Skip to content

Comment on VLC 3.0.7 and security

Comments

If you've listened to some of my talks or spoke to me (I'm sorry for you), you know I'm a bit critic of those programs, because they give money to find the issues, not to fix them.
> What about you give money to VLC instead of random hackers?
Well, security is important, so this is cool for our users, but still this is a mixed bag, for me.

I've asked that question to Julia Reda a few months ago, and I think the answer was pretty interesting. It boils down to the absence of companies that provide this service ("security bugfix bounties") and are also willing to deal with basically being an EU contractor. So instead the EU-FOSSA bounties went to HackerOne, which is not perfect but is a step in the right direction that could be implemented immediately.

Also note that Google does provide bounties for security patches and hardening (https://www.google.com/about/appsecurity/patch-rewards/ -- VLC or ffmpeg are not in there, but many base libraries are) and for integrating FOSS projects into their fuzzing frameworks (https://www.google.com/about/appsecurity/patch-rewards/autof...). I don't know of any other company providing this kind of bounties for FOSS devs.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.