3 ms·
ffmpeg to this day has and creates some of the scariest security problems you'll see. I love ffmpeg, but I fear this will all end in tears...
by FesterCluck 5y ago
ffmpeg to this day has and creates some of the scariest security problems you'll see. I love ffmpeg, but I fear this will all end in tears...
- q-rews 5y agoSo this is a great step in the right direction since wasm is run in the JavaScript sandbox.
- timc3 5y agoCould you point me to some examples or perhaps share some? I totally believe you, but we depend on ffmpeg (and we license the relative codecs) and I wanted understand what kind of problems we should be looking out for.
- thih9 5y agoDo you have an example of a security problem that would still be an issue in the wasm and browser context?
- bostik 5y agoIs this still true? I know it certainly was several years ago, and the problem was magnified by every video sharing site using it in their ingestion and transcoding pipelines. It's a single, incredibly powerful and versatile tool, to the point where it's often easier[ß] to fiddle around with command line parameters than to hit the underlying libraries directly. And by design, in that kind of setup ffmpeg is processing vast quantities of untrusted inputs, coming in at all possible (and some impossible) combinations of video formats, container formats, invalid segment headers, bitstream corruptions and whatever else you can think of. If my memory serves me right, when M. Zalewski first joined Google, he worked on YouTube's video processing ... and to make their engine more robust, started to fuzz ffmpeg. I've heard people describe the result as if shaking a plum tree. As a result of all these years of hardening, these days ffmpeg should be reasonably robust against malicious inputs. Now, if anyone is generating command lines for it and passing anything from user input to that - well, that's an open invitation to abuse. ß: subjective, of course. But I've tried to look at using the libraries for something fairly straightforward and every single time it's been much more effective use of my time to just look up what the necessary ffmpeg CLI flags+arguments were.
- freemint 5y agoYou can use ß as foot note? I've never seen that before.
- bostik 5y agoI believe you can use any character your keyboard and/or chosen input method supports. I happen to like ß. From memory alone I've seen people use the +/- symbol, the upright cross, the double-cross and the cross product symbol, just on HN.