Open source VideoLAN media player asks why it's blocked in India
Rubbishes suggestions poisoned clones or ancient malware are worthy reasons for ban
Developers of the open source VideoLAN media player have started sniping at India's government over an apparent block on the project's website.
VideoLAN, aka VLC, develops a media player and transcriber famed for playing and transcoding almost any media format, and doing so quickly through a pleasant interface. The project claims its wares have been downloaded over four billion times.
But for the last few months, would-be users located in India have not been able to download from videolan.org, which has been inaccessible for users of some ISPs and in some states.
Governments and ISPs have offered no explanation for the site's inaccessibility.
One theory relates to the fact that, in April 2022, Symantec suggested a China-linked crime gang named Cicada was conducting a global espionage campaign using tools including attacks on VideoLAN.
India has banned hundreds of Chinese apps, so blocking videloan.org makes some sense in that context.
As VideoLAN is open source, it's also possible to create fake versions of the software and embed malware. The project has also had security issues involving opening poisoned media files – but largely blamed them on a dependency rather than its own efforts.
Indian blocks of VideoLAN went largely unnoticed for weeks, until last weekend when Indian media reported on the matter. VideoLAN sprang into action on Twitter.
If you are in India, please help us. https://t.co/rOpIjlx0q9— VideoLAN (@videolan) August 12, 2022
India's Internet Freedom Foundation then revealed it had been asking questions about the ban, to no avail.
On June 07, 2022, we filed a Right to Information application with @DoT_India seeking information on the blocking of the website of VideoLAN[dot]org in India. DoT transferred it to @GoI_MeitY, which then responded on July 14 that “No information is available [with MeitY]” (1/4) https://t.co/usQHOmaJdW— Internet Freedom Foundation (IFF) (@internetfreedom) August 14, 2022
One theory that emerged during recent days was that India is worried about downloads of compromised versions of VideoLAN, so blocked its website to prevent further downloads
The project today rebutted that argument by stating "Blocking the main website will just push users to weirder websites, and therefore towards shady versions of VLC."
- India proposes increased power to vet tech mergers
- Honor moving team out of India for 'obvious reasons,' says CEO
- India binned made-in-Singapore app in latest round of China bans
The project also shared the following thread penned by ethical hacker Sunny Nehra.
1/ No idea why VLC is banned.— Sunny Nehra (@sunnynehrabro) August 13, 2022
-> VLC is French project not Chinese.
-> For those taking about Cicada malware campaign, plz understand that a very outdated is vulnerable to DLL Hijacking (patched in 2010) and the threat actor need to install outdated VLC version for that attack.
The Register has contacted India's Department of Telecommunications seeking information on the ban and will update this story if we receive a substantive response. ®