trash
37
Arthur Besse
link
fedilink
99M

Big ups to the ffmpeg team for making swiss army knife software that probably hundreds of millions of people use every day even though they’ve never heard of it!

Skimming the changelog, though, this caught my eye:

codec/format registration APIs removed, all formats are always registered

This seems like a bad decision to me. Obscure codecs are more likely to have old unnoticed exploitable bugs, so, for defense in depth, websites processing user uploads using ffmpeg-based tools are well advised to disable support for the vast majority of formats that ffmpeg supports. I assume they can still do that at compile time, which I would guess is what big sites with dedicated security teams probably do, but being able to disable codecs through the API would mean that smaller sites could also implement this kind of security posture while still using distro-provided packages (eg without taking on the burden of building ffmpeg themselves). I hope the developers reconsider this!

(Of course you should also still run it in a sandbox…)

@LLVMcompile
link
fedilink
49M

Firefox and chromium (two out of three big web engines) use ffmpeg so billions use every day, for sure. In chrome though they disabled the obscure codecs.

CHEF-KOCH
banned
link
fedilink
29M

They might going or trying to make v5.0 LTS.

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

  • 0 users online
  • 18 users / day
  • 32 users / week
  • 74 users / month
  • 358 users / 6 months
  • 5.5K subscribers
  • 1.41K Posts
  • 5.21K Comments
  • Modlog