Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
sjvn
@sjvn@mastodon.social  ·  activity timestamp 19 hours ago

FFmpeg to Google Fund Us or Stop Sending Bugs: https://thenewstack.io/ffmpeg-to-google-fund-us-or-stop-sending-bugs/ by @sjvn

The clash between small volunteer-driven, open-source projects, such as FFmpeg & the billion-dollar companies built on their work, which demand rapid security patches, is heating up.

The New Stack

FFmpeg to Google: Fund Us or Stop Sending Bugs

A lively discussion about open source, security, and who pays the bills has erupted on Twitter. 
  • Copy link
  • Flag this post
  • Block
Eliot Lash
@Eliot_L@social.coop replied  ·  activity timestamp 3 hours ago

@sjvn Yeah this sucks. I made a summary of this article.

Four panel "drowning high five" meme.
1: open source maintainer 's hand is reaching out of the water.
2: Google's hand reaches towards it.
3: Google's hand high-fives it with the label "CVE Slop"
4. Maintainer's hand sinks into the water
Four panel "drowning high five" meme. 1: open source maintainer 's hand is reaching out of the water. 2: Google's hand reaches towards it. 3: Google's hand high-fives it with the label "CVE Slop" 4. Maintainer's hand sinks into the water
Four panel "drowning high five" meme. 1: open source maintainer 's hand is reaching out of the water. 2: Google's hand reaches towards it. 3: Google's hand high-fives it with the label "CVE Slop" 4. Maintainer's hand sinks into the water
  • Copy link
  • Flag this comment
  • Block
Nicole Parsons
@Npars01@mstdn.social replied  ·  activity timestamp 8 hours ago

@sjvn

Wonder if FFmpeg can do to Google what Pantone did to Adobe?

https://www.theverge.com/2022/11/1/23434305/adobe-pantone-subscription-announcement-photoshop-illustrator

https://www.wired.com/story/adobe-pantone-color-subscription-fee/

https://www.userlandia.com/home/2022/11/adobe-pantone-faq

https://www.nsymbio.com/2023/07/06/adobe-drops-pantone/

Or form an evil axis alliance elsewhere
https://news.microsoft.com/source/2025/11/05/pantone-and-microsoft-unite-to-enhance-creative-exploration-through-ai/

https://www.fastcompany.com/91435187/pantone-color-generator-ai-tool

Userlandia

The Adobe and Pantone Color Apocalypse: Frequently Asked Questions — Userlandia

Adobe has let their license for Pantone colors lapse, with the hues disappearing from their apps. Pantone wants you to pay them for digital color libraries with a subscription scheme. What does this mean for digital content creators and the design industry?
WIRED

Adobe Just Held a Bunch of Colors Hostage

Certain Pantone collections now require users to pay $15 a month to access them—with colors turned black unless you pay up.
The Verge

You now have to pay to use Pantone colors in Adobe products

Pretty colors come with a premium price.
  • Copy link
  • Flag this comment
  • Block
Henrik Pauli
@phl@mastodon.social replied  ·  activity timestamp 11 hours ago

@sjvn Will Google create a fake community poll like they did with XSLT and try to replace this too?

  • Copy link
  • Flag this comment
  • Block
KarlE
@KarlE@mstdn.animexx.de replied  ·  activity timestamp 13 hours ago

@sjvn I feel it would be appropriate that companies as powerful as Google (or indeed any commercial "customers") should deliver an OSS bug report together with a suggested patch, in the coding style of the project concerned and tested.

  • Copy link
  • Flag this comment
  • Block
.:\dGh/:.
@darkghosthunter@mastodon.social replied  ·  activity timestamp 13 hours ago

@sjvn This is the kind of shit that "Free for everyone except if you make more than $1M" type of licenses try fix.

I guess people have an ideology to defend when they don't support 100% free software, but corpos don't care.

Next FFmpeg release should have that kind of licensing.

  • Copy link
  • Flag this comment
  • Block
Tim
@stiv@mastodon.social replied  ·  activity timestamp 14 hours ago

@sjvn Now look here- big tech didn't lay all these people off just so it could fund open source!

  • Copy link
  • Flag this comment
  • Block
Kevin Karhan :verified:
@kkarhan@infosec.space replied  ·  activity timestamp 14 hours ago

@sjvn this is actually very simple to solve:

  • Make #Support paid-only and reject submission from non - subscribers.

This something an increasing number of #FLOSS projects do: Rejecting submissions of non-allowlisted users without a valid #SupportSubscription at time of submission!

  • So if #Google is literally demanding an #SLA they should OFC pay for that.

Anything else is just being a rich asshole corporation leeching!

  • Copy link
  • Flag this comment
  • Block
Kevin Karhan :verified:
@kkarhan@infosec.space replied  ·  activity timestamp 14 hours ago

@sjvn
Just like people pay for the SLA of their #FireBrigade via #taxation and the #FireInsurance which has to cough up the cost of Firefighter Deployments in case of a Fire.

  • Copy link
  • Flag this comment
  • Block
John Breen
@jab01701mid@mastodon.social replied  ·  activity timestamp 14 hours ago

@sjvn Hey, I've got the source. Send me a PR to resolve, and a check for $10,000, and I'm happy to help.

  • Copy link
  • Flag this comment
  • Block
lp0 on fire :unverified:
@lp0_on_fire@social.linux.pizza replied  ·  activity timestamp 15 hours ago

@sjvn, in what way are they sending bugs? Are they causing faulty commits to be made, or something?

Stupid journalistic error. This is about bug reports, not bugs.

  • Copy link
  • Flag this comment
  • Block
Maxi 11x 💉
@frumble@chaos.social replied  ·  activity timestamp 15 hours ago

@sjvn This is off topic but why is #ffmpeg still active on fascist Xitter and not at all on the fediverse? This isn’t painting them in sympathetic light.

  • Copy link
  • Flag this comment
  • Block
Jeff Atwood
@codinghorror@infosec.exchange replied  ·  activity timestamp 16 hours ago

@sjvn fuck this. If Google won't donate, I will. I just did, in fact.

  • Copy link
  • Flag this comment
  • Block
Nicole Parsons
@Npars01@mstdn.social replied  ·  activity timestamp 16 hours ago

@sjvn

US corporations with billions of dollars of investment by petrostate despots
https://www.cnbc.com/2018/04/07/heres-a-look-at-who.html

Very keen on forever unpaid labor.
https://digit-research.org/blog/unpaid-work-and-the-case-of-open-source-labour/

https://www.promarket.org/2024/10/08/how-cultural-norms-help-companies-exploit-unpaid-workers/

https://medium.com/@reshaping_work/what-are-the-features-of-unpaid-labour-in-the-platform-economy-ac42a3f8256b

https://www.weizenbaum-institut.de/news/detail/theory-on-the-politics-of-unpaid-labour/

Social media platforms; unpaid content "voluntarily" donated to billionaires Elon Musk, Zuckerberg, & Larry Ellison.
https://www.oii.ox.ac.uk/news-events/videos/unpaid-labour-in-the-platform-economy-a-typology-of-wage-theft-in-the-digital-age/

Unpaid media moderators
https://news.northwestern.edu/stories/2022/05/unpaid-social-media-moderators

https://cornellresearch.medium.com/dream-work-unpaid-labor-in-the-gig-economy-4926e673bec5

https://mstdn.social/@Npars01/115533069491772554

  • Copy link
  • Flag this comment
  • Block
Josh Bressers
@joshbressers@infosec.exchange replied  ·  activity timestamp 16 hours ago

@sjvn You should talk to @Di4na about open source sustainability

He has far more insight and experience than a bunch of folks from big tech

  • Copy link
  • Flag this comment
  • Block
Peter Kraus
@pkraus@berlin.social replied  ·  activity timestamp 17 hours ago

@sjvn "Google provides more assistance to open source software projects than almost any other organization, and these debates are more likely to drive away potential sponsors than to attract them."

Why are you still here, Google?

  • Copy link
  • Flag this comment
  • Block
Bart Veldhuizen 🚀
@BartV@mastodon.social replied  ·  activity timestamp 17 hours ago

@sjvn add more bugs that specifically break Google’s systems and nothing else

  • Copy link
  • Flag this comment
  • Block
Sassinake! - ⊃∪∩⪽
@Sassinake@mastodon.social replied  ·  activity timestamp 17 hours ago

@sjvn

they are just going to buy them and corrupt them.

  • Copy link
  • Flag this comment
  • Block
Toni Aittoniemi
@gimulnautti@mastodon.green replied  ·  activity timestamp 17 hours ago

@sjvn @sjvn Golems with golden heads and clay legs…

  • Copy link
  • Flag this comment
  • Block
Multimilliardaire
@multimilliardaire@piaille.fr replied  ·  activity timestamp 18 hours ago

@sjvn

Mais que fait #ffmpeg sur X/Twitter 💩 au juste ?

  • Copy link
  • Flag this comment
  • Block
Wolf480pl
@wolf480pl@mstdn.io replied  ·  activity timestamp 18 hours ago

@sjvn I think it's unclear what's preventing ffmpeg devs from just ignoring these bug reports.

Like, if GPZ were to publish the details of an unfixed vuln in a rarely-used feature of ffmpeg, there shouldn't be much impact on real users, most of the pain would be with the CVE-obsessed corpos that use ffmpeg in their products, right?

  • Copy link
  • Flag this comment
  • Block
Gregory
@grishka@mastodon.social replied  ·  activity timestamp 18 hours ago

@sjvn sometimes, in my personal projects, when someone acts like I owe them something by virtue of having made and published the project, I do this:
https://github.com/grishka/NearDrop/issues/198

  • Copy link
  • Flag this comment
  • Block
tuxta
@tuxta@social.linux.pizza replied  ·  activity timestamp 6 hours ago

@grishka @sjvn that thread just pissed me off ! Good response to this jerk !

  • Copy link
  • Flag this comment
  • Block
Caden
@tarix29@tech.lgbt replied  ·  activity timestamp 14 hours ago

@grishka @sjvn it's crazy how people view GitHub issues as a way to get people to do work for them for free

  • Copy link
  • Flag this comment
  • Block
zardoz.el
@zardoz03@mastodon.online replied  ·  activity timestamp 18 hours ago

@grishka @sjvn jesus christ

  • Copy link
  • Flag this comment
  • Block
Antacon
@Antacon@ruby.social replied  ·  activity timestamp 18 hours ago

@grishka @sjvn this is insane. Submitting bugs on GitHub, then brushing off your suggestion of fetching logs??? Not even an iota of empathy or an attempt at doing better. I'm sorry you are dealing with that.

  • Copy link
  • Flag this comment
  • Block
Kevin Karhan :verified:
@kkarhan@infosec.space replied  ·  activity timestamp 14 hours ago

@Antacon @grishka @sjvn shit like this is why I see more projects than ever limiting issue submissions to support subscribers only...

  • Also people who report bugs but then refuse to reply to comments or even remotely work towards making them reproduceable are just a waste of time.
  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login