Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

VLC 2.1.5 compromised https://wikileaks.org/ciav7p1/cms/page_15729066.html

edit: please see response below from remlov

edit: this post was premature, see below posts



Please don't spread disinformation.

"...the asset will have 'downloaded' the portable version of VLC player (2.1.5)..."

This does not sound like a copy of the public version and that it's "compromised". You could check for yourself if you like: https://github.com/videolan/vlc :)


It's a version of VLC that, in addition to the things it normally does, collects information. The operator, who knowingly runs the software, can then collect the information and turn it over to someone else.


> The asset has the ability to plug in a personal thumbdrive to the network.

Sounds like it just patches a local copy of VLC by running an installer. I don't know if I would consider that compromised.


2.2.0 was released in early 2015.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: