Comment on FFmpeg to Google: Fund Us or Stop Sending Bugs

lmmarsano@lemmynsfw.com ⁨23⁩ ⁨hours⁩ ago

They’re bug reports: no one needs to fix them. This problem is solved easily enough by letting the chips fall.

If companies want them fixed badly enough, they can send bug fixes, which is much cheaper than the alternative (paying more engineers to develop a non-open alternative). Those companies have at least as much interest as anyone to keep that software maintained & secure.

The position of the FFmpeg X account is that somehow disclosing vulnerabilities is a bad thing.

The truth is never a bad thing. They don’t need to care. A bug is a bug: better to know than not.

source
Sort:hotnewtop