Bug#960454: chromium: Make Chromium ask before downloading and enabling DRM

2021-01-25 Thread Charlemagne Lasse
Completely disabling the autoupdater was an extremely bad idea. Now even various autoupdater scripts to update the global version in /usr/lib/chromium/WidevineCdm don't work anymore - so leaving users in a broken state. See also #981069

Bug#960454: chromium: Make Chromium ask before downloading and enabling DRM

2021-01-01 Thread Michel Le Bihan
Hello, Yes, it won't be updated. If there will be a security issue/vuln, then probably somebody will write about it and we will do something about that. Michel Le Bihan Le vendredi 01 janvier 2021 à 20:34 +0100, Stephen Kitt a écrit : > Hi, > > On Fri, 25 Dec 2020 20:50:04 +0100 Michel Le

Bug#960454: chromium: Make Chromium ask before downloading and enabling DRM

2021-01-01 Thread Stephen Kitt
Hi, On Fri, 25 Dec 2020 20:50:04 +0100 Michel Le Bihan wrote: > With > https://salsa.debian.org/mimi8/chromium/-/commit/d21192e70824befdfeed5a5145275139cd6c4ffa > the Widevine component won't be downloaded automatically. However, > unlike when `enable_widevine=false` is set, Widevine CDM

Bug#960454: chromium: Make Chromium ask before downloading and enabling DRM

2021-01-01 Thread Christoph Anton Mitterer
On Fri, 2021-01-01 at 12:10 +0100, Michel Le Bihan wrote: > > > That's actually intended. It would be easier to set the build flag > that > disables it, but some users are still interested in using it. The way > it's done currently still allows them to use it. Yeah, but the point is, AFAIU, for

Bug#960454: chromium: Make Chromium ask before downloading and enabling DRM

2021-01-01 Thread Michel Le Bihan
Hello Le vendredi 01 janvier 2021 à 02:53 +0100, Christoph Anton Mitterer a écrit : > Hey. > > > Just wondered: > > > 1) Since this is a binary blob who, by it's nature, is made for > surveillance, it's IMO more a rather serious security issue than just > a > DFSG-policy problem. > No one

Bug#960454: chromium: Make Chromium ask before downloading and enabling DRM

2020-12-31 Thread Christoph Anton Mitterer
Hey. Just wondered: 1) Since this is a binary blob who, by it's nature, is made for surveillance, it's IMO more a rather serious security issue than just a DFSG-policy problem. No one really knows what exactly Google ships there. So maybe people should be told about this more actively in a

Bug#960454: chromium: Make Chromium ask before downloading and enabling DRM

2020-12-25 Thread Michel Le Bihan
Hello, With https://salsa.debian.org/mimi8/chromium/-/commit/d21192e70824befdfeed5a5145275139cd6c4ffa the Widevine component won't be downloaded automatically. However, unlike when `enable_widevine=false` is set, Widevine CDM component will still be used when found in