4 ms·
It’s not bug reports. It’s CVE. There is a convergence of very annoying trends happening: more and more are garbage found and written using AI and with an impa
by StopDisinfo910 11mo ago
It’s not bug reports. It’s CVE.
There is a convergence of very annoying trends happening: more and more are garbage found and written using AI and with an impact which is questionable at best, the way CVE are published and classified is idiotic and platform founding vulnerability research like Google are more and more hostile to projects leaving very little time to actually work on fixes before publishing.
This is leading to more and more open source developers throwing the towel.
- ranger_danger 11mo agoCVEs aren't caused by bugs?
- kykat 11mo agoYou could argue that, but I think that a bug is the software failing to do what it was specified, or what it promised to do. If security wasn't promised, it's not a bug.
- adastra22 11mo agoWhich is exactly the case here. This CVE is for a hobby codec written to support digital preservation of a some obscure video files from the 90’s that are used nowhere else. No security was promised.
- StopDisinfo910 11mo agoThey are not published in project bug trackers and are managed completely differently so no, personally, I don't view CVE as bug reports. Also, please, don't distrort what I say and omit part of my comment, thank you. Some of them are not even bugs in the traditional sense of the world but expected behaviours which can lead to unsecure side effects.
- jsnell 11mo agoIt seems like you might misunderstand what CVEs are? They're just identifiers. This was a bug, which caused an exploitable security vulnerability. The bug was reported to ffmpeg, over their preferred method for being notified about vulnerabilities in the software they maintain. Once ffmpeg fixed the bug, a CVE number was issued for the purpose of tracking (e.g. which versions are vulnerable, which were never vulnerable, which have a fix). Having a CVE identifier is important because we can't just talk about "the ffmpeg vulnerability" when there have been a dozen this year, each with different attack surfaces. But it really is just an arbitrary number, while the bug is the actual problem.
- StopDisinfo910 11mo agoI'm not misunderstanding anything. CVE involves a third party and it's not just a number. It's a number and an evaluation of severity. Things which are usually managed inside a project now have a visibility outside of it. You might justify it as you want like the need to have an identifier. It doesn't fundamentally change how that impacts the dynamic. Also, the discussion is not about a specific bug. It's a general discussion regarding how Google handles disclosure in the general case.
- walletdrainer 11mo agoNot always, there have been a plenty of CVEs issued for completely absurd reasons.
- ikiris 11mo agoThe lowered lead times are because devs have an entitled additude that others fix their code when they discover bugs in it. The 90 day period is the grace period for the dev, not a demand. If they don't want to fix it then it goes public.
- ivell 11mo agoIt is super strange to say that who devoted their time and effort and then gives away their work for free is somehow entitled. If this keeps up, there won't be anyone willing to maintain the software due to burn out. In today's situation, free software is keeping many companies honest. Losing that kind of leverage would be a loss to the society overall. And the public disclosure is going to hurt the users which could include defense, banks and other critical institutions.
- adastra22 11mo ago> The lowered lead times are because devs have an entitled additude that others fix their code when they discover bugs in it. That’s how open source works.