Skip to content

Comment on VLC 3.0.7 and security

Comments

> people ranging from the usual security-asshole

This pretty much illustrates the attitude of most of the bug bounties programs holders.

VLC have a past with "security-asshole" that could explains why JB seems tired with some members of the infosec community in general. From what I've read from the past controversies, each time a security issue arises in VLC the team is attacked by an angry mob of infosecs.

This blog post closing remarks summarize the recurring issue well: https://www.beauzee.fr/2017/07/04/videolan-and-https/

Yeah, that'd really put me off reporting anything.

If you read a (dead, for some reason) comment by the author, he explains what that means: https://news.ycombinator.com/item?id=20147573

Perhaps he should be more specific in the blog post instead. Removing phrases like "security-asshole" in the first place would also go a long way.

Removing phrases like "security-asshole" in the first place would also go a long way.

I absolutely refuse to remove phrases like that. This is exactly what some of those people are and because they are security people does not allow them to behave less well than other people.

And I find that I'm being quite polite by not shaming those people publicly.

hey, I work in a low-level security group under a larger generic security org - at a general level, there are too many security-assholes and they make our lives harder when interacting with developers as they think we're all like that.

security-assholes are a huge problem

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.