Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
endlessmonotony
Nov 4, 2009

by Fritz the Horse

ErIog posted:

Install PotPlayer and get hacked by Koreans?

Edit: Looks like there was a similar CVE in PotPlayer for .wav file parsing last year, lol. My hunch is that any media application that handles tons of different formats is always going to be a secfuck because parsing is a secfuck and you can't support a ton of different formats and codecs without having a lot of parsers around.

I mean, yeah, that's what I expect, but by now they have a track record of throwing shitfits on twitter over their secfucks, which is worse than just having secfucks.

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe

CommieGIR posted:

:stare: I really have my doubts that MITRE failed to report that to them...

I'm sure they reported it, but it was through https

Schadenboner
Aug 15, 2011

by Shine

20 days is not 2 months, though?

E: Unless it is? loving metric system! :argh:

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://trac.videolan.org/vlc/ticket/22474

pr0digal
Sep 12, 2008

Alan Rickman Overdrive



Perfectly normal comment on a bugtracker

El Mero Mero
Oct 13, 2001

FTC Equifax settlement is out

Anyone's lifetime supply of credit monitoring running out?

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

endlessmonotony posted:

Okay VLC is clearly a clusterfuck.

What are everyone's recommendations for the same level of "install it and forget about it" these days?

For Windows:
CCCP: Combined Community Codec Pack. Comes with Media Player Classic. A little old, but works flawlessly.

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
multimedia is an utter disaster and anyone sane eventually has enough and flees in terror

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
if your parser doesn’t successfully parse /dev/random, someone will eventually complain about it not being able to open their file missing every fourth byte that was created by someone who completely misunderstood the spec because some other program accidentally manages to open it due to bugs in that program’s parser. if your parser is two cycles too slow then on one specific model of cpu which was only ever bought by seven people you’ll drop frames, and that’s The End Of The World so we can’t possibly get rid of this giant pile of UB (that’s only faster because some of the bounds checks are getting optimized out)

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
sometimes people jam files together with cat so I hope your parser handles the file suddenly becoming a different file type midway through. this one too smart for his own good rear end in a top hat made one which does handle that in the 90s so if you don’t then you suck and should die

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
obviously a PowerPoint file is a video, why won’t you play it?

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
uhh pptx is a video container format, deal with it

The_Franz
Aug 8, 2003

CommieGIR posted:

For Windows:
CCCP: Combined Community Codec Pack. Comes with Media Player Classic. A little old, but works flawlessly.

lol recommending codec packs in 2019

"hmm, yes, vlc had a bug, so instead i'll just install this random mishmash of software put together by 14 year old anime enthusiasts and downloaded from a random site. oh, i have to remember to do a custom install so i can unselect all of the adware"

you can just install plain mpc on windows and it will play everything that isn't an old realmedia file or some pirated pedo anime that some nerdlingers enabled a bunch of experimental encoder flags on so their waifu's face has minimal banding

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
despite the name, cccp isn't a codec pack and it doesn't come with any adware

it is horribly out of date these days though

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
also if you're trying to avoid software written by anime fans you will want to avoid mpc too

pseudorandom name
May 6, 2007

are torrents still encoded in the dumbest possible non-standard codecs and containers or have the adopted MPEG 4 yet?

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
theres an alternate reality game unfolding. thread here https://forums.somethingawful.com/showthread.php?threadid=3894623

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

The_Franz posted:

lol recommending codec packs in 2019

"hmm, yes, vlc had a bug, so instead i'll just install this random mishmash of software put together by 14 year old anime enthusiasts and downloaded from a random site. oh, i have to remember to do a custom install so i can unselect all of the adware"

you can just install plain mpc on windows and it will play everything that isn't an old realmedia file or some pirated pedo anime that some nerdlingers enabled a bunch of experimental encoder flags on so their waifu's face has minimal banding

Its a good product, and its covers all the bases :shrug:

Plorkyeran posted:

it is horribly out of date these days though

Yeah, but it still works.

Janitor Prime
Jan 22, 2004

PC LOAD LETTER

What da fuck does that mean

Fun Shoe

pseudorandom name posted:

are torrents still encoded in the dumbest possible non-standard codecs and containers or have the adopted MPEG 4 yet?

Everything released is in H.264 and mkv container. I'm more pissed that they have been slow to move to H.265 which has better compression and is supported by most devices since 2016.

The solution to all this codec poo poo is Plex. It will transcode your stupid formats on the fly and let you play it back on whatever device you have.

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
just link to a thread about video codecs and keep this thread security-related jfc

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed

CommieGIR posted:

Yeah, but it still works.

using a four-year-old video player is appropriate for this thread

Midjack
Dec 24, 2007



Plorkyeran posted:

using a four-year-old video player is appropriate for this thread

probably more appropriate for the bitcoin thread really

ClassActionFursuit
Mar 15, 2006

CommieGIR posted:

For Windows:
CCCP: Combined Community Codec Pack. Comes with Media Player Classic. A little old, but works flawlessly.

what a username/post combo

:ussr:

BlankSystemDaemon
Mar 13, 2009



endlessmonotony posted:

Okay VLC is clearly a clusterfuck.

What are everyone's recommendations for the same level of "install it and forget about it" these days?
MPV. Use a package manager to install it, and remember to run the package manager regularly to update and upgrade.
On Windows there's Chocolatey, Linux has a variety, the BSDs use some form of pkg*, and macOS has homebrew.

The only realistic way to get things faster is to build from source, and unless you're an absolute nerd, you don't wanna have to deal with that mess.

endlessmonotony
Nov 4, 2009

by Fritz the Horse

D. Ebdrup posted:

MPV. Use a package manager to install it, and remember to run the package manager regularly to update and upgrade.
On Windows there's Chocolatey, Linux has a variety, the BSDs use some form of pkg*, and macOS has homebrew.

The only realistic way to get things faster is to build from source, and unless you're an absolute nerd, you don't wanna have to deal with that mess.

I'm more looking for something I can toss onto family etc computers as "the video player" for whatever the hell their ancient phones record video in and avoiding secfucks, janitoring or calls about how it doesn't work.

But what it sounds like is that all media players are the secfucks.

Xarn
Jun 26, 2015

pr0digal posted:



Perfectly normal comment on a bugtracker

Sadly deleted.

cinci zoo sniper
Mar 15, 2013




endlessmonotony posted:

I'm more looking for something I can toss onto family etc computers as "the video player" for whatever the hell their ancient phones record video in and avoiding secfucks, janitoring or calls about how it doesn't work.

But what it sounds like is that all media players are the secfucks.

mpc-be

Dylan16807
May 12, 2010
the most recent comment currently says

quote:

Issue is too old libebml in Ubuntu 18.04: libebml 1.3.6 fixes this issue. End of story: VLC is not vulnerable, whether this is 3.0.7.1 or even 3.0.4. The issue is in a 3rd party library, and it was fixed in VLC binaries version 3.0.3, out more than one year ago...

so I completely understand why someone would look at an article titled "You Might Want to Uninstall VLC. Immediately." (how I first heard of this) and complain about fake news.

even if the exploit was active it would just mean not opening any strange mkvs for a while.

Xarn
Jun 26, 2015
Ubuntu 18.04 is the LTS release of what is, AFAIK, the most popular Linux distro. Now, you might say that it is reasonable to be annoyed by the fact that distro package is stuck in the stone age (been there, it is indeed annoying as gently caress), but 1) that does not make it fake news, 2) you should post it after you figure out that the problem is indeed caused by an obsolete version of a distro, not as one of the first comments on an issue.


Or maybe I am the security idiot, who knows :shrug:

Dylan16807
May 12, 2010

Xarn posted:

Ubuntu 18.04 is the LTS release of what is, AFAIK, the most popular Linux distro. Now, you might say that it is reasonable to be annoyed by the fact that distro package is stuck in the stone age (been there, it is indeed annoying as gently caress), but 1) that does not make it fake news
but nobody is calling it a linux-only problem in a package depended on by VLC

the articles are falsely claiming that the windows version is vulnerable

Xarn posted:

2) you should post it after you figure out that the problem is indeed caused by an obsolete version of a distro, not as one of the first comments on an issue.
I'm not sure what went on behind the scenes but they at least knew it didn't work on the current version at that point

Dylan16807 fucked around with this message at 12:34 on Jul 24, 2019

Potato Salad
Oct 23, 2014

nobody cares


...uhhhhhhhhhhh now that I've had a sec to look at this, this is an issue upstream of vlc

like, very clearly upstream. if I was responsible for publishing this cve, and I know it's easy to 2020 hindsight armchair yours poo poo, I definitely would have asked the question of who actually owns the glitch

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I installed a handful of MS published codecs through the windows app store so they are get maintained property and watch stuff either through the browser or windows media player and sleep in a bed with my wife

Jewel
May 2, 2009

ouch

https://bugzilla.mozilla.org/show_bug.cgi?id=1567114

quote:

MITM on all HTTPS traffic in Kazakhstan
They asked end-users to install government-issued certificate authority on all devices in every browser

Shaggar
Apr 26, 2006

BangersInMyKnickers posted:

I installed a handful of MS published codecs through the windows app store so they are get maintained property and watch stuff either through the browser or windows media player and sleep in a bed with my wife

the UWP windows media player seems to work fine for everything

bonelessdongs
Jul 17, 2019

Vomik posted:

the eu already has their own intelligence agencies with backdoors why would they need the nsa’s

American backdoors are the best in the world, let me tell you folks

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
so this got posted to the grey thread

saphirecalypso posted:

I have always been a fan of elliptic curve. Is there anything that you suggest which is better?

I am new to these forums.



apparently there is a crypto challenge involved. if you look at his rap sheet it appears that they posted another thread and people took a crack at it

Wiggly Wayne DDS
Sep 11, 2010



Rufus Ping posted:

theres an alternate reality game unfolding. thread here https://forums.somethingawful.com/showthread.php?threadid=3894623
smh at this arg

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Xarn posted:

Ubuntu 18.04 is the LTS release of what is, AFAIK, the most popular Linux distro. Now, you might say that it is reasonable to be annoyed by the fact that distro package is stuck in the stone age (been there, it is indeed annoying as gently caress), but 1) that does not make it fake news, 2) you should post it after you figure out that the problem is indeed caused by an obsolete version of a distro, not as one of the first comments on an issue.


Or maybe I am the security idiot, who knows :shrug:

Android is the most popular linux. Ubuntu is the most well known because people love trash, but RHEL variants are more popular for the one real, non-phone, use of linux which is on servers.

The_Franz
Aug 8, 2003

Dylan16807 posted:

the most recent comment currently says


so I completely understand why someone would look at an article titled "You Might Want to Uninstall VLC. Immediately." (how I first heard of this) and complain about fake news.

even if the exploit was active it would just mean not opening any strange mkvs for a while.

people love to poo poo on vlc in general, and i can understand why. i once made the mistake of sending in a fix for a minor bug that i found and dealing with those french sperglords was not worth it. they seem actively hostile to outsiders

Adbot
ADBOT LOVES YOU

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

The_Franz posted:

they seem actively hostile to outsiders

But enough about the french, what about the vlc guys specifically

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply