Live data from Hacker News

FFmpeg to Google: Fund us or stop sending bugs

thenewstack.io

731–740 of 913 posts

Re: FFmpeg to Google: Fund us or stop sending bugs

#732
post #719

Earlier quoted context omitted.

Google did more than what is "strictly legal or required", and what they did was submit a good and valid bug report. But for some reason we're mad because they didn't do even more. Why? The Copenhagen Interpetation of Ethics is annoyingly prevalent ( https://forum.effectivealtruism.org/posts/QXpxioWSQcNuNnNTy/... )

"I noticed your window was broken, so I took the liberty of helping you, working for free, by posting a sign that says UNLOCKED WINDOW HERE with exact details on how it was broken. I did lots of gratis work for you which you do not need to do yourself now. The world is safer now. Why are you not grateful?"

[deleted]

Re: FFmpeg to Google: Fund us or stop sending bugs

#733

Earlier quoted context omitted.

> Software owes it to its users to be secure. There is no such obligation. There is no warranty and software is provided AS-IS explicitly by the license.

I disagree, as software engineers we owe it to the craft to create correct software especially when we intend to distribute. Anything less is poor taste. You bring up licensing. I’m not talking about legally I’m talking about a social contract.

The choice of license is also a a partial descriptor of the social contract. If I wanted to work on it for “customers” I would sell it. I don’t owe you anything otherwise.

The social contract is “here is something I’ve worked on for free, and it is a gift. Take it or leave it.”

You want me to work on something for it? FYPM

Re: FFmpeg to Google: Fund us or stop sending bugs

#735

As much as I hate to be on Google's side I think they're doing a reasonable thing here. Valid bug reports are valuable contributions on their own, and disclosing security issues is standard practice. Not disclosing them doesn't help anyone. Security through obscurity is not security. If neither FFMPEG nor Google dedicate resources to fixing the issue in 90 days, making it public at least ensures that it gets visibili…

That was exactly my thought. To be fair, I probably end up thinking that because this article is written is this trashy dumbass style, which portrays it as "Google bug reports vs. ffmpeg bug fixes", which is simply unfair: as you've said, a bug report is a contribution, not some kind of a demand. That being said, I kinda do understand if someone from ffmpeg said something snarky about that on Twitter, since surely if Google (of all things) as an organization sees it valuable to contribute by sending bug reports, it surely isn't less feasible (logistically or economically) for them to also work on a patch, than it is for random people within ffmpeg mailing list itself.

Re: FFmpeg to Google: Fund us or stop sending bugs

#736

Earlier quoted context omitted.

Easy: ffmpeg discontinues or relicenses some ffmpeg functionality that AWS depends on for those product alines and AWS is screwed. I've seen that happen in other open source projects.

But if it gets relicensed, they would still be able to use the current version. Amazon definitely would be able to fund an independent fork.

Oh the irony - we don't want to pay for ffmpeg's development, but sure can finance a fork if we have to.

Re: FFmpeg to Google: Fund us or stop sending bugs

#738
post #323

Earlier quoted context omitted.

As yet, Valve is the only company I know of doing this, and it's paying off in dividends both for Linux and for Valve. In just 5ish years of Valve investing people and money into Linux- specifically mesa and WINE, Linux has gone from a product that is kind of shaky with Windows, to "I can throw a windows program or game at it and it usually works". Imagine how further the OSS ecosystem would be if Open Source hadn't…

Valve is so successful because it is a private company, and the CEO is the CTO and he is essentially the corporate equivalent of a religious monk. How else can you get 20+ years to slowly build a software business? As a side note YC and tech startups themselves have become reality TV. Your goal should be Valve! You should be Gabe Newell! You don’t need to be famous! Just build something valuable and be patient

> How else can you get 20+ years to slowly build a software business?

It used to be normal to build a business slowly over 20 years. Now everyone grabs for the venture capital, grows so fast they almost burst, and the venture capital inevitably ends in enshittification as companies are forced by shareholders to go against their business model and shit over their customers in order to generate exponential profit margins.

Re: FFmpeg to Google: Fund us or stop sending bugs

#739
post #605

Earlier quoted context omitted.

This was not a case of stumbling across a bug. This was dedicated security research taking days if not weeks of high paid employees to find. And after all that, they just drop an issue, instead of spending a little extra time on producing a patch.

It’s possible that this is a more efficient use of their time when it comes to open source security as a whole, most projects do not have a problem with reports like this. If not pumping out patches allows them to get more security issues fixed, that’s fine!

From the perspective of Google maybe, but from the perspective of open source projects, how much does this drain them?

Making open source code more secure and at the same time less prevalent seems like a net loss for society. And if those researchers could spare some time to write patches for open source projects, that might benefit society more than dropping disclosure deadlines on volunteers.

Re: FFmpeg to Google: Fund us or stop sending bugs

#740
post #323

Earlier quoted context omitted.

I've been a proponent of upstreaming fixes for open source software. Why? - It makes continued downstream consumption easier, you don't have to rely on fragile secret patches. - It gives back to projects that helped you to begin with, it's a simple form of paying it forward. - It all around seems like the "ethical" and "correct" thing to do. Unfortunately, in my experience, there's often a lot of barriers within comp…

As yet, Valve is the only company I know of doing this, and it's paying off in dividends both for Linux and for Valve. In just 5ish years of Valve investing people and money into Linux- specifically mesa and WINE, Linux has gone from a product that is kind of shaky with Windows, to "I can throw a windows program or game at it and it usually works". Imagine how further the OSS ecosystem would be if Open Source hadn't…

WINE was a thing for years and generally worked okay for a lot of things.

I was playing Fallout 3 on WINE well before Valve got involved with minimal tweaks or DIY effort.

Proton with Steam works flawlessly for most things including AAA games like RDR2 and it's great, but don't forget that WINE was out there making it work for a while

Post reply on HN