• baronofclubs@lemmy.world
    link
    fedilink
    arrow-up
    18
    ·
    11 hours ago

    Google also appended a 90 day disclosure policy to their reports. FFmpeg can always say , we’re not going to fix that, but that would mean a security issue would be published, and letting nefarious actors act on it. Even if it would only affect 3 users, the idea that the follow up information of, “don’t use FFmpeg for this use case or you’ll be hacked,” would be out there.

    The criticism arrises from the fact Google, the multinational mega-corp, is sending these reports with the 90 day disclosure policy to a tiny unpaid team. How about the company with something like $100,000,000,000/year in net income offer a patch or two?