Microsoft employee:

Hi, This is a high priority ticket and the FFmpeg version is currently used in a highly visible product in Microsoft. We have customers experience issues with Caption during Teams Live Event. Please help

Maintainer’s comment on twitter:

After politely requesting a support contract from Microsoft for long term maintenance, they offered a one-time payment of a few thousand dollars instead.

This is unacceptable.

And further:

The lesson from the xz fiasco is that investments in maintenance and sustainability are unsexy and probably won’t get a middle manager their promotion but pay off a thousandfold over many years.

But try selling that to a bean counter

    • @[email protected]
      link
      fedilink
      81 year ago

      Maybe OP didn’t share enough context, because this whole thing looks like a big over-reaction on their part.

      • There’s no accusation of misusing the license, so they’re using it properly
      • there’s a bug tracker, which they used for a bug report
      • OP demanded money when there was no expectation of it

      So what’s going on here? With the information given, Microsoft did what they should have and OP is acting the huge asshole

      • @[email protected]
        link
        fedilink
        English
        11 year ago

        The rest of the tweets definitely don’t make him appear as less of a self-righteous ass.

        This actually made me cringe:

        Your weekly reminder that FFmpeg powers all online video - Youtube, Facebook, Instagram, Disney+, Netflix etc etc, all run FFmpeg underneath

  • agilob
    link
    fedilink
    English
    721 year ago

    Old issue, so why post it now make it sound like MS demands something?

    Opened 11 months ago Last modified 11 months ago

    It’s a regression, so ffmpeg should fix a regression.

    • Cosmic Cleric
      link
      fedilink
      13
      edit-2
      1 year ago

      Old issue, so why post it now make it sound like MS demands something?

      I think it’s because of that recent security issue, and then the subject of corporations tithing into open source code efforts instead of just using it for freeish, that grew around the discussion of that security vulnerability.

      • @[email protected]
        link
        fedilink
        51 year ago

        I don’t think people understood your joke. This thread is all about MS not reading docs or the comment by the guy helping them. Then you ask a date question like you didn’t even see the date on the tweet. Classic! Well done, but subtle.

    • SibboOP
      link
      fedilink
      641 year ago

      The tweet is from today. The ffmpeg team felt like it needed to be said.

      • Lexi Sneptaur
        link
        fedilink
        English
        221 year ago

        Thanks for additional context. I don’t open Twitter links anymore because 3/4 of the time the link doesn’t work after Musk made changes

        • @[email protected]
          link
          fedilink
          English
          11 year ago

          You can try to read through https://archive.today . It’s a site archiving site, it has a couple of tricks to evade such restrictions. Not the most private one… but better than visiting twitter directly.

        • Aatube
          link
          fedilink
          121 year ago

          The Elon Musk of Twitter or the Elon Musk in the FFMPEG ticket?

  • @[email protected]
    link
    fedilink
    451 year ago

    I am confused. I realize this is just a flag change not even a dev problem but PEBKAC, still - in the event of an actual bug, why wouldn’t Microsoft have a dev contribute to the project and fix it instead of just opening a ticket?

    • @[email protected]
      link
      fedilink
      421 year ago

      Filling an issue quickly is good etiquette. Then you can discuss in the ticket the best way to solve/work around.

      • TechNom (nobody)
        link
        fedilink
        English
        41 year ago

        The devs don’t take an issue with the ticket being filed. They’re irritated by one particular reply which sounds like “My million dollar product depends on this bug fix. Please do that for me”. MS isn’t offering a solution. They’re asking for one.

        To be fair MS offers an amount for the fix. Most companies just bully the devs instead. However, I don’t think it’s quite fair (though legal) to offer one time payments for a core library that they use.

      • @[email protected]
        link
        fedilink
        31 year ago

        Wtf is a real elon musk? He is not elon musk of tesla. But is not uncommon for multiple people to have the same name.

        Poor man it must be annoying to have to introduce yourself as “elon musk, no not that elon musk” all the time?

  • @[email protected]
    link
    fedilink
    English
    81 year ago

    If you look up Zied Aouina (issue creator), he’s a principal SWE at MS. Seems within his power to read the codebase and figure out his question if he claims he can’t find the documentation.

  • @[email protected]
    link
    fedilink
    551 year ago

    Good, tell leech corporations and specially Microsoft to fuck right off. Pay for it or do it yourselves.

  • @[email protected]
    link
    fedilink
    English
    48
    edit-2
    1 year ago

    Corporations treat free software as an endless pool of free resources to exploit, pollute, and then shut down.

  • @[email protected]
    link
    fedilink
    1081 year ago

    “A failure to plan on your part does not constitute an emergency on my part.” -Someone hopefully working on ffmpeg.

      • @[email protected]
        link
        fedilink
        English
        141 year ago

        In this case, it’s actually Microsofts fault. There is no bug in ffmpeg, Microsoft just didn’t properly use it

      • @[email protected]
        link
        fedilink
        English
        21 year ago

        the xz vulnerability was done through a superflous dependency to systemd, xz was only the library that was abused to use systemd’s superflous dependency hell. sshd does not use xz, but systemd does depend on it. sshd does not need systemd, but it was attacked through its library dependency.

        we should remove any pointless dependencies that can be found on a system to prevent such attacks in future by reducing dependency based attack vectors to a minimum.

        also we should increase the overall level of privilege separation where systemd is a good bad example, just look at the init binary and its capability zoo.

        The company who hired “the” systemd developer should IMHO start to really fix these issues !

        so please hold your “$they have fixed it” back until the the root cause that made the xz dependency level attack possible in the first place has been really fixed =)

        Of course pointing it out was good, but now the root cause should be fixed, not just a random symptom that happened to be the first visible atrack that used this attack vector introduced by systemd.

    • Oliver Lowe
      link
      fedilink
      221 year ago

      “A failure to plan on your part does not constitute an emergency on my part.”

      Wow now that is a quote I’m going to steal. Wondering if “A failure to understand on your part does not constitute an emergency on my part.” has the same punch or is as relevant… anyway, thanks for sharing!