Hacker News new | ask | show | jobs
by iamnothere 33 days ago
Because people often use VLC to view untrusted content.

Video is a great vector for distributing malware, especially sought-after grey area content like porn, conflict videos, celebrity leaks, pirated films, etc. Not enough people pay attention to the impact of video as a vector for compromise. All downloaded video should be sandboxed!

1 comments

How many victims are known to be exploited by video codecs? Compare that with the wider landscape of how victims are being exploited.
Codec vulnerabilities in the browser have been a recurring source of exploits, as have similar vulnerabilities in phone messenger apps. The phone ones are particularly bad because phones typically preprocess received media files (for thumbnailing etc) so a vulnerability here can sometimes be chained into a remotely triggered near-instant compromise.

I don’t know if there is data on exploits due to downloaded media but it would be an easy way to exploit specific target populations (find a video of interest to them and “leak” it somewhere).

If said videos or media are doing that, there would be a corpus of samples by now. I'm very sceptical of this.
Absence of evidence is not evidence of absence, but I concede that attacks via locally downloaded video may not be a widespread problem at the moment. The problem is we just don’t know. I doubt these attacks would be effective against government or corporate targets (not sure who is torrenting on their work computer) and that’s where most post-exploit forensic data is gathered.