431
jprule (lemmy.blahaj.zone)
you are viewing a single comment's thread
view the rest of the comments
[-] aBundleOfFerrets@sh.itjust.works 64 points 1 week ago

Google has apparently been mogged into rewriting the jpegxl reference library in rust to make it more “secure” so that it can be used in browsers (apparently the reason they refuse to put it in chrome, and the reason firefox devs cite) (never mind the fact that this apparently didn’t stop Apple) we can only hope they actually finish the damn thing…

[-] socsa@piefed.social 10 points 6 days ago

To be fair, this isn't just happening out of the blue. Apple had a bunch of zero day, no click vulnerabilities from its media decoders, which were some of the original Pegasus vectors. Complex media rendering is a very legitimate security concern, particularly in the browser space on general purpose machines. IDK if doing a full RUST implementation is the right answer, but the idea of not wanting to add a massive potential attack vector for redundant functionality is not completely insane.

this post was submitted on 22 Sep 2025
431 points (98.2% liked)

196

18411 readers
343 users here now

Be sure to follow the rule before you head out.


Rule: You must post before you leave.



Other rules

Behavior rules:

Posting rules:

NSFW: NSFW content is permitted but it must be tagged and have content warnings. Anything that doesn't adhere to this will be removed. Content warnings should be added like: [penis], [explicit description of sex]. Non-sexualized breasts of any gender are not considered inappropriate and therefore do not need to be blurred/tagged.

If you have any questions, feel free to contact us on our matrix channel or email.

Other 196's:

founded 2 years ago
MODERATORS