Suggestion for security feature

Markus <[email protected]>
Newsgroups gmane.comp.video.videolan.vlc.general
Message-ID <[email protected]>
Hello VLC developers!

I have a suggestion for a security feature:

When you open a .mpg file with vlc, it doesn't mean, that there is
actually mpeg inside it. File extensions are useless. But users normally
open mpg-files directly with vlc without checking the real content. It
doesn't matter if the file contains mpg, mp4, flv, or whatever.

But what if the real content is a playlist file? (pls-file)

An attacker is able to create a pls file which links to a
"streaming"-server which collects ip adresses. The attacker can know
rename his pls file to wikileaks.mpg, extend the file to a normal file
size and drop the file somewhere... -> massive privacy problem!

In my oppinion, vlc should really ask the user for permission to connect
to the internet:
Maybe in first-start dialog: "allow everytime", "ask everytime"

Thank you for your great player!

______________________________________________________
vlc mailing list
To unsubscribe or modify your subscription options:
http://mailman.videolan.org/listinfo/vlc
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.