5 ms·
are you perhaps a teen? that's a magnet link, its used to transfer things via bittorrent. we used to put them in the spokes of our bicycles when we'd ride down
by aliqot 4y ago
are you perhaps a teen? that's a magnet link, its used to transfer things via bittorrent. we used to put them in the spokes of our bicycles when we'd ride down to the five-and-dime
- wil421 4y agoWhen I was riding bikes to the store we had dialup and floppies were giving way to CDs. It’s been over a decade since I’ve used BitTorrent and I didn’t know magnet links were still popular. I hate seeding and there was also a lot of malware hidden in public trackers. Once I switched to Usenet I never looked back. P2P file sharing has never been a good experience for me.
- ryandrake 4y agoHow does one get malware from playing a .mkv or .mp4 video file?
- deleted 4y ago[deleted]
- Laaas 4y agoA sophisticated attacker could make use of bugs in the player to hack the system. This sort of trick is often used against high value targets where the effort needed makes it worth it.
- deleted 4y ago[deleted]
- Loughla 4y agoWhy do I feel like the people downloading ConAir(1997)YIFYWEB-DLs.MKV are not high value targets?
- chongli 4y agoWhy does the video player have the capability to do anything other than read video files the user specifies through the system file chooser dialog and play them on the screen?
- pessimizer 4y agooverflows
- chongli 4y agoNo, what I’m asking is: why does the operating system allow the video player to do anything other than what it needs to do to play videos? If the video player suddenly starts trying to access files on its own (anything not explicitly chosen by the user through system file dialog) or trying to access the internet then the user should be prompted to give permission. We have this kind of API permission (capability) system on phones. Why can’t we have a really fine-grained one on desktops? It’s like a firewall for APIs.
- 1317 4y agoboth of those examples happen within normal usage file system for finding external subs (or like, playing the video) internet for streaming and then oh look, it has the permission
- vel0city 4y agoMany times these kinds of attacks are buffer overflows, tricking the hardware/OS to execute code it wasn't intending. Its not just that the media player starts to behave strangely, often the attack corrupts code outside the media player. See the Android Mediaserver vulnerabilities, or many of the buffer overflow vulnerabilities in ffmpeg. If an attack corrupts how the OS checks permissions, it doesn't matter if you've got some API framework for calls, it broke out of it.
- MobiusHorizons 4y agoThe ux you are describing is a lot worse than what people get with vlc or mplayer. For example, you can open videos from the cli, which means there is no file chooser involved. Also if you have a subtitle file (.srt) with the same name as the video you opened, the subtitles will automatically be added. Both of these are things people want as part of a versatile video player. The level of lockdown you were describing is what we have on mobile platforms (which incidentally still have lots of malware). Generally speaking, people want more flexibility out of general purpose computers. On the other hand something like pledge would be useful here, since the attack vector is untrusted files, not untrusted applications. With pledge, the application could open any files, then relinquish the ability to open new files before parsing the contents.
- dec0dedab0de 4y agoThere would need to be an unpatched vulnerability in your player that the file exploited. Only virus I ever got was from an mp3 file that exploited the vulnerable version of winamp that I was using because I hated the newer version.
- wil421 4y agoMost of the time it’s a rar file that contains screenshots, album art, thumbnails, etc. not just a video file. I’ve been burnt a decade plus ago when I automated some extractions into a media folder on an old windows laptop. By the time I noticed, it was deep in the registry and near impossible to remove. It was something akin to MacKeeper malware on Macs, I don’t recall the old windows malware names. With my Usenet automation I’ve never had the issue in about 9ish years but it could happen. I pay a usenet provider and indexer a low fee to rid myself of torrents and seeding.
- ghotli 4y agoThis is a really good talk I saw in person on this exact subject. Focuses on using rust and the nom library for safe parsing. He opens with a description of how VLC is one of the worst offenders for vulnerabilities historically because it supports so many different file formats / parsers written in c. > Safe and fast parsers with Nom and Rust https://www.youtube.com/watch?v=8mA5ZwWB3M0 https://www.youtube.com/watch?v=8mA5ZwWB3M0
- vel0city 4y agoMedia decoders are often rather complicated and often involve parsing data directly into large and constantly changing memory buffers. A huge chunk of Android vulnerabilities have been from vulnerabilities in media libraries, even JPEG parsing has been known to lead to vulnerabilities in Linux.
- brokenmachine 4y agoThere's a really good explanation in the book "A Bug Hunters Diary". It used an old version of vlc and a buffer overflow vulnerability to get code execution.
- Laaas 4y agoWhat do you use instead? IPFS isn't very practical compared to Bittorrent I find.
- ayewo 4y agoWhich Usenet service do you use?
- mlindner 4y agoThere's no malware risk from trackers lol...
- adwww 4y agoI've not torrented in at least a decade, and I don't remember seeing magnet links inline in text like that. Certainly don't miss those hours of waiting for an ISO to download only to find it's all corrupt, or a record label plant, or a handheld recording of a cinema screen...
- soperj 4y ago> Certainly don't miss those hours of waiting I think you mean 2 decades. I haven't waited an hour for anything to download since I used to grab bootleg concerts that were very poorly seeded in the early/mid aughts.
- aliqot 4y agoSome of us rural nerds are only recently coming off the dialups
- brokenmachine 4y agoDepends on how rare the linux isos you're interested in are.