches for open source projects, that might benefit society more than dropping disclosure deadlines on volunteers.
Re: FFmpeg to Google: Fund us or stop sending bugs
#740Earlier quoted context omitted.
I've been a proponent of upstreaming fixes for open source software. Why? - It makes continued downstream consumption easier, you don't have to rely on fragile secret patches. - It gives back to projects that helped you to begin with, it's a simple form of paying it forward. - It all around seems like the "ethical" and "correct" thing to do. Unfortunately, in my experience, there's often a lot of barriers within comp…
As yet, Valve is the only company I know of doing this, and it's paying off in dividends both for Linux and for Valve. In just 5ish years of Valve investing people and money into Linux- specifically mesa and WINE, Linux has gone from a product that is kind of shaky with Windows, to "I can throw a windows program or game at it and it usually works". Imagine how further the OSS ecosystem would be if Open Source hadn't…
I was playing Fallout 3 on WINE well before Valve got involved with minimal tweaks or DIY effort.
Proton with Steam works flawlessly for most things including AAA games like RDR2 and it's great, but don't forget that WINE was out there making it work for a while