Navigate Select ESC Close

Is Google expecting too much of opensource

2025-11-09 Science & Technology
63.9k
2.5k
332
ThePrimeTime
ThePrimeTime
1.1m subscribers

LLM-Identified Vulnerabilities vs. Open Source Maintainer Burden

Discover the ethical and logistical conflicts arising when massive corporations use AI to report obscure security bugs to under-resourced volunteer software projects.

Short Summary

  • Google reported a low-impact vulnerability in FFmpeg via an LLM system ('Big Sleep'), triggering pushback over disclosure timelines and resource imbalance.
  • Maintainers argue that entities powerful enough to find bugs should also shoulder the burden of writing and submitting the patch, not just dropping a time-bound report.
  • The conversation highlights the dilemma: knowing about threats versus the practical inability of small teams to triage an ever-increasing volume of AI-generated reports.
  • This episode details the trade-offs between security discovery and the sustainability of open-source maintenance workflows under AI pressure.

This discussion centers on a recent controversy involving FFmpeg, an open-source media framework, and Google's AI-driven security tools. Guests Teimu Casey and Trash weigh in regarding whether automated bug reporting from resource-rich entities imposes an unfair mandate on volunteer maintainers, especially concerning disclosure deadlines and the exploitability of the reported issues.

Unlock all features

FREE: Get instant access to 10 AI summaries, chats, or transcripts per day.

Description

https://twitch.tv/ThePrimeagen - I Stream on Twitch https://twitter.com/terminaldotshop - Want to order coffee over SSH? ssh terminal.shop Become Backend Dev: https://boot.dev/prime (plus i make courses for them) This is also the best way to support me is to support yourself becoming a better backend engineer. Great News? Want me to research and create video????: https://www.reddit.com/r/ThePrimeagen Kinesis Advantage 360: https://bit.ly/Prime-Kinesis 00:00:00 - Intro 00:01:23 - the issue 00:04:01 - the takes 00:09:16 - the bug 00:10:22 - AI Disclosure 00:11:42 - Prime weighs in 00:13:28 - Disclosure credit 00:14:40 - Big Sleep 00:15:24 - AI Bugs Finders vs Static Analysis 00:17:40 - Do they owe them anything at all 00:19:40 - Is this optional or worthwhile 00:23:33 - Bugs in general 00:26:08 - Triage timespend 00:27:01 - Outro

Top Comments (10)

@AshbeelPaul 2025-11-09

"Talk is cheap. Submit patches."

1.8k 20 replies
@ZeroUm_ 2025-11-09

1. If you make a lot of money with someone else's software, fund them. 2. Automated bug findings should be triaged by a human expert before sending the report to the authors. 3. Patches are welcome, but they should not be required. The reporter does not know the software as well as the author. Even with triage, it could be unexploitable.

1.1k 24 replies
@PhrozenN 2025-11-09

I kind of agree with the ffmpeg people. If you find a bug/security issue, and you have the expertise to find it, you probably have the expertise to at least give an example on how to fix it as well! When you're a multi billion $ company that actually rely on the project, you damn well better help them out

670 24 replies
@israelribeiro3373 2025-11-09

In my opinion, if your company depends in any kind of open source free software like ffmpeg for the stuff it does (Youtube probably uses it, for example), if you have ANY demands from the tool, it's your job to allocate resources to make it happen. Be it funding or putting employees to work on the tool to implement any patches or features needed. You can't build anything on top of effectively third-party people's pet projects and then demand free work, no matter the perceived importance of said project.

536 27 replies
@bencamp1051 2025-11-09

A teenage hacker in the 90s put more effort into telling the exploitable how to patch their vulnerabilities.

517 1 replies
@gsgregory2022 2025-11-09

I think the issue here is the power dynamic. Their new income is up at 100 billion. They literally have enough money to pay a years salary to the top 10 ffmpeg contributors and it wouldn't even be noticed in their financial disclosures, it would barely be a rounding error. The fact that what they decided to do the the opensource community is to just throw AI security reports at them and try and bully them into fixing it in 90 days instead of saying "hey we use this major thing, lets give them cash to fix this, or fix it ourselves" shows how little they value the projects they are built on.

443 16 replies
@michaelguarino417 2025-11-10

The reason Google is doing it is because they're clearly staking their cloud platform differentiation on security out of the box. it's a big reason they bought wiz as well. If they own the cybersecurity AI landscape, that strengthens their position further, it's effectively marketing for that story.

143 3 replies
@WearyTimeTraveler 2025-11-09

It’s in manufacturers best interest to ensure healthy supply chains, given how much Google has profited from ffmpeg, they should be paying them and contributing to code

64 5 replies
@Triavanicus 2025-11-09

Hey Ed, welcome to the standup. So what are your blockers for the month, and how are you going to resolve them with AI?

57
@etgaming6063 2025-11-09

I know a bug bounty hunter that pressured Microsoft to fix and pay within 90 days since these multi-billion dollar companies will not pay until they patch it. Bug hunters get paid like 10 to 30 thousand for vulnerabilities on these giant companies that would cost them millions upon millions. This is totally different from an LLM telling OSS they have 90 days to fix bugs or they tell everyone which would exploit not only the company, but all the innocent that use that software.

41

Unlock the Data Inside
Turn Videos into Knowledge

  • Get FREE 10/day: transcripts, summaries, chats
  • Chat with videos, export text & PDF
  • $1 free API credit for RAG, chatbots & research

Free forever plan • All features unlocked

App screenshot