←back to thread

1125 points CrankyBear | 1 comments | | HN request time: 0.207s | source
Show context
profsummergig ◴[] No.45891496[source]
A bunch of people who make era-defining software for free. A labor of love.

Another bunch of people who make era-defining software where they extract everything they can. From customers, transactionally. From the first bunch, pure extraction (slavery, anyone?).

replies(4): >>45891584 #>>45892197 #>>45892562 #>>45896041 #
ivell ◴[] No.45891584[source]
Irrespective of what Google does, security research is still useful for all of us.

They could adopt a more flexible policy for FOSS though.

replies(3): >>45891820 #>>45892009 #>>45892299 #
adastra22 ◴[] No.45892009[source]
Is it? I’ve gotten nothing but headaches from these automated CVE-seeking teams.
replies(1): >>45892966 #
viraptor ◴[] No.45892966[source]
You got lower chances of getting hacked by a random file on the internet. At Project Zero level they're also not CVE seeking - it doesn't even matter at that scale, it's not an independent trying to become known.
replies(1): >>45895143 #
adastra22 ◴[] No.45895143[source]
I have yet to see one on any project I’ve been attached to that was actually exploitable under real circumstances. But the CVE hunting teams treat them all as if they were.
replies(1): >>45895931 #
saagarjha ◴[] No.45895931[source]
You should honestly consider not responding if you are unaware of Project Zero.
replies(1): >>45896378 #
adastra22 ◴[] No.45896378[source]
TFA is about Project Zero getting uppity about an unexploitable non-issue in ffmpeg.

Project Zero hasn't reported any vulnerabilities in any software I maintain. Lots of other security groups have, some well respected as well, but to my knowledge none of these "outside" reports were actual vulnerabilities when analyzed in context.

replies(1): >>45896507 #
saagarjha ◴[] No.45896507[source]
You are welcome to view the report however you like, but a world where an easily reproducible OOB read and UAF in the default configuration is an "unexploitable non-issue" is not reality.
replies(1): >>45897502 #
adastra22 ◴[] No.45897502[source]
For a codec that isn't configured by default, and only used and maintained by a hobbyist video game content preservation group. Yeah it's a non-issue.
replies(2): >>45898406 #>>45898464 #
1. saagarjha ◴[] No.45898406[source]
It's used by exploit authors, too.