VideoLANOvěřený účet

@videolan

Official tweets from the project, and the community.

videolan.org
Připojil se listopad 2009

Tweety

Zablokovali jste uživatele @videolan.

Opravdu chcete tyto tweety zobrazit? Zobrazením tweetů nedojde k odblokování uživatele @videolan.

  1. Připnutý tweet
    24. 7.

    About the "security issue" on : VLC is not vulnerable. tl;dr: the issue is in a 3rd party library, called libebml, which was fixed more than 16 months ago. VLC since version 3.0.3 has the correct version shipped, and did not even check their claim. Thread:

    Zobrazit toto vlákno
    Vrátit
  2. 2. 8.

    VLC for Android has a new beta version, 3.2.0 beta2: numerous updates in the interface to make it more usable and fixed in the backend! Register on

    Vrátit
  3. Retweetnuto uživatelem
    31. 7.

    We are excited to announce for . Learn all about building Crossplatform Multimedia Apps! Make sure to save your stop, we have limited availability!

    Vrátit
  4. 31. 7.

    Of course, the Safari demo is using dav1d in Wasm! cc

    Zobrazit toto vlákno
    Vrátit
  5. 31. 7.

    AV1 live encode and playback demo at AV1 in (ARM+x86), , , Safari and VLC, all using dav1d. Encoded live with SVT-AV1 in (360p to 1080p) format.

    Zobrazit toto vlákno
    Vrátit
  6. 26. 7.

    As some of you suggested, we are going to try the process to become our own CNA for VLC (and maybe some other multimedia libraries). This should avoid issues like the one we just had.

    Vrátit
  7. Retweetnuto uživatelem
    25. 7.
    Odpověď uživatelům

    libebml vulnerability has been fixed, for Ubuntu 18.04 users. A good "sudo apt update" & "sudo apt upgrade" will fix it.

    Vrátit
  8. Retweetnuto uživatelem
    25. 7.

    Perfect illustration of talk of JB Kempf from about toxicity of some of the infosec community members (VLN reporters, institutions, companies, media). We HAVE TO FIX our community, NOW. Slides: /video: RT please

    Vrátit
  9. Retweetnuto uživatelem
    25. 7.

    VLC wasn't vulnerable after all, and some reporters failed to do their homework. We saw headlines like "You Might Want to Uninstall VLC. Immediately."

    Vrátit
  10. Retweetnuto uživatelem
    24. 7.

    VLC developer debunks reports of ‘critical security issue’ in open source media player

    Vrátit
  11. Retweetnuto uživatelem
    24. 7.

    What's liability? Well, they may issue a 'we are sorry' tweet. While will have to deal with the mess for a couple of months (if not years). Nice job, MITRE!

    Vrátit
  12. Retweetnuto uživatelem
    24. 7.

    For the record, the bug was in libebml 1.3.5. It was fixed in libebml 1.3.6 which was released on 2018-04-20. It is included in official VLC builds since 3.0.3.

    Vrátit
  13. 24. 7.

    Would behave the same way if we were Microsoft or another big company? But no, we're just a small non-profit, that does not even have the money to pay someone fulltime... End-of-thread.

    Zobrazit toto vlákno
    Vrátit
  14. 24. 7.

    And to finish, both NVD and were contacted more than 12 hours, (7pm CET) and we still are waiting for an answer, while is asking us for clarifications...

    Zobrazit toto vlákno
    Vrátit
  15. 24. 7.

    joined of course, with the ridiculous "60%" of the fix is done, which is what the reporter added in the public bugtracker...

    Zobrazit toto vlákno
    Vrátit
  16. 24. 7.

    It is still on the frontpage. If you are working at , are you not a bit ashamed?

    Zobrazit toto vlákno
    Vrátit
  17. 24. 7.

    You can bet that noone of them will correct their article, or it will be in a small subtweet somewhere hidden.

    Zobrazit toto vlákno
    Vrátit
  18. 24. 7.

    and then, of course, decided to play the clickbaiting of "Uninstall VLC now, or you are all going to die". Of course, did not contact at all to check their info. And then, we got hundreds of article about VLC insecurity.

    Zobrazit toto vlákno
    Vrátit
  19. 24. 7.

    So, when decided to do their "disclosure", all the media jumped in, without checking anything nor contacting us.

    Zobrazit toto vlákno
    Vrátit
  20. 24. 7.

    And of course, did not contact us for clarifications.

    Zobrazit toto vlákno
    Vrátit
  21. 24. 7.

    Then, this time, for whatever reason, decided to do an advisory , without checking either the crash (it's not hard), or the vulnerability, or even contacting us.

    Zobrazit toto vlákno
    Vrátit

Načítání se zjevně nějak vleče.

Možná je překročena kapacita Twitteru nebo došlo k momentálnímu zablokování. Zkuste to znovu nebo se podívejte na stavovou stránku Twitteru, kde najdete další informace.

    Také by se vám mohlo líbit

    ·