• MentalEdge@sopuli.xyz
    link
    fedilink
    arrow-up
    80
    ·
    edit-2
    10 hours ago

    In a nutshell:

    Google is spending a shitload of money to find bugs in FOSS projects, but then refuses to spend the fraction more it would cost to contribute an actual fix, rather than just a bug report.

    Basically, they are willing a spend a ton on finding a bunch of work for FOSS developers to do, but not on actually getting any of it done.

    • Anna@lemmy.ml
      link
      fedilink
      arrow-up
      39
      ·
      9 hours ago

      Not just that the bug they reported only affects some obscure LucasArt codec which isn’t even included in the build by default. Plus I’m pretty sure Google heavily uses ffmpeg for YouTube.

      • bamboo@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        17
        ·
        5 hours ago

        Plus google doesn’t really care if the obscure LucasArt codec is actually fixed, they’re raising the bugs publicly to sell their AI. This is marketing, not security. The more bugs it finds the better, since sales doesn’t care about the quality of the bugs found.