VLC threatens to sue Secunia over full disclosure
secunia.com
secunia.com
Comments on rebuttal ask "why don't they provide you with working exploit? (in example EIP = 0x41414141)"
So someone claims they did attaching an example mkv file? http://seclists.org/fulldisclosure/2013/Jul/71 https://twitter.com/coolkaveh/status/354716804783943680
Even worse, while attacking Secunia for supposed "lies", they confess to a lie of their own:
https://twitter.com/videolan/status/354861344710864896
Unbelievable.
At some point, you need to make them react. And the only way a small open source project can get an answer from a big company is usually threat to attack their wallet.
Sure, it might have been not the best thing to say, but I don't know how else we can make them react on the various issues that have been going on for years with Secunia.
Aside from the fact that it was socially unacceptable, do you realize you could have exposed yourself to legal attack?
I don't know what rules are typical in Europe for declaratory judgement actions, but in the US, Secunia would have basis for filing against you to have their speech declared non-defamatory.
If you don't have a lawyer to do it for you, don't threaten legal action.
I would prefer spending my free time working on VLC (which I do usually) than having to deal with those things... Especially since we still have no vulnerability POC...
It is not illegal in Denmark, if one of the participants publishes it. Similarly, it is not illegal to record a conversation in Denmark without acknowledgement from the other participants, if one of the participants is the one recording it.
I don't claim to know the law on this in those countries, though Svip says it's not illegal in Denmark (Secunia's jurisdiction).
Letter of the law aside, are court records not public in your jurisdiction? In the US, that email would have been promptly entered into evidence without redaction. In that light, posting it now makes no practical difference. You'd already dishonestly informed them you were commencing suit in 24 hours.
> I would prefer spending my free time working on VLC
Then do so. And if you really feel the VLC project needs to respond to Secunia in any way, have someone else do it. You're not very good at it.
I'm so glad that you volunteered... Seriously, do you have any idea how few we are?
Anyway....interesting debate about statically linked libraries. Seems like the original vulnerability was in ffmpeg (vlc statically links to it). So in this case what should/can videolan do ?
As such, it's VLC responsibility to not ship a product that may harm a user's computer, even if the error is not in their code.
To give you a similar example, have a look at this post about the impact of vulnerabilities in third party libraries on commercial forensic products[1].
I would suspect that expert witnesses relying on this could have a case argued against them in court regarding the integrity of the application data and their processes if they're not prepared.
[1] - https://www.cert.org/blogs/certcc/2013/07/forensics_software...
All the vulnerabilities have been fixed. Which one are you referring to?
> Seems like the original vulnerability was in ffmpeg (vlc statically links to it). So in this case what should/can videolan do ?
I responded to the question. But to answer yours:
> Which one are you referring to?
Specifically the ffmpeg bug that Secunia reported that you claimed to fix, which wasn't quite correctly fixed, when you decided to go and stir up drama on the Internet and threaten Secunia with lawyers you don't have and can't afford.
That one.
And that it's fixed now is irrelevant. You made a dick move by threatening legal action without having anything to back it up and it's cost you a lot of goodwill no doubt by stirring it up.
Thus far Secunia has done neither.
Yet, they actually faked a report and lied about the Impact of the MKV issue...
Well at least it's not wonder why those 2 groups fail to communicate. Thanks for the update Maxious!
Also see the response from VLC: http://www.jbkempf.com/blog/post/2013/More-lies-from-Secunia
Not full disclosure at all, just security claims that no one can back up.
This isn't necessarily a bad thing, they're probably more resilient as well due to that loosely coupled structure, it just means that sometimes you get inconsistent communications, sometimes about important topics. It would be a mistake to think that VLC has some underlying dislike of vulnerability reports or an aversion to fixing known bugs, and I would be really surprised if counsel has been retained (or has vetted) this 'plan' to sue.
why shouldn't secunia work with him about the exploit ?
But I have to ask, why it is so important to VLC, or you, that secunia take down their advisory? Does it really affect VLC negatively?
Because we receive a LOT of emails, from PSI users and from clueless users telling us that our software is insecure. This is a lot of support load and takes quite a bit of time.