← Graph

Protecting against ffmpeg vulnerabilities

question 2 connections

Audience question after the talk: how did/would the speaker protect the system against ffmpeg vulnerabilities? Answer: in the proof-of-concept they didn't, because videos came from the client's customers; today the speaker would isolate the ffmpeg process and restrict its access to the rest of the system. Back then ffmpeg's ability to compromise a server wasn't as widely known.

answer_summary
They didn't at the time (trusted input); today he would sandbox ffmpeg and deny it access to the rest of the system.
question Protecting against ffmpeg vulnerabilities
about
FFmpeg tool
Question concerns security of the ffmpeg process.
question Protecting against ffmpeg vulnerabilities
asked_at
Audience Q&A after the talk.

Provenance

Read by
5 extractions