Live data from Hacker News

“Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

blogs.adobe.com

31–40 of 43 posts

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#31
post #22

I'm a bit confused about the title of this post. The actual title of the blog post is "Security Updates Available for Adobe Flash Player (APSB16-08)". The current HN link text is “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”. I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an annou…

Wow, I can see it way now. I had first imagined a community of loyal Adobe fans wondering why Adobe hasn't addressed CVE-whatever-is-up-today and getting pitch-forky. I saw the title as a response to that: in the tone of "Yeah, folks, Adobe knows. Here's the fix, now calm the fuck down."

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#32
post #20
post #12

Adobe's attitude towards security is mediocre, possibly irresponsible. They know that Flash is being phased out, so they invest no effort. For 2014--15, they relied on Google Project Zero to find and sometimes even fix their security flaws.

"Thoughts on Flash" is almost 6 years old. http://www.apple.com/hotnews/thoughts-on-flash/ Adobe is a business. They need to move on too. When companies like Microsoft or Adobe, for example, let users hang on for too long to legacy software, it hurts everyone.

Nobody is asking them to build new features, just fix security issues. And Flash is still a supported platform by their designing tools like Animate.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#33
post #6
post #5

Earlier quoted context omitted.

Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.

Early PDF was quite sane. It was the Postscript imaging model turned into a binary bytecode format with almost all the programmability features removed. Later on it got wonky (though never even close to the extent to which Flash did!) with all the hypertextification features. But basic PDF is actually one of the Great File Formats in computer history.

The sane version is the one defined as the PDF/A ISO standard. Stuff like pulling remote resources, embedding executable code, etc are all forbidden.

https://en.wikipedia.org/wiki/PDF/A

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#34
post #22

I'm a bit confused about the title of this post. The actual title of the blog post is "Security Updates Available for Adobe Flash Player (APSB16-08)". The current HN link text is “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”. I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an annou…

The HN link text seems to be taken from [1], which contains the CVE id.

[1] https://helpx.adobe.com/security/products/flash-player/apsb1...

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#35

Completely disabled Flash in my main browser (Firefox) a couple months ago. The occasional video player doesn't have a HTML5 fallback, but otherwise it's all good.

Completely disabled Flash in my main browser over decade ago.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#36
post #25

Is there a site which lists details of these CVE security issues? The closest thing I could find via google is cve.mitre.org but CVE-2016-1010 is "reserved" for future usage.

In this case Adobe is mentioning only the "registration number" of the vulnerability to avoid revealing publically what the actual vulnerability is. Don't you feel safer already?

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#37
post #20

Earlier quoted context omitted.

"Thoughts on Flash" is almost 6 years old. http://www.apple.com/hotnews/thoughts-on-flash/ Adobe is a business. They need to move on too. When companies like Microsoft or Adobe, for example, let users hang on for too long to legacy software, it hurts everyone.

Nobody is asking them to build new features, just fix security issues. And Flash is still a supported platform by their designing tools like Animate.

Adobe Animate isn't a new tool, fyi. It used to be called "Adobe Flash Professional". They renamed it in order to distance it from Flash.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#38

Completely disabled Flash in my main browser (Firefox) a couple months ago. The occasional video player doesn't have a HTML5 fallback, but otherwise it's all good.

I've got Chrome set to only run flash when I explicitly allow it. (chrome://settings/content -> Plugins -> Let me choose when to run plugin content)

All plugins are blocked unless I right click on the area where they appear on-screen and click "Run this plugin". Over time I've found myself needing to do that less and less.

Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”

#39
post #22

I'm a bit confused about the title of this post. The actual title of the blog post is "Security Updates Available for Adobe Flash Player (APSB16-08)". The current HN link text is “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”. I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an annou…

I think the intention here is to make people realize they should have disabled Flash a long time ago and use it only for a limited number of critical whitelisted websites (like banking sites built on Air). If you do otherwise, you're increasing the risk of being a victim of a malicious attack.

FUD is FUD, and this is preaching to the choir anyway.
Post reply on HN