Arguably the most brilliant engineer in FFmpeg left because of this. He reverse engineered dozens of codecs by hand as a volunteer. Then security "researchers" and corporate employees came along repeatedly insisted "critical" security issues were fixed immediately waving their
His contribution to preserving millions of undecodable video files for generations to come is monumentally underappreciated. But instead he's burnt out from dealing with the security "researchers" and corporate employees waving CVEs. We will never get talent like that back.
Also when we mean "by hand", we mean stack traces disassembled with pen and paper. There were no reverse engineering tools like Ghidra available back then.
@_Mark_Atwood @amazon Wow
@FFmpeg On the other hand, exposing users to potentially RCE through malicious video files is not ideal either. Mind you I realize how important the volunteers work is, but you are the ones promoting unsafe languages on social media while dismissing security reports publicly.
@DevPolice Send patches to fix them
@FFmpeg Why don't we just pay them? I understand that might seem obvious, but I don't understand why FFmpeg doesn't solicit funding or get involved in some business that would enable them to pay their engineers.
@FFmpeg wait so dumb question, can volunteers just not do it? just say no to fixing anything on priority. they can't force you right?
@harjassgambhir Sure, but as the libxml2 author says the security [theatre] and corporate community is very aggressive with their CVEs and tables of red for noncompliance. Even for an obscure game codec from the 1990s, that should just be disabled to begin with.
@FFmpeg I'm a security researcher, with 20+ years of experience...I feel your pain, CVEs are a huge load of BS...most of them are utterly fake crap like "here, if I have root access I can hack your system"...
@lcq24 Thanks
@FFmpeg I asked Grok who you are referring to. Which one is it?
@ryazan_dev It's not appropriate to name without permission
@FFmpeg It's also another example of the skills bottleneck, where the % of people capable of contributing & fixing these issues is so small that they inevitably face burnout. Your posts promoting low level programming will hopefully inspire more.
@pythag_mjw Thanks
@FFmpeg This is the main reason why i always send patch too. ( even though it is not always on par with the maintainer standards 🥲)
@megachar0x01 ❤️
@FFmpeg I’ve reversed and exploited FW bugs before…the process involves understanding what’s going on under the hood. If you understand what’s going on to exploit it, patching it is trivial. Are these “white hats” just a bunch of script kiddies running fuzzers?
@FFmpeg Maybe this is evidence that your strategy of writing everything in C and handrolled assembly isn't actually a good idea It's actually possible to have fun without creating exploitable vulnerabilities
@FFmpeg I think consider updating the license to forbid any publicly traded company from using the software. I think a nearlyfree license would be interesting that forbids large companies and their employees from touching it.
@FFmpeg You guys contributed so much more to the IT world than most of the enterprises people worship. Nearly every company runs your stuff and that's what you get. Stealing oss, np, contributing, barely, donate, omg. There are so many oss projects people are running on, without they
@FFmpeg CVEs no longer suit any purpose, they cried wolf too many times. When every scanning tool looks at your dependency set and has a set of issues even when you meticulously ensure that you’re always up to date on everything, you just start to notice care anymore. I’ve seen enough
@FFmpeg If it is any comfort, most of real security researchers that I know (the ones that do go deep, that care about real impact and not just their careers) also have problems with those behaviors. It is even worse when they grow to become 'leaders' that define work for others.
@FFmpeg His suggestion that vulnerabilities in open source projects be treated exactly as any other bug and immediately publicly reported and triaged seems exactly right. Identifying a problem in an open source project and then tasking someone else with it runs totally contrary to the
@FFmpeg Oh look! Open Source as a means for for-profit companies to guilt unpaid hackers into fixing bugs by pre-emptively blaming them for fictional cyber security incedences. Amazing how far from Free software's origins the movement has gone, arriving at psychological coercion.


