10 ms·
VLC 3.0.7 and security
- kderbe 7y agoI submitted this for discussion because of the "Opinion about bug bounties" section at the bottom of the post. It was interesting to read about the wide variety in quality of responses to an open source bug bounty.
- philpem 7y agoThere's a wide variety in the quality of responses to bug reports too. Last year I stumbled across a bug which could result in a leak of personal data (specifically, private messages). So I did the good-samaritan thing and reported it, opening with "I don't want a bug bounty for this" (it was a pretty trivial bug, just a high impact one). What I got back was a wall-of-text missive about how it wasn't on the OWASP TOP10, wasn't eligible for a bug bounty anyway, and finished with a personal attack. I didn't even reply to it. I haven't bothered submitting anything else, not on Hackerone, not anywhere.
- michaelmrose 7y agoYou should have released the email complete with personal attack and all info needed to reproduce the bug after 90 days. Their incompetence isn't your problem but it is their users problem.
- Aissen 7y agoWhat's interesting here is that the VLC team (partially) implemented what Alex Ionescu called for in the conclusion of his SSTIC 2019 keynote "Pay for the fix, not for the bug": https://www.sstic.org/2019/presentation/keynote_2019/ https://www.sstic.org/2019/presentation/keynote_2019/ They did pay for the bugs, but with "large extra-bonuses for fixes". Maybe this will pave the road to a different approach.
- deleted 7y ago[deleted]
- forgotmypwd123 7y ago>On 8 June 2019, 08:03 by ahmet sahin simsek >hi >I downloaded thé new version and I have a problème withe subtitle please can you help me How do these people manage to find these unrelated blog posts and decide to request tech support there?
- ducttape12 7y agoAnd why do they feel it's appropriate to ask for help there? This would be like going to a talk from a presidential candidate about fuel economy, and raising your hand and saying "My car doesn't start, can you help me?"
- Scoundreller 7y agoProbably a relatively new internet user with little understanding of how the whole thing works. Just uses it to watch content. If “Facebook” is the internet to you, typing into the first comment box you find seems more reasonable than finding an FAQ. User seems to even have their spell-check in French mode - possibly not even using their own computer to ask the question.
- delcaran 7y ago[OT] Non-English speaker here. Is there any difference (in grammar and/or meaning) between "an FAQ" and "a FAQ"? I'm asking because it sounds good but it goes against the little English grammar I remember from school...
- geofft 7y ago"a" vs. "an" is based on the first sound of the word, not the first letter. You would say "an honor" but "a hair" because, while they both start with the letter h, one has a silent h and the other doesn't. If you pronounce "FAQ" by spelling out the letters (and not like "fack"), it starts with "eff", so you should say "an FAQ." I think that's the pronunciation I usually hear.
- vesinisa 7y ago> The medium security issues are mostly out-of-band reads, heap overflows, NULL-dereference and use-after-free security issues. Those issues should not be exploitable with ASLR [...] Is this really valid? I remember reading numerous Google Project Zero blog posts that begin with finding an issue that should not be exploitable thanks to ASLR, and then the research would promptly proceed to defeating ASLR - usually by chaining to some unrelated and much less serious side channel exploit.
- saagarjha 7y agoDetermining whether bugs are exploitable is hard: usually, the answer tends to be “yes, if you try hard enough”.
- XMPPwocky 7y agoAnd there's a whole lot of cases where bug A isn't exploitable, and bug B isn't exploitable, but bugs A and B are exploitable.
- tlamponi 7y agoCannot really be said in a general way. With a lot of effort probably all of those could lead to more serious things, but not easily in a platform and setup agnostic way, i.e., you probably need time and be able to try multiple times to get you a realistic chance. If it's not possible to try multiple times (e.g., your try crashes or runs into some other protection mechanism (no-execute flag on page set, return address validation, ...) then there's, again depending on the specifics of the bug and it's context, a very slim chance to achieve a (arbitrary) remote code execution, or something similar serious, realistically. Also, for side channels you often need to be able to run code on the host, in some way, at which point it's probably not really interesting to exploit through VLC (as it runs normally as non-root/non-admin user anyway). Else, you'd need to be able to get some VLC responses which have a code-address related measurable characteristic (normally time-deltas), not sure if VLC can be forced to leak such infos from remote.
- vesinisa 7y ago
- delroth 7y ago> If you've listened to some of my talks or spoke to me (I'm sorry for you), you know I'm a bit critic of those programs, because they give money to find the issues, not to fix them. >> What about you give money to VLC instead of random hackers? > Well, security is important, so this is cool for our users, but still this is a mixed bag, for me. I've asked that question to Julia Reda a few months ago, and I think the answer was pretty interesting. It boils down to the absence of companies that provide this service ("security bugfix bounties") and are also willing to deal with basically being an EU contractor. So instead the EU-FOSSA bounties went to HackerOne, which is not perfect but is a step in the right direction that could be implemented immediately. Also note that Google does provide bounties for security patches and hardening (https://www.google.com/about/appsecurity/patch-rewards/ https://www.google.com/about/appsecurity/patch-rewards/ -- VLC or ffmpeg are not in there, but many base libraries are) and for integrating FOSS projects into their fuzzing frameworks (https://www.google.com/about/appsecurity/patch-rewards/autofuzz/ https://www.google.com/about/appsecurity/patch-rewards/autof...). I don't know of any other company providing this kind of bounties for FOSS devs.
- viach 7y ago>> people ranging from the usual security-asshole This pretty much illustrates the attitude of most of the bug bounties programs holders.
- vardump 7y agoYeah, that'd really put me off reporting anything.
- M2Ys4U 7y agoIf you read a (dead, for some reason) comment by the author, he explains what that means: https://news.ycombinator.com/item?id=20147573 https://news.ycombinator.com/item?id=20147573
- vardump 7y agoPerhaps he should be more specific in the blog post instead. Removing phrases like "security-asshole" in the first place would also go a long way.
- jbk 7y ago> Removing phrases like "security-asshole" in the first place would also go a long way. I absolutely refuse to remove phrases like that. This is exactly what some of those people are and because they are security people does not allow them to behave less well than other people. And I find that I'm being quite polite by not shaming those people publicly.
- dwndwn 7y agohey, I work in a low-level security group under a larger generic security org - at a general level, there are too many security-assholes and they make our lives harder when interacting with developers as they think we're all like that. security-assholes are a huge problem
- 7y ago
- vanderZwan 7y agoWhat this blog post doesn't mention is that they finally addressed the bug where if you have a broken file and looping enabled, it no longer gives you infinite pop-ups saying it can't play the file
- saagarjha 7y agoThat’s not a security bug, though?
- DonHopkins 7y agoI filed a bug report about something just like that many years ago (hanging in a CPU intensive loop if you remove all the files in the looping playlist out form under it, i.e. a disk drive goes offline or USB stick is unplugged), and he brushed it off and dismissed my bug report, telling me simply not to do that. And I also took the time to file several other very detailed bug reports against the Video Effects / Magnification Zoom user interface, which is not only ugly and poorly designed from an ergonomic perspective, but actually drawn into the video at video resolution instead of being drawn in an overlay at full screen resolution, so it gets rotated and is unusable when you combine it with Video Effects / Transform / Rotate, because it fails to transform the mouse events the same as the video and user interface. He brushed that one off as working as designed, too. It's still just the same as it was many years ago when I filed that bug report. I'm serious: Give it a try, you'll fall out of your seat laughing at how terrible it is! Check out the lowres pixelated font it uses to draw "VLC ZOOM HIDE" between the thumbnail and the bizarre curved zoom scale wedge! The mouse target area of the zoom wedge actually diminishes in size with the width of the wedge, until the minimum zoom target area is only one video pixel wide at the bottom, so it's almost impossible to click. (And it's totally impossible to click anywhere when the video is rotated or flipped, since the target area isn't correspondingly transformed.) Yes, I know the drill: It's free software, so I should just download the source code, read it, figure out the problem, fix it myself, and post a pull request. But I don't feel spending my time doing that after the author of VLC won't even admit there's a problem.
- wyldfire 7y agoFirst off, let me just say that I use VLC and I think it's really great. I really appreciate the work done: VLC is my preferred application for watching videos on linux or android. > from the usual security-asshole to some of the nicest guys ever It's not clear whether the asshole in question is being dogmatic about some ninety-day disclosure-to-publication deadline or whether they're maybe being rude about the project having security bugs. I have read lots of stories (mostly ones shown here on HN) about knee-jerk overreactions from CIO/CTOs from not-too-large or not-too-technical businesses w/vulnerabilities. Those kind of blame-the-messenger things likely shape their behavior with respect to disclosures. > The result of that, is that when you don't know how much to award for a security issue (is it medium or low?), you decide on the niceness of the reporter :) Gee, this sounds like it's not considering the impact to the user. Isn't that the intent of impact ratings? I suppose the risk of misclassification here is wasting the budget of the bounty on low-harm issues or dissuading researchers from digging deeper to find the high-impact ones.
- jbk 7y ago(author of the blogpost here) > It's not clear whether the asshole in question is being dogmatic about some ninety-day disclosure-to-publication deadline or whether they're maybe being rude about the project having security bugs. Being dogmatic with 90days disclosure, would get you a "hardline security reporter", but not an "asshole". Notably, because there has been no reporter that refused to extend by a reasonable amount of days, for us. "Hey, can we get 120 days, because we got other bugfixes and we want to do all of them together". No, we're talking about actual assholery here: - requesting answer and reproducibility in 24hours, and sending 10 mails in the mean time; - sending the same issues more than 10 times, because the stacktrace he has is slightly different, but refusing to listen when told that this was the same issue, and therefore only one bounty; - refusing to read the guidelines, and refusing to test the good version, and then insulting us; - agressivity, or insults, to the point where the HackerOne team had to intervene several times; - plugging the output of his fuzzer to HackerOne without checking if it actually crashes or if it is a different bug; - submitting the same bug to a different program (Google Android Apps) to get 2 times the bounty, while the bug DID NOT apply on Android, but he did not even check; - a few others that I forgot. So yeah, this is not about dogmatic or hardliners: we know how to deal with those in the open source communities.
- dontbenebby 7y agoInterestingly I had to enable JS to see the checksum for the file download (?!). Reproducible builds + a signed list of hashes would be a nice move for security.
- jbk 7y agoAll videolan files are GPG-signed and have several hashes (md5+sha1+sha256)
- dontbenebby 7y agoAh, maybe I missed the link on the DL page. All I see on the DL page are links to the source, nothing on GPG nor hashes https://www.videolan.org/vlc/#download https://www.videolan.org/vlc/#download When I clicked to DL my version, all I saw was a "click here to see hash" that needed me to enable JS. Just sha256, which is good btw, more is not better when it comes to hashes - sha256 is sufficient. Many open source projects provide all these on 1 page, rather than rely on complex code to deliver the info or display it on the DL page. Ex: https://www.torproject.org/download/ https://www.torproject.org/download/ lists sigs under each OS option.
- jbk 7y agoWell tor project and VLC have a very different audience, but I'll see what I can do.
- dontbenebby 7y agoI totally understand. Back in grad shool I focused on usable security, and usually less clicks to get to something means more likely people will use the info. Thanks for your help.
- apexalpha 7y agoI always wondered what purpose these hashes shown on dl pages serve. If someone can hack your website to change out the .exe or whatever, surely they could also just change the hash displayed?
- rurban 7y agoThat the link to Julia Reda's mentioned bug bounty program, which caused all these new reportings: https://juliareda.eu/2018/12/eu-fossa-bug-bounties/ https://juliareda.eu/2018/12/eu-fossa-bug-bounties/ eg glibc got a payout of 45.000 which means 4 exceptional risk bugs and 1 critical. https://www.intigriti.com/public/project/glibc/glibc https://www.intigriti.com/public/project/glibc/glibc I find that quite disturbing.