[MPlayer-dev-eng] [PATCH] Do not read codecs.conf files by default

Diego Biurrun diego at biurrun.de
Sun Jan 21 22:43:35 CET 2007


On Wed, Jan 17, 2007 at 07:13:29PM +0100, Michael Niedermayer wrote:
> 
> On Wed, Jan 17, 2007 at 04:24:56PM +0100, Diego Biurrun wrote:
> > > 
> > > it doesnt matter why the users condecs.conf is not read anymore, what
> > > matters is that the user is not aware of the change which could lead
> > > to security issues
> > 
> > I maintain that this is an esoteric example.  The change would of course
> > be mentioned in the release notes.  If somebody is paranoid enough to fear
> > codecs.conf files, reading release notes can be expected.
> 
> i maintain that i am VERY STRONGLY against ignoring an installed codecs.conf
> and no i wont participate in this disscussion any further as theres no sense
> in it, the suggested change puts users at risk and that fact has not been 
> disputed by any of the arguments

I haven't disputed the fact that risk may exist.  I have just disputed
the fact that this is an example that matters in practice and that this
is a sane way to avoid security issues.

Anyway, I agree that this discussion is not going anywhere.  I'll try to
put a fresh spin to it with some new arguments in a later mail.

Diego



More information about the MPlayer-dev-eng mailing list