6 ms·
> Have you seen JPEG XL source code? I like the format, but the reference implementation in C++ looked pretty bad at least 2 years ago. I hope they rewrote it,
by chimeracoder 10mo ago
> Have you seen JPEG XL source code? I like the format, but the reference implementation in C++ looked pretty bad at least 2 years ago. I hope they rewrote it, because it surely looked like a security issue waiting to happen.
At this point, in 2025, any substantial (non-degenerative) image processing written in C++ is a security issue waiting to happen. That's not specific to JPEG XL.
- SoKamil 10mo ago> any substantial (non-degenerative) Why this quality poses security issues?
- izacus 10mo agoAnd yet whole of HN is VERY VERY angry because Google won't ship that pile of C++ into most popular software (and app framework) in the world.
- usrnm 10mo agoThe most popular software in question is also a giant pile of C++, btw.
- izacus 10mo agoWhat are you saying here?
- ncruces 10mo agoAre you familiar with the rule of two? https://chromium.googlesource.com/chromium/src/+/main/docs/security/rule-of-2.md https://chromium.googlesource.com/chromium/src/+/main/docs/s... No new code goes in that violates the rule, and ideally no code at all goes in that is both unsafe and parses untrusted data (regardless of sandboxing) and old code doing both gets replaced. A giant pile of C++ can be used for rendering, not parsing untrusted data. A giant pile of C++ can sit behind a validator: a memory-safe JSON validator can vet a stream, before an C++ library deserializes it. Etc.
- ux266478 10mo agoWho is saying Google should ship the reference implementation? It's a standard, and Google has the labor to write their own implementation.
- izacus 10mo agoThat sounds like an even more request for someone to do for free, doesn't it?
- ipdashc 10mo agoIt's Google, it's one of the biggest tech companies in the world making boatloads of money, in part off their browser. They're currently best known as one of the companies trying to create AI God. They really can't write an... image format parser?
- izacus 10mo agoCool, but why does that mean they need to write a codec for you for free?
- aniviacat 10mo agoThey don't need to, they're free to become IE6. I don't think it's irrational to be upset when a (near-)monopoly browser holds back useful features. Even if said browser is provided for free.
- encom 10mo agoThey are IE6. They have near total market dominance, and dictate web standards. It's a very comparable situation to IE6 days.
- jeffbee 10mo agoGoogle did write one. They wrote the bad one that we're discussing.
- mort96 10mo agoMozilla's position for some time now has been, "we aren't opposed to shipping JXL support, but we'd want to ship a decent implementation in a memory safe language, not the reference C++ implementation". That position hasn't been met with very much criticism. Google's position, on the other hand, has been a flat-out "no, we will not ship JXL". That's what has been met with criticism. Not an imagined reluctance to shipping a C++ JXL implementation.
- spookie 10mo agoWell, the first public implementation dates to 2020. And, the Cpp choice is obvious, simpler integration with the majority of existing image processing libs, tools and utilities. Not to mention GUI toolkits. Nonetheless, we should really bear in mind how entrenched Cpp is. If you normalize CVEs by language popularity Java looks downright dangerous!