3 ms·
FFmpeg seem to be taking the position that their code must be considered insecure in production unless you pay them for security consulting [1]. On the one han
by gnfargbl 11mo ago
FFmpeg seem to be taking the position that their code must be considered insecure in production unless you pay them for security consulting [1].
On the one hand, that's fine; it's their project, and if attack surface is not a priority for them, or they want to monetise that function, then nobody else has a right to complain.
On the other hand, we have plenty of evidence that untrusted input validation bugs pose a very high risk to end users. So, for as long as this is their policy, FFmpeg code really should not be included in any system where security is at all important. Perhaps we need a "fundamentally unsafe for use" sticker for OSS projects taking this stance?
[1] https://x.com/FFmpeg/status/1984425167070630289 https://x.com/FFmpeg/status/1984425167070630289
- vreg 11mo agoAll code should be considered potentially vulnerable, that's why we have so many layers of exploit mitigation from the compiler to the runtime environment to the overall design of the system the code is running in.
- TZubiri 11mo ago> unless you pay them You can't pay for the software >"FFmpeg is not available under any other licensing terms, especially not proprietary/commercial ones, not even in exchange for payment" https://www.ffmpeg.org/legal.html https://www.ffmpeg.org/legal.html
- deleted 11mo ago[deleted]
- gnfargbl 11mo agoI edited my post to make the nature of the requested payment clearer.