Hacker News new | ask | show | jobs
by zahlman 31 days ago
Do you feel the same way about seeing "Segmentation fault (core dumped)" in the terminal from some other arbitrary program?

If not, why not?

1 comments

Because people often use VLC to view untrusted content.

Video is a great vector for distributing malware, especially sought-after grey area content like porn, conflict videos, celebrity leaks, pirated films, etc. Not enough people pay attention to the impact of video as a vector for compromise. All downloaded video should be sandboxed!

How many victims are known to be exploited by video codecs? Compare that with the wider landscape of how victims are being exploited.
Codec vulnerabilities in the browser have been a recurring source of exploits, as have similar vulnerabilities in phone messenger apps. The phone ones are particularly bad because phones typically preprocess received media files (for thumbnailing etc) so a vulnerability here can sometimes be chained into a remotely triggered near-instant compromise.

I don’t know if there is data on exploits due to downloaded media but it would be an easy way to exploit specific target populations (find a video of interest to them and “leak” it somewhere).

If said videos or media are doing that, there would be a corpus of samples by now. I'm very sceptical of this.
Absence of evidence is not evidence of absence, but I concede that attacks via locally downloaded video may not be a widespread problem at the moment. The problem is we just don’t know. I doubt these attacks would be effective against government or corporate targets (not sure who is torrenting on their work computer) and that’s where most post-exploit forensic data is gathered.