4 ms·
Can't trust user input, you'd have to spend quite a bit of energy just checking to see if it's good. You also want to transcode multiple resolutions, it'd end u
by pta2002 5y ago
Can't trust user input, you'd have to spend quite a bit of energy just checking to see if it's good. You also want to transcode multiple resolutions, it'd end up being quite slow if it's done using JS.
- amelius 5y agoVerification is simpler than encoding, I suppose.
- londons_explore 5y agoChecking the result is good shouldn't be too hard - a simple spot check of a few frames should be sufficient, and it isn't like the uploader gets a massive advantage for uploading corrupt files. The CPU and bandwidth costs of transcoding to 40+ different audio and video formats would be massive though. I could imagine a 5 minute video taking more than 24 hours to transcode on a phone.
- simcop2387 5y ago> Checking the result is good shouldn't be too hard - a simple spot check of a few frames should be sufficient, and it isn't like the uploader gets a massive advantage for uploading corrupt files. Uploading corrupt files could allow the uploader to execute code on future client machines. You must check every frame and the full encoding of the video.
- kevincox 5y agoMust is a strong word. In theory browsers and other clients treat all video stream as untrusted and it is safe to watch an arbitrary video. However complex formats like videos are a huge attack surface. So yes, for the bigger names like Google this is an unacceptable risk. They will generally avoid serving any user-generated complex format like video, images or audio to users directly. Everything is transcoded to reduce the likelihood that an exploit was included.