3 ms·
Irrespective of what Google does, security research is still useful for all of us. They could adopt a more flexible policy for FOSS though.
by ivell 11mo ago
Irrespective of what Google does, security research is still useful for all of us.
They could adopt a more flexible policy for FOSS though.
- doctorwho42 11mo agoOr they could contribute solutions to said bugs? Its not like they would distract that much from their bottom line
- SR2Z 11mo agoGoogle is a major contributor to open-source video, to the point where it would not be viable without them.
- FridgeSeal 11mo ago[flagged]
- SR2Z 11mo agoLook, I know you're being snarky, but YES. All of the viable open-source video codecs of the past 10 years would not have happened without Google. Not just for technical reasons, but for expensive patent-related legal reasons too. Given that ffmpeg is an open-source video transcoding tool, I don't think you can easily just dismiss this as "big company abuses open source." The ffmpeg devs are volunteers or paid to work on specific parts of the tool. That's why they're unimpressed. What Google is doing here is pretty reasonable.
- degamad 11mo agoExactly. The call-out is not "please stop doing security research". It is, "if you have a lot of money to spend on security research, please spend some of it on discovering the bugs, and some on fixing them (or paying us to fix them), instead of all of it on discovering bugs too fast for us to fix them in time".
- adastra22 11mo agoIs it? I’ve gotten nothing but headaches from these automated CVE-seeking teams.
- viraptor 11mo agoYou got lower chances of getting hacked by a random file on the internet. At Project Zero level they're also not CVE seeking - it doesn't even matter at that scale, it's not an independent trying to become known.
- adastra22 11mo agoI have yet to see one on any project I’ve been attached to that was actually exploitable under real circumstances. But the CVE hunting teams treat them all as if they were.
- saagarjha 11mo agoYou should honestly consider not responding if you are unaware of Project Zero.
- adastra22 11mo agoTFA is about Project Zero getting uppity about an unexploitable non-issue in ffmpeg. Project Zero hasn't reported any vulnerabilities in any software I maintain. Lots of other security groups have, some well respected as well, but to my knowledge none of these "outside" reports were actual vulnerabilities when analyzed in context.
- saagarjha 11mo agoYou are welcome to view the report however you like, but a world where an easily reproducible OOB read and UAF in the default configuration is an "unexploitable non-issue" is not reality.
- xuhu 11mo agoIt's as useful as brute forcing one of your neighbor's 100 online passwords every day and writing it on the door of a random supermarket.