Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Image with Movie in 10.4.7



On 7/25/06 at 7:05 PM, =:-)f <email@hidden> wrote:

> I want this feature back, too!
> 
> I am over 18 Years old, I usually decide for my own, which risk I am
> going to accept.

OK, before people start marching on Cupertino singing "We Shall
Overcome" (recursively), please read again what Pierre-Olivier said when
this first came up:

On 7/13/06 at 11:36 AM, Pierre-Olivier Latour <email@hidden> wrote:

> We had to disable this as we had no other way to prevent the
> composition to self-reference itself through Movie patch and crash.

and:

On 7/13/06 at 12:27 PM, Pierre-Olivier Latour <email@hidden> wrote:

> the issue here is with the QT integration, where the file can end up
> loading itself infinitely. Obviously, that crashes, and since this
> kind of crashes are considered potential security issues, we have to
> prevent them.

I don't think Pierre-Olivier, who has forgotten more about QTZ than any
of us ever knew, would lightly say there was "no other way" to disable
recursive crashing from compositions loading movies that load the same
composition.

That means that until either the QuickTime media handler or Quartz
Composer itself are redesigned to catch this stuff, then leaving it
enabled means Apple has to face articles with phrases like, "The latest
security issue allows maliciously-crafted QuickTime movies to crash the
applications that play them, potentially losing your data.  The company,
when asked for comment, could say only that developers were over 18 and
could make their own decisions about what risks to accept."

If you haven't already gone to <http://bugreporter.apple.com/> and filed
an enhancement request for this functionality to be restored, then do so
now -- that's what makes the official list of things to do, not things
on any mailing list.

I think Pierre-Olivier and the other Apple folk on the list get your
passion for a way to play compositions within other compositions, but
that's not going to outweigh security issues, no matter how many risks
*you* want to take.

--
Matt Deatherage                              <email@hidden>
GCSF, Incorporated                      <http://www.macjournals.com>

"I want everybody to tell me the truth, even if it costs them their jobs."
  -- Samuel Goldwyn


 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Quartzcomposer-dev mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
http://lists.apple.com/mailman/options/quartzcomposer-dev/email@hidden

This email sent to email@hidden

References: 
 >Image with Movie in 10.4.7 (From: "=:-)f" <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.