←back to thread

1124 points CrankyBear | 5 comments | | HN request time: 0.015s | source
Show context
firefax ◴[] No.45893096[source]
Is it unreasonable to ask that if a massive company funds someone to find a CVE in an open source project, they should also submit a patch? Google is a search company. Seems kind of... evil... to pay your devs to find holes in something with nothing to do with searching, then refuse to pay them to fix the problem they noticed.
replies(1): >>45895794 #
tpmoney ◴[] No.45895794[source]
Google contributes to ffmpeg on a fairly regular basis https://git.ffmpeg.org/gitweb/ffmpeg.git/search/HEAD?s=@goog...

No it's not "unreasonable" to ask for patches along with bug fixes, but it is unreasonable to be mad if they don't. They could just not file the bug reports at all, and that is an objectively worse outcome.

replies(2): >>45896133 #>>45902975 #
firefax ◴[] No.45902975[source]
>No it's not "unreasonable" to ask for patches along with bug fixes, but it is unreasonable to be mad if they don't

Your stance seems to be is that it is unreasonable to be annoyed by someone who is being unreasonable.

When I searched for synonyms for "unreasonable" in a major English language thesarus, the following synonyms were listed:

indefensible, mindless, reasonless, senseless, unjustified, untenable, unwarranted

So yes, it absolutely is valid for the FFMPEG crew to feel trolled by Project Zero.

replies(2): >>45904757 #>>45907957 #
1. Dylan16807 ◴[] No.45904757[source]
> Your stance seems to be is that it is unreasonable to be annoyed by someone who is being unreasonable.

No, that's not their stance.

You talked about whether ffmpeg was reasonable. They talked about whether ffmpeg was unreasonable.

You never accused google of being unreasonable, and they never mentioned it either.

So this idea of "responding to google being unreasonable" is a brand new premise. And I'm pretty sure they would disagree with that premise.

replies(1): >>45905006 #
2. firefax ◴[] No.45905006[source]
Are you on the autistic spectrum and/or not a native speaker of English? If we are discussing if FFMPEG's stance is reasonable, then it follows we are discussing of Google's actions are unreasonable.

Google is absolutely being unreasonable here -- they should instruct their engineers to submit a patch when submitting CVEs, and FFMPEG is perfectly valid to engage in a little activism to nudge them along.

replies(1): >>45905071 #
3. Dylan16807 ◴[] No.45905071[source]
> [...]then it follows we are discussing[...]

It's all connected but... Here, I'll phrase it more simply:

They didn't agree that google is being unreasonable. You are not interpreting them right.

I don't care how confident you are that google is being unreasonable. The "your stance seems to be" statement in your previous comment is wrong.

replies(1): >>45905159 #
4. firefax ◴[] No.45905159{3}[source]
Let's pull back up the core line here:

>it's not "unreasonable" to ask for patches along with bug fixes, but it is unreasonable to be mad if they don't

So the ask (make a patch for your CVEs) is reasonable. It follows that to fail to do so is unreasonable. Whether the poster agrees Google is unreasonable or not is up for debate, but if they choose to espouse that the request is reasonable and that Google is reasonable, they're putting forth an irrational belief not rooted in their own logic.

But hey, lots of folks on HN are biased towards Google for financial reasons, so I totally get it.

But either their stance is how I said, or if their stance differs they are a hypocrite, there really is no middle ground here.

replies(1): >>45906879 #
5. Dylan16807 ◴[] No.45906879{4}[source]
> So the ask (make a patch for your CVEs) is reasonable. It follows that to fail to do so is unreasonable.

Ah, that's where the confusion happens. It's your stance that it follows, but tpmoney was directly disagreeing with that logic.

tpmoney's stance, and my stance, is that it's reasonable to ask and it's also reasonable to say no.

It's not irrational to say that you can reasonably decline a reasonable request. Jeez.

(Also even if it was irrational, that wouldn't make tpmoney a hypocrite. That claim is just weird.)