This image Can Hack You (The .webp Exploit)

Поделиться
HTML-код
  • Опубликовано: 11 сен 2024

Комментарии • 672

  • @MundanityInsantiy
    @MundanityInsantiy 11 месяцев назад +1213

    Memes have never been more dangerous

    • @HunterHogan
      @HunterHogan 11 месяцев назад +16

      You obviously didn't experience The Hamster Dance.

    • @blackneos940
      @blackneos940 11 месяцев назад +7

      @@HunterHogan Open the gate, take it off it's hinges. Just give PSAs about Goatse Caramels...

    • @sleepyyui
      @sleepyyui 11 месяцев назад +2

      lmao

    • @dennis8196
      @dennis8196 11 месяцев назад +12

      Don't underestimate the power of Rick Ashley.

    • @williambrasky3891
      @williambrasky3891 11 месяцев назад +5

      Listen, unless we can do an OTA update to patch our parents against racist memes they see on Facebook, memes have always been more dangerous. (And if we can, how? Pls tell me, pls. I beg of you).

  • @TheOfficialOriginalChad
    @TheOfficialOriginalChad 11 месяцев назад +1695

    Google makes an image format…and it becomes an exploit for very single piece of software that uses it. Phenomenal.

    • @Bigfoot_With_Internet_Access
      @Bigfoot_With_Internet_Access 11 месяцев назад +128

      Big tech moment

    • @cph101dev
      @cph101dev 11 месяцев назад +59

      Well that’s google for you

    • @c0d1ngclips25
      @c0d1ngclips25 11 месяцев назад +123

      what comes next? registering a .zip tld?

    • @iUUkk
      @iUUkk 11 месяцев назад +77

      It's already been proven that some software has backdoors that are disguised as exploits. I wouldn't be surprised if this was one of those.

    • @c0d1ngclips25
      @c0d1ngclips25 11 месяцев назад +14

      @@iUUkk no doubt, but do you have official sources on that?

  • @Daniel-be6cj
    @Daniel-be6cj 11 месяцев назад +577

    It sucks that this happened but on the other hand I'm glad my longstanding hatred of webp continues to be justified

    • @Mantellla
      @Mantellla 11 месяцев назад +2

      real

    • @kakyoindonut3213
      @kakyoindonut3213 11 месяцев назад +61

      There's actually no valid reason webp exists other than to annoy people who download images from the web

    • @-BigChungus
      @-BigChungus 11 месяцев назад +38

      I have a chrome extension that automatically converts webps to jpgs and pngs, it’s actually really useful

    • @macchiato_1881
      @macchiato_1881 11 месяцев назад

      ​@@-BigChungusanyone with half a brain can go to a website to convert file formats. You're not that unique.

    • @akioasakura3624
      @akioasakura3624 11 месяцев назад +2

      1000% agreed brother

  • @VirtualOA
    @VirtualOA 11 месяцев назад +314

    Webp files are the bane of my existence when I want a PNG file. Glad to know that there was a massive security issue with it.

    • @ButcherTTV
      @ButcherTTV 11 месяцев назад +18

      #endwebp

    • @oliverz321
      @oliverz321 11 месяцев назад +15

      there are some chrome extensions that allow you to convert webp to PNG before you download it

    • @laurens2562
      @laurens2562 11 месяцев назад

      @@oliverz321 you can just rename any .webp file to a .png and it works. might also work with webp to other extensions but i'm not sure

    • @InnerEagle
      @InnerEagle 11 месяцев назад +9

      when I see a webp I automatically get pissed off
      Even if it's since 1997 im on the internet, I never had the necessity of working with webp, so can we let that format die?

    • @phygs
      @phygs 10 месяцев назад

      plenty of those for PNG too

  • @skylarkblue1
    @skylarkblue1 11 месяцев назад +444

    For what it's worth, discord was never vulnerable due to multiple reasons. This was also likely true for multiple of the named programs. People just saw webp and panicked without doing any research other than "is the file type there? then it's vulnerable". Not to mention the ones that where vulnerable mostly all got patched before the chaos started anyway.

    • @internet_userr
      @internet_userr 11 месяцев назад +22

      I'm not reading that

    • @internet_userr
      @internet_userr 11 месяцев назад +138

      Alright I read it

    • @ianthehunter3532
      @ianthehunter3532 11 месяцев назад +15

      @@internet_userr you that read wrong

    • @kevinbissinger
      @kevinbissinger 11 месяцев назад

      ​@@internet_userrname checks out

    • @erikedlund2904
      @erikedlund2904 11 месяцев назад +10

      You and discord should get a room

  • @XxTWMLxX
    @XxTWMLxX 11 месяцев назад +35

    Google makes an image format.... Its used for malware... Google makes a domain "zip" and its used for malware.... Google is on a roll lol

    • @harleyspeedthrust4013
      @harleyspeedthrust4013 11 месяцев назад +1

      they're not very smart over at google - i think it's time that faang becomes faan, or fana, or whatever i don't really care. all i know is that google is full of idiots especially at the higher levels

  • @btarg1
    @btarg1 11 месяцев назад +212

    Damn it's always the NSO Group. I have to say as cool as this is, I hate the NSO with a burning passion, I was hoping it would be some hobbyist security geek who came up with this :(

    • @dennis8196
      @dennis8196 11 месяцев назад +84

      To be fair, it probably was, and they sold it to the NSO who then claimed credit for it, plausible deniability for the finder and more money than the bug bounty that it might have been eligible for.

    • @richardlyman2961
      @richardlyman2961 11 месяцев назад

      @@dennis8196Bug bounties are a fucking joke who would turn in a bug for 10k when you would sell it to Russians for 500

    • @ShadowEclipse777
      @ShadowEclipse777 11 месяцев назад

      ​@@dennis8196 that would make a lot of sense

    • @blisphul8084
      @blisphul8084 11 месяцев назад +3

      At least NSO group is helping expose the vulnerabilities sooner rather than later.

    • @Lewisking50
      @Lewisking50 11 месяцев назад +3

      qrd? what's the problem with NSO group?

  • @Ceereeal
    @Ceereeal 11 месяцев назад +36

    How can Google make a photo file format and not even make it compatible with their OWN APPLICATIONS

  • @lavavex
    @lavavex 11 месяцев назад +56

    I would totally get hacked by that image in the thumbnail tbh

    • @NorthernChimp
      @NorthernChimp 11 месяцев назад +4

      It hacked my brain on see.

  • @yeetyeet7070
    @yeetyeet7070 11 месяцев назад +14

    The lack of a heads-up by Apple and Google (both PR/SM-partners) isn't suspicious at all.

  • @asdfghyter
    @asdfghyter 11 месяцев назад +149

    it’s 2023 and we’re still getting new buffer overflow bugs in major software. you would’ve thought that we had done something systematic about it by now, but no. ”i’m clever enough, so it’s fine for me to write this software in a memory unsafe language and not use any static analysis tools to verify this“ still seems to be a prevalent mindset and people still trust people who does that for some reason

    • @Gramini
      @Gramini 11 месяцев назад +19

      There's a programming language that aims to prevent most memory unsafety bugs; it's somewhat new but it constantly grows in popularity. To my knowledge, the Rust library for decoding webp was not affected :)

    • @asdfghyter
      @asdfghyter 11 месяцев назад +20

      @@Gramini yep, i assumed as much. i was explicitly thinking about rust when writing this comment.
      most programming languages are memory safe, but they also use a garbage collector, making them less well suited for high performance libraries like an image format codec, so rust would clearly be the best fit

    • @nicholasvinen
      @nicholasvinen 11 месяцев назад +11

      The practices required to avoid this kind of bug (and related crashes) in languages like C are not difficult to implement.

    • @shardnugget
      @shardnugget 11 месяцев назад +2

      Bros not a coder

    • @asdfghyter
      @asdfghyter 11 месяцев назад +2

      @@shardnugget who is not a coder?

  • @exosfear512
    @exosfear512 11 месяцев назад +18

    Also there is the objectively superior format jxl, which is royalty free and backwards compatible but Google being Google decided to drop support for it for chrome because it's their anticompetitive practices. Don't be evil.

    • @legendaryra3590
      @legendaryra3590 11 месяцев назад +1

      What about AVIF which has better compression than WebP and is also royalty free? AVIF is also supported on chrome

  • @interstellarsurfer
    @interstellarsurfer 11 месяцев назад +187

    Google giving birth to another exploit? No way. 🤣

    • @DudeSoWin
      @DudeSoWin 11 месяцев назад +35

      Can we stop using new file formats that offer no advantage except a free backdoor?

    • @Proferk
      @Proferk 11 месяцев назад

      Stop blaming google for everything... Software is bound to have vulnerabilities. No matter if it's made by Google or by Joe.
      They didn't "give birth" to it. It was found by someone auditing the code.

    • @ギコ
      @ギコ 11 месяцев назад +5

      ​@@DudeSoWinthe only good thing with webp is that it's better for storage

    • @Entropy67
      @Entropy67 11 месяцев назад +12

      ​@@DudeSoWinfrom what I can tell there is advantages though

    • @vaisakhkm783
      @vaisakhkm783 11 месяцев назад +3

      In reality, google's products are most secure in the world... actually security is a joke in most MNCs
      especially when MNCs are deploying collage freshers to critical production environment for saving money, what else to expect....

  • @joez.2794
    @joez.2794 11 месяцев назад +85

    Images running code. Something nobody asked for, wanted, or needed. Why do I get the impression security is never going to get any better?

    • @Gramini
      @Gramini 11 месяцев назад +25

      It's not like that was a feature or anything. It was just a (critical) bug in a library that decoded the format, that could lead to code smuggling/code execution.

    • @apache937
      @apache937 11 месяцев назад +14

      everything needs to be fully sandboxed, viewing image on discord should NEVER be able to breach outside of discord. the security of our systems are a joke @@Gramini

    • @somexne
      @somexne 11 месяцев назад +5

      It's not like that. It's on the decompression mechanism. It's a total fine image, and the display of it doesn't kill, but some buffer of IoP there has code that scapes the permitetted and then gets executed. I agree with both commenters above me tho, although this would not suffice, as there are jailbreaks for a reason. They would exploit the decoder and then the venv. That's why even VirtualBox and other venvs are not 100% secure. There are malware that search for venvs to break or yeet itself.

    • @battokizu
      @battokizu 11 месяцев назад

      ​@@apache937webapps have been a disaster for the human race. You use discord you are using their spyware. No ones to blame but yourself.

    • @NinjaRunningWild
      @NinjaRunningWild 11 месяцев назад

      @@apache937because corporations keep “kitchen sinking” everything they get their hands on. “Let’s make a new platform, but make it more vulnerable to attack. What could go wrong?”

  • @ImInSpainWithoutTheS
    @ImInSpainWithoutTheS 11 месяцев назад +33

    my reason for hating webp is because I use blender, and when I need to import reference images, they're just not supported at all. PNG is far better in this case

    • @ali32bit42
      @ali32bit42 11 месяцев назад +1

      use image paste. its a life saver

    • @nullvoid3545
      @nullvoid3545 11 месяцев назад +2

      JpegXL ftw!!!

  • @AyySorento
    @AyySorento 11 месяцев назад +43

    Me with thousands of .webp images saved on my computer: *gulp*

    • @MyDarkKnightRisesWhenISeeU
      @MyDarkKnightRisesWhenISeeU 11 месяцев назад +8

      Honest question: Why do you have them saved as .webp? Has this any advantage? I always hate it, when i want to download an image and its .webp ^^

    • @AyySorento
      @AyySorento 11 месяцев назад

      @@MyDarkKnightRisesWhenISeeU Many websites now, such as Reddit, only give that format. So if you try to download an image, that might be your only option. Sites like Twitter are starting as well. Whenever and however possible, I do try to avoid it but it's starting to become a point where it's the only option. Truthfully, the low file size does greatly help storage space on servers/networks, but the quality takes a hit. If I really care, I'll find a way. If it's just something to save, I could care less.

    • @GeometricPidgeon
      @GeometricPidgeon 11 месяцев назад

      ​@@MyDarkKnightRisesWhenISeeUwatch the video.

    • @mgord9518
      @mgord9518 11 месяцев назад +6

      ​@@MyDarkKnightRisesWhenISeeUThey're a lot smaller than the 30 year old formats it intends to replace

    • @lifeai1889
      @lifeai1889 11 месяцев назад +1

      ​@@MyDarkKnightRisesWhenISeeUyeah same because I can't resend it then

  • @Tar9989
    @Tar9989 11 месяцев назад +113

    Yet again google ruins everything.

  • @solidacid1337
    @solidacid1337 11 месяцев назад +109

    It took me 10 minutes to be able to even view this video.
    Thanks RUclips, for FORCING me to view all of those scam and/or gambling ads.
    I really wish there was a comparable alternative. Until there is, I guess I'll just have to go on without watching videos on RUclips.
    I HOPE that RUclipss anti-adblocking ends up killing the platform.
    Ads are EVERYWHERE, in stores, on the streets, at bus stops, on TV, in every single app.
    I'm ALREADY paying for contacts to even be able to see, why the F do I have to pay AGAIN to be able to be able to see stuff without ads?!
    RUclips reported 29.2 BILLION dollars of revenue last year. Forcing ads on us an blocking people with adblockers is just forking GREEDY.
    If RUclips wants me to buy "Premium", at least make it worth the money! $13.99 a month, just to not be constantly be exposed to scam and gambling(same thing) ads is ridiculous!
    At LEAST give me something of value for that money.

    • @Seytonic
      @Seytonic  11 месяцев назад +53

      I am on lbry :)

    • @solidacid1337
      @solidacid1337 11 месяцев назад +11

      @@Seytonic hadn’t heard about it until now! Great to know I can view your awesome content somewhere else!
      I love your videos man!
      Keep doing what you do, you’re awesome!

    • @its_herocast276
      @its_herocast276 11 месяцев назад +7

      Can't believe you don't know Rumble

    • @NorthernChimp
      @NorthernChimp 11 месяцев назад +6

      Forcing? You can skip the ads after 5 seconds. And if you wait 30 seconds before skipping, the RUclipsr will get their money even without you watching the whole ad.

    • @impyrobot
      @impyrobot 11 месяцев назад

      Unlock origin on browser and revanced on android both completely free and open source I've not seen a RUclips ad in years.

  • @anuamba
    @anuamba 11 месяцев назад +2

    Beluga being the center of the problem 😂😂😂😂

  • @DamianAI9
    @DamianAI9 11 месяцев назад +11

    I love that you used the Cat as an Example XD

  • @SlinkyD
    @SlinkyD 11 месяцев назад +6

    3:50
    Rust on a buffer overflow vulnerability list.
    When safe ain't safe, just be careful. 🤣🤣🙃

    • @Gramini
      @Gramini 11 месяцев назад +1

      Was curious about that as well. Given that the text about it mentions "the vulnerable library" I guess it's just Rust bindings to the C-library libwebp. There's also a pure Rust library for webp.

    • @SlinkyD
      @SlinkyD 11 месяцев назад

      @@Gramini Apple & Google was mum about it. They cutting edge corps. that like to hide their faults. Not a stretch to think it was the actual Rust lib since their logo was up with the others. They'll sue devs for wrong colors, they'll sue that site for libel & whatever else if it wasn't true.
      Oxidized brains won't shut up about Rust until they see something like that. And they squirm inside their soul when they see a oxidized program segfault.

    • @corinnarust
      @corinnarust 11 месяцев назад +2

      As a Rust developer, I'm kind of confused, it should not be possible unless using unsafe Rust or C bindings (which are also unsafe)

    • @SlinkyD
      @SlinkyD 11 месяцев назад +1

      I ain't a dev just to be clear. I just know from what I've experienced, it "shouldn't" be on the list like it is. That list seemed specific to me. Also, I acknowledge there are missing details & ambiguity to the problem being in "safe" Rust specifically.
      I saw it, my brain giggled, then I wrote 🤷🏿‍♂️

  • @Bigfoot_With_Internet_Access
    @Bigfoot_With_Internet_Access 11 месяцев назад +11

    If you're on windows you can open webp images in paint and then save it as a normal image btw

    • @Rudxain
      @Rudxain 11 месяцев назад

      Doesn't that trigger the exploit too? (I mean loading and parsing the WEBP into MSP memory)

    • @akurasubject9617
      @akurasubject9617 11 месяцев назад

      ​@@Rudxaini don't think so because only thing paint can do is view and edit images and nothing else.

    • @hlw2499
      @hlw2499 11 месяцев назад

      @@akurasubject9617 The problem is exactly that. The exploit allowed the hacker to insert malicious code into the software reading the image, and making it do things it wasn't supposed to do, like installing a malware.

  • @m-man
    @m-man 11 месяцев назад +5

    hey i emailed seytonic about this webp exploit Fri, Sep 29! no way!

  • @beastfr0meast93
    @beastfr0meast93 11 месяцев назад +59

    that exploit has been around for a looooong time 😂

    • @distortions
      @distortions 11 месяцев назад +7

      Well yeah..

    • @featheroml
      @featheroml 11 месяцев назад +5

      Yes? Do you not know what a zero day is?

    • @beastfr0meast93
      @beastfr0meast93 11 месяцев назад +1

      @@featheroml dude - yes. Zero days, that the bug is known(public).
      This has been known public

    • @Gottrolledbythebest485
      @Gottrolledbythebest485 11 месяцев назад

      Like 10-9 months

    • @Gottrolledbythebest485
      @Gottrolledbythebest485 11 месяцев назад

      @@beastfr0meast93no zero day means the company that makes the software ex Google is oblivious to the fact that the bug exists.

  • @Saphintosh
    @Saphintosh 11 месяцев назад +81

    I swear to god, the only utility of the webp format is to give work to do to people developping websites to convert them

    • @anon_y_mousse
      @anon_y_mousse 11 месяцев назад +25

      That's one of the reasons I hate them so vehemently. If you're not converting a lossless or much higher quality image to webp, then you're losing image quality to convert instead of just using what you already have. Far too many people don't seem to understand this and all the webp images I've found had a lower quality image because of it.

    • @shapelessed
      @shapelessed 11 месяцев назад

      @@anon_y_mousse And yet webp is getting more traction simply because being able to decrease the average size of an image by 10-15% over other formats is potentially millions worth of savings. The most expensive thing for a website or a service is literally bandwidth.

    • @Gramini
      @Gramini 11 месяцев назад +8

      Apart from reducing file size by around 60%, saving massively on storage and transmission size/cost/time.

    • @hiperion_1416
      @hiperion_1416 11 месяцев назад +11

      and to make the web loading time on cellular data 50% faster, thats the main reason it was developed

    • @anon_y_mousse
      @anon_y_mousse 11 месяцев назад +5

      @@Gramini And to point it out again, if it's not an original image that will lose image quality.

  • @X1ZR
    @X1ZR 11 месяцев назад +6

    The internet can be scary place...

    • @shapelessed
      @shapelessed 11 месяцев назад +2

      As a web dev I can with 100% certainty tell you - Yes, it god damn is. Just deep dive into some open-source analytics and tracking software, then realise closed-source big-tech solutions are even worse.

  • @CyanicCore
    @CyanicCore 10 месяцев назад +1

    Well this is (once again) terrifying.

  • @c-LAW
    @c-LAW 11 месяцев назад +16

    2:13 " Pegasus can track your location, read your messages and call logs, and activate your microphone and camera..." Isn't this what apple and google does anyway? and ever app installed on these OS's?

    • @H0mework
      @H0mework 11 месяцев назад +11

      So can your mom if you don't get the point.

    • @retro-porygon
      @retro-porygon 11 месяцев назад +9

      Yes. Difference is, Google and Apple hands your data to advertisers. Pegasus hands your data to authoritarian governments.
      One is far more worrisome than the other if you are a journalist, researcher, activist or express any political dissent.

    • @turolretar
      @turolretar 11 месяцев назад

      Exactly, like I’ve got nothing to hide bozos, so can spy on me with your little camera like a creepy ass dude if you want

    • @Ulysees31
      @Ulysees31 11 месяцев назад

      ​@retro-porygon I agree. Advertisers can be relentless.

    • @fluf201playz
      @fluf201playz 11 месяцев назад +6

      @@retro-porygon they do give it to governments if they request it stop talking your bs

  • @Lupinicus1664
    @Lupinicus1664 11 месяцев назад +7

    Another excellent video. Nice work 👍

  • @Jondo-ik7nv
    @Jondo-ik7nv 11 месяцев назад

    Watched your ad purely because you put it at the end. Thank you for that.

  • @TobiCooki
    @TobiCooki 11 месяцев назад +10

    ah the good times of webp's crashing your discord app

    • @ryshellso526
      @ryshellso526 11 месяцев назад +2

      Discord is cancer anyway...

  • @xDMG15x
    @xDMG15x 11 месяцев назад +18

    Wait… you had .webp > png but the thing you mentioned was that they support transparency, like png. Why is it better than png?
    Also, every image format has better compression than jpeg

    • @alfie67
      @alfie67 11 месяцев назад +21

      webP has better compression + smaller file size with same image quality

    • @8BitShadow
      @8BitShadow 11 месяцев назад +8

      because it also supports animation. Which APNG already does, it's just not very well implemented.

    • @sabersz
      @sabersz 11 месяцев назад

      Webp is still dogshit. Every time I download an image and it turns out to be a webp i want to throw my computer through Google HQ's doors

    • @xDMG15x
      @xDMG15x 11 месяцев назад +19

      @@alfie67 png has lossless compression. The animation answer makes sense though

    • @gljames24
      @gljames24 11 месяцев назад +6

      ​​@@alfie67So does JXL while being better in every other category as well.

  • @poncowow9847
    @poncowow9847 11 месяцев назад +4

    That's cruel how could they hack people with beluga cat image? Did they stop using those xxxx site?

  • @xDMG15x
    @xDMG15x 11 месяцев назад +9

    So is it zero click? Or would the user be required to actually add a random pass to their wallet sent from a random person?

    • @Gramini
      @Gramini 11 месяцев назад +1

      IIRC the prepared image just needs to be decoded. So it depends on the targeted app if it requires a click/action for the image to show or not.

    • @xDMG15x
      @xDMG15x 11 месяцев назад

      @@Gramini copy that, thank you. By the looks of the screenshot in the video the cat pic didnt appear in the imessage preview of the pass

  • @MostlyMobiles
    @MostlyMobiles 11 месяцев назад +30

    Beluga is trying to hack you 😂

    • @LeftyPencil
      @LeftyPencil 11 месяцев назад +2

      I had to double take at the channel lol

    • @user-tn3gt8fj7c
      @user-tn3gt8fj7c 11 месяцев назад +4

      Hecker took the channel 💀

    • @richie0099
      @richie0099 11 месяцев назад +1

      I’m sure he was just trying to send his picture directly to a girls iPhone and it turned into a malware for all phones

  • @weshuiz1325
    @weshuiz1325 11 месяцев назад +8

    Discord already patched it btw

  • @myhandleiswhat
    @myhandleiswhat 11 месяцев назад +4

    Outside of a web browser I still can't view animated webp files. Conversion sites cause the file to bloat up as well. So it's still a basically useless format.

    • @128Gigabytes
      @128Gigabytes 11 месяцев назад +1

      they arent bloating up, webp had them compressed

    • @myhandleiswhat
      @myhandleiswhat 11 месяцев назад

      @@128Gigabytes if I didn't have to convert them to view/send them animated they wouldn't bloat up.

  • @DarkLink606
    @DarkLink606 11 месяцев назад +152

    Never waste the chance of turning a crisis into an opportunity: time for devs to deprecate the most annoying file format for good in all platforms. It's a security threat.
    If the malware turns out not to be exclusive to webp, at least we get rid of webp, that is something.

    • @sungiant2000
      @sungiant2000 11 месяцев назад +23

      What's wrong with webp? Aside from the vulnerability of course (since it is patched on most platforms now). Seems a little silly to move back to more inefficient formats. It's not like webp is a closed standard.

    • @Meck5531
      @Meck5531 11 месяцев назад +4

      The future is AVIF a AV1 product

    • @Stahl_und_Eisen
      @Stahl_und_Eisen 11 месяцев назад +14

      Bro hating on webp kinda cringe

    • @Gramini
      @Gramini 11 месяцев назад +14

      Yes, please get rid of gif, it's so annoying to deal with. But I wouldn't call it a security thread.
      If you watched the video you'd know that the problem was not webp, but libwebp, a somewhat common library to decode such images. The format itself is perfectly fine.

    • @mgord9518
      @mgord9518 11 месяцев назад

      ​@@Meck5531Avif will probably be overshadowed by jxl. Jxl is faster at en/decoding, retains better quality, supports progressive loading and gets better compression ratios
      Jxl > avif > webp > png, jpeg, gif

  • @Sparkette
    @Sparkette 11 месяцев назад +4

    Google Voice doesn't support them either. I use it for texting from my computer and it's annoying having to convert webp images to png.

  • @HikaruAkitsuki
    @HikaruAkitsuki 11 месяцев назад +10

    For both WordPress, Nodejs and Ruby on Rails developers, this is kinda concerning. But if we will not allowed webp format on user post system, maybe it will gonna fine for a while.

  • @JEffinger
    @JEffinger 11 месяцев назад +71

    No accident that they didn't report it. My guess is they knew state sponsored groups were using the exploit

    • @xDMG15x
      @xDMG15x 11 месяцев назад +10

      Exactly. As pro privacy as apple touts, i bet they know about us government spying methods that they could thwart if they wanted

    • @Coecoo
      @Coecoo 11 месяцев назад +9

      Critical security vulnerabilities are always intentionally kept under wraps for months or even years due to government agencies using them. The US in particular does this a LOT.

    • @Gramini
      @Gramini 11 месяцев назад

      Who do you mean with "they"?
      The NSO Group? Of course they wouldn't report it, they are/were actively exploiting it…
      Google? They didn't knew and fixed it once reported…

  • @papabaddad
    @papabaddad 11 месяцев назад +1

    the other thing about being black hat and selling a zero day to bad actors is you have to trust they'll actually pay you 20mil

  • @DexieTheSheep
    @DexieTheSheep 10 месяцев назад +2

    It seems like every week NSO Group is being said to have gone dark and then comes back with no explanation whatsoever... I don't get it... are they shut down or not? :/

  • @jonathantheyorkie
    @jonathantheyorkie 10 месяцев назад +1

    Here is how great the education system is (Sarcasm intended). I get in trouble at school for trying to save my grandmother from this attack. The school I go to, the majority of people live in very nice and expensive homes (Except for me and a few other students) so they LITERALLY expected me to allow my grandmother get hacked, and then I get in trouble with them if I don't do what they want so I can waste 1500 dollars on another computer that is completely unnecessary. Just awesome.(Sarcasm intended again)

  • @mantacid1221
    @mantacid1221 10 месяцев назад +2

    Has google ever developed something that didn’t make hacking easier? First there’s the new TLDs (.zip for example) and now this?

  • @sparquisdesade
    @sparquisdesade 11 месяцев назад +3

    THANKS GOOGLE! Man, I can't help but feel google an apple should be fined by the FCC or something for this

  • @boris_raduloff
    @boris_raduloff 11 месяцев назад +2

    I found out Google domains has died from that b-roll footage 💀

  • @MalouMendoza9600
    @MalouMendoza9600 11 месяцев назад +1

    Always on point! 💪🏼

  • @haloball12
    @haloball12 11 месяцев назад +3

    Getting sponsored by akami is crazy 😭

  • @alreadydead.
    @alreadydead. 11 месяцев назад +2

    The hacked person is called Ahmed Tantawi.. and he was about to be a president

    • @40arpent
      @40arpent Месяц назад

      According to citizenlab, Egypt was the client and just put him in jail...

    • @alreadydead.
      @alreadydead. 28 дней назад

      @@40arpent cause the current president doesn't allow anyone to take his place... lol

  • @WizDumbDumb
    @WizDumbDumb 11 месяцев назад +31

    IOS is not secure At one time it was very secure but popularity brings malice as you mentioned. I have seen the most recent ios exploit in action twice in the past six months. Apple claims to have patched this in the most recent update but I still have concerns as this is the same exploit they claimed to have patched previously

  • @imnotbeluga007
    @imnotbeluga007 11 месяцев назад +2

    In short, hecker hecked Beluga.

  • @Get_yotted
    @Get_yotted 11 месяцев назад +2

    Funny, Google always creating formats that carry malware

  • @gonzotrash
    @gonzotrash 11 месяцев назад

    This is not the first time this has happened and I'm not surprised it happened again

  • @ShakilShahadat
    @ShakilShahadat 11 месяцев назад +2

    That's Beluga. Damn it hecker!

    • @user-tn3gt8fj7c
      @user-tn3gt8fj7c 11 месяцев назад +1

      blud hecked the channel no way 💀

  • @Simqinq
    @Simqinq 10 месяцев назад +1

    Yes, I have ae 2020 still and webp got me mad bro 😭

  • @Heran983
    @Heran983 11 месяцев назад +4

    No way memes are becoming more dangerous.

  • @lainwired3946
    @lainwired3946 11 месяцев назад +1

    When you say tor is vunerable i assune you mean the browser bundle? So does that mesn firefox too, or domething the tor foundation swapped out?

  • @NinjaRunningWild
    @NinjaRunningWild 11 месяцев назад +37

    Typical Google. Reinvents what doesn’t need reinvention & makes it vulnerable at the same time. Great job!

    • @Bomkz
      @Bomkz 11 месяцев назад +8

      okay but tbh both jpgs and gifs are too space inefficient with compression and don't support transparency like pngs do

    • @TheTubejunky
      @TheTubejunky 11 месяцев назад +4

      It was probably created this way intentionally by google. Think about their monopoly on data.

    • @rashidisw
      @rashidisw 11 месяцев назад

      i just use ffmpeg to re-compress .jpg(s) into more efficient space usages,
      I just use the [-preset veryslow] parameter. So far the quality drop of the recompressed images are quite hard to detect.

    • @boggless2771
      @boggless2771 11 месяцев назад +2

      ​@@TheTubejunkyas if its the format thats the problem. Its not, its libwebp thats the problem. And that when Apple/Google fixed it, didnt fix it upstream.

  • @somekindofdude1130
    @somekindofdude1130 11 месяцев назад +1

    They are compatible with ms paint and they were since the start.

  • @arrux4822
    @arrux4822 11 месяцев назад +4

    Surely they are using these exploits on "bad guys", right guys?

    • @bubbleboy821
      @bubbleboy821 11 месяцев назад +7

      Absolutely. Only the "bad" guys. And by bad, they mean everyone and anyone they want.

  • @Abcdefg-fh3fb
    @Abcdefg-fh3fb 11 месяцев назад +1

    i hate webp files so much its unreal

  • @dyscotopia
    @dyscotopia 11 месяцев назад +1

    I think companies like dot webp images precisely because they are hard to work with... It keeps images from being reused without consent.
    Of course nothing loading up in paint and saving as a jpeg can't fix

    • @carlosnava1471
      @carlosnava1471 11 месяцев назад +2

      No, it's because it makes for smaller file sizes and therefore is cheaper to host and deliver, stop spreading misinformation please

    • @dyscotopia
      @dyscotopia 11 месяцев назад

      @@carlosnava1471 it doesn't have to be a binary thing. I have known many web developers and have built pages in Word press and Drupal, and while I personally haven't been asked, have heard of clients on more than one occasion with concerns over their images being reappropriated. Webp makes that slightly less convenient and has those other benefits to an extent also

  • @stephenmandelbaum2027
    @stephenmandelbaum2027 11 месяцев назад +1

    Beluga out there causing trouble...

  • @aIiceqt
    @aIiceqt 11 месяцев назад +1

    i hope this means that the cat image will be seen as the personification of malice because i hate it

  • @ashrist621
    @ashrist621 11 месяцев назад

    i saw a guy named Text to Speech make a video about this and how it related to discord. haven't watched this vid but wasn't this patched roughly a week ago, or has it appeared as something different?

  • @land3021
    @land3021 10 месяцев назад

    4:30 Man, they must get paid well!!!

  • @loganroman5658
    @loganroman5658 10 месяцев назад +2

    Who in the google building made webp?

  • @aysnov
    @aysnov 10 месяцев назад

    I'm not sure what's worse, that people still write buffer overflow bugs in 2023, or that they can still result in arbitrary code execution on a modern system.

  • @AshnSilvercorp
    @AshnSilvercorp 11 месяцев назад +7

    Europe: _See, closed source security is going great?

    • @HyBlock
      @HyBlock 11 месяцев назад +2

      webp isn't closed source though?

    • @AshnSilvercorp
      @AshnSilvercorp 11 месяцев назад

      @@HyBlock sometimes Google's form of open-source feels like a malicious compliance.
      Even tho it's open-source, the methodology of fixing and not reporting these issues is the same way if a closed-source OS does the same and then never reports the issue to anyone else.

  • @pablolarreategui9489
    @pablolarreategui9489 11 месяцев назад +2

    I don’t find the danger in that photo

  • @yeetyeet7070
    @yeetyeet7070 11 месяцев назад +1

    Besides google being evil and there being a non-zero chance this has was malicious from the start,
    I fucking hate WebP and WebM. What's wrong with PNG? it's soo much better.

  • @mintrananas
    @mintrananas 11 месяцев назад

    wow beluga called hecker

  • @toast99bubbles
    @toast99bubbles 11 месяцев назад

    Often when I download an image from Facebook Messenger, it downloads as a webp, then when I try to send it to someone, Messenger says it's not a compatible file format and also seems to think it's a gif too.

  • @CarterHax
    @CarterHax 11 месяцев назад +3

    I bet NSO was PISSED when he got the exploit patched. I wouldn't be surprised if they put a hit out on him, Mostly because their shitty exploit got patched.

    • @fusseldieb
      @fusseldieb 11 месяцев назад +2

      I bet they have a plan B, C, D and E.

    • @40arpent
      @40arpent Месяц назад

      Well according to citizenlab Egypt was the client and a politician was the target. The government put him in jail...

  • @AaronNazzy
    @AaronNazzy 11 месяцев назад +1

    Malware makes a return!

  • @BASSNETIC-MUSIC
    @BASSNETIC-MUSIC 11 месяцев назад +2

    Well, I'd rather get hacked by a polite cat than a rude one...

  • @mongolianbeef847
    @mongolianbeef847 10 месяцев назад +2

    just change the extension to .png

  • @AshtonDavies_
    @AshtonDavies_ 11 месяцев назад

    Google just can't produce something that doesn't have vulnerable flaws. 😑

  • @ZeronimeYT
    @ZeronimeYT 10 месяцев назад

    You need to convert webp to jpg or png first then you can insert it into video editing software like Vegas.
    So, yeah. I hate webp.

  • @boredreindeer5602
    @boredreindeer5602 11 месяцев назад

    Are there any video formates that do it?

  • @MuntyScruntFundle
    @MuntyScruntFundle 11 месяцев назад

    Would be nice to know what dates this was a problem. And what to remove if somehow it through....

  • @Keksgesicht
    @Keksgesicht 11 месяцев назад

    Is there a CVE number or something else which actually explains how this exploid works?

  • @huddunlap3999
    @huddunlap3999 11 месяцев назад +1

    This is why I subscribe.

  • @mbk5430
    @mbk5430 11 месяцев назад +1

    Can we rename the file extension to .welp ?

  • @darukutsu
    @darukutsu 11 месяцев назад +3

    JXL for the win.

  • @heythere7130
    @heythere7130 11 месяцев назад +1

    beluga is getting more powerful

  • @marko19914
    @marko19914 11 месяцев назад +1

    When was this vulnerabilty patched?

    • @KimvanConrad
      @KimvanConrad 11 месяцев назад

      like a month or two ago

  • @PenguinPolar
    @PenguinPolar 11 месяцев назад

    There's a lot of misinformation abut this, its not webp, its the video type, so some apps that people think are were vulnerable actuality are not.

  • @Aresydatch
    @Aresydatch 10 месяцев назад

    Jpeg XR for the win

  • @twinfastasytowers
    @twinfastasytowers 10 месяцев назад

    This is why I just screenshot webp images.

  • @TheEnderFlash
    @TheEnderFlash 11 месяцев назад +3

    how is nso legal and israel is not sanctioned in the west for hosting these guys

  • @nobbyfirefly57
    @nobbyfirefly57 11 месяцев назад

    Finally, RUclips sends it to me on time

  • @takeraparterer
    @takeraparterer 11 месяцев назад +1

    btw discord uses a safe version of libwebp

  • @nmxsanchez
    @nmxsanchez 11 месяцев назад +1

    That cat is NOT polite! He hacked my father

  • @TtEL
    @TtEL 11 месяцев назад

    I am concerned because I was just sent an image from an unknown number while watching

  • @wayronhelloneighborcontent9810
    @wayronhelloneighborcontent9810 11 месяцев назад

    As someone who's never stood for .webp files, those girls in high school saying "I just had a gut feeling" don't seem so crazy now

  • @reed6514
    @reed6514 11 месяцев назад +1

    Didnt Akamai buy out Linode?

  • @Standenanian
    @Standenanian 11 месяцев назад

    Didn't know NSO Group before this video but I hate them now

  • @donedane2269
    @donedane2269 11 месяцев назад +5

    you didnt need chrome to open webp you just needed an image suite like nomacs