• ɯᴉuoʇuɐ@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    1
    ·
    2 months ago

    Has anyone read the article? I barely understand what the fuss is actually about, the text is meandering and repeats semi-relevant details (specifically the part about libxml2).

    • MentalEdge@sopuli.xyz
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      2 months ago

      In a nutshell:

      Google is spending a shitload of money to find bugs in FOSS projects, but then refuses to spend the fraction more it would cost to contribute an actual fix, rather than just a bug report.

      Basically, they are willing a spend a ton on finding a bunch of work for FOSS developers to do, but not on actually getting any of it done.

      • Anna@lemmy.ml
        link
        fedilink
        arrow-up
        0
        ·
        2 months ago

        Not just that the bug they reported only affects some obscure LucasArt codec which isn’t even included in the build by default. Plus I’m pretty sure Google heavily uses ffmpeg for YouTube.

        • bamboo@lemmy.blahaj.zone
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          Plus google doesn’t really care if the obscure LucasArt codec is actually fixed, they’re raising the bugs publicly to sell their AI. This is marketing, not security. The more bugs it finds the better, since sales doesn’t care about the quality of the bugs found.