• TehPers@beehaw.org
    link
    fedilink
    English
    arrow-up
    11
    ·
    edit-2
    2 hours ago

    The issue is not whether security issues exist in ffmpeg. It’s clear that vulnerabilities need to be fixed.

    The issue is with who actually fixes them. Your last sentence is the core of it. Google can submit as many bug reports as they want, but they better be willing to ensure the bugs get fixed too.

    • solrize@lemmy.ml
      link
      fedilink
      arrow-up
      3
      ·
      2 hours ago

      Google having found the bugs can either submit bug reports or quietly sit on them, or even exploit them as spyware, among other ideas. Whether they fund ffmpeg is a completely separate question. I can see how the 90 day disclosure window can be a problem if the number of reports is high.

      • TehPers@beehaw.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        49 minutes ago

        Bug reports that apply only to Google’s services or which surface only because of them are bugs Google needs to fix. They can and do submit bug reports all they want. Nobody is obligated to fix them.

        The other part of this is, of course, disclosure. Google’s disclosure of these bugs discredits ffmpeg developers and puts the blame on them if they fail to fix the vulnerabilities. They can acknowledge the project as being a volunteer, hobby project created by others if they want, and they can treat it like that. But if they’re doing that, they should not be putting responsibilities on them.

        If Google wants to use ffmpeg, they can. But a bug in ffmpeg that affects Google’s services is a bug in Google’s service. It is not the responsibility of unpaid volunteers to maintain their services for them.

    • Midnitte@beehaw.org
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 hours ago

      If it’s a mission critical library, then the corporations should be willing to shell out money to ensure critical bugs are fixed.

      Google can’t have their cake and eat it too.