I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second.
I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
I believe this sums up the problem with online news: being first matters most to news sites. It drives traffic. Accurate reporting comes second.
I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
Actually, one did: numerama. That's all.
> I feel bad for VideoLAN, according to them the bug was in a 3rd party lib and was fixed 16 months ago.
My night and morning have been difficult, as you can imagine...
Thank you for your efforts in developing VLC, it is a great tool.
It shines bad light on the official institutions that they haven't checked back with you.
I've used VLC on all supported platforms for almost as long as it's been in existence: THANK YOU.
Please keep up the awesome work, VLC is a treasure.
The economics of the industry drive this behavior - most reporters have a quota of stories they have to write per day and there's no time or budget to even email sources let alone sit around waiting for a reply.
If you want to read more about this, I recommend the book "Trust me, I'm lying" by Ryan Holiday.
That said, I “read” a lot of of audiobooks and this one is self-narrated. I highly recommend the book, but don’t recommend Ryan Holiday as a narrator.
i also tried listening to conspiracy, also by him, and it was much more enjoyable (he narrates, but the sound quality is much better).
VLC is not a commercial product, but equally still took the same impact from this and as we know, many end-user will be oblivious of any retraction as the case with many media retractions/corrections that get buried and do not traction.
Maybe we need Open Lawyer as well as Open Source!
I'm of the thinking that the only way media would get any education would be litigation. Sad I know, but that is the World they operate in. Why else do media outlets have lawyer departments.
Apologies.
@ you and any lawyers
I know you probably don't want to go to some long-term battle in the courts with any of these groups. What about a libel suit in small claims court against each one? I wonder if that's even possible. If so, start with one to keep time/costs down, then (if victorious) hit the others either one at a time or simultaneously. At the least, the wins raise you some funding while providing some small deterrence from them doing it again.
Has any American newspaper or person or politician on twitter been forced to retract exaggerated claims?
Seemingly.
https://digitalcommons.wku.edu/cgi/viewcontent.cgi?article=1...
I'm not sure, doesn't look like this would fall under their remit, but no definitive yes or no jumping out for me either.
https://en.wikipedia.org/wiki/Software_Freedom_Conservancy
Not a long litigation list either, so hard to see any comparable cases in the two instances listed.
So I'm going to lean against a no, but I'm not 100% sure upon this.
To boot https://www.securityfocus.com/bid/109304 claims all versions are vulnerable and the vendor reported it
Of course, we never reported such a thing: a security issue in a 3rd party library, fixed more than 16months ago. And VLC binaries were updated 16months ago too...
The issue is that MITRE is not doing its job when assigning the CVE or even checking the validity of the claim. But they refuse to talk to us. Why?
Because stonewalling is SOP for government bureaucracies when they screw up.
When you're the government the various systems the people you screwed have for recourse work slightly differently so stonewalling works better than spewing out a ton of deny and distract PR like corporations do.
FTFY
A lot of people seem to be under the impression that when you just privatize a government agency, it magically becomes better. It doesn't.
Even on vulnerable systems this seems to have been a local issue (or do they do that for anything that might potentially pull malicious files from outside sources? Sounds kind of backwards.)
They always do that with VLC: even file can be on a playlist, and a playlist can be sent by email or over the web, with a link...
So they classify all VLC bugs with network and remote.
Hover your mouse over each button https://www.first.org/cvss/calculator/3.0 . There's Attack complexity 'low' and 'high', for instance. You're either a script kiddie or have a two billion dollar exploitation budget and all the human resources you need, but nothing in between.
AC not about the attacker, but the configuration of the component being assessed.
"A successful attack depends on conditions beyond the attacker's control. That is, a successful attack cannot be accomplished at will, but requires the attacker to invest in some measurable amount of effort in preparation or execution against the vulnerable component before a successful attack can be expected. For example, a successful attack may require the attacker: to perform target-specific reconnaissance; to prepare the target environment to improve exploit reliability; or to inject herself into the logical network path between the target and the resource requested by the victim in order to read and/or modify network communications (e.g. a man in the middle attack)."
But you could also argue 'Attack complexity' of any exploit which has per-os/arch exploits requires reconnaissance. There, I just boxed MS08-67 (which is arch-specific, iirc) as 'Attack Complexity: High' with pretty much any theoretical crypto attack which would cost billions to exploit :)
Lets not forget CVSS doesn't assess likelihood or business impact well (or at all) either. Your org is far more likely to get rekt if you do not enforce application whitelisting, compared to an intranet-exposed drupalgeddon vulnerability.
This problem has been around as long as more than one news outlet has been around... Getting the story first over getting the story right didn't get invented by online news.