I'm a bit confused about the title of this post. The actual title of the blog post is "Security Updates Available for Adobe Flash Player (APSB16-08)". The current HN link text is “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”. I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an annou…
“Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
31–40 of 43 posts
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#32Adobe's attitude towards security is mediocre, possibly irresponsible. They know that Flash is being phased out, so they invest no effort. For 2014--15, they relied on Google Project Zero to find and sometimes even fix their security flaws.
"Thoughts on Flash" is almost 6 years old. http://www.apple.com/hotnews/thoughts-on-flash/ Adobe is a business. They need to move on too. When companies like Microsoft or Adobe, for example, let users hang on for too long to legacy software, it hurts everyone.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#33Earlier quoted context omitted.
Is the PDF format itself broken, or just the awful Adobe Reader? There are dozens of PDF reader implementations, including all the major browsers. I cannot imagine they are all exploitable in the same way.
Early PDF was quite sane. It was the Postscript imaging model turned into a binary bytecode format with almost all the programmability features removed. Later on it got wonky (though never even close to the extent to which Flash did!) with all the hypertextification features. But basic PDF is actually one of the Great File Formats in computer history.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#34I'm a bit confused about the title of this post. The actual title of the blog post is "Security Updates Available for Adobe Flash Player (APSB16-08)". The current HN link text is “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”. I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an annou…
[1] https://helpx.adobe.com/security/products/flash-player/apsb1...
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#35Completely disabled Flash in my main browser (Firefox) a couple months ago. The occasional video player doesn't have a HTML5 fallback, but otherwise it's all good.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#36Is there a site which lists details of these CVE security issues? The closest thing I could find via google is cve.mitre.org but CVE-2016-1010 is "reserved" for future usage.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#37Earlier quoted context omitted.
"Thoughts on Flash" is almost 6 years old. http://www.apple.com/hotnews/thoughts-on-flash/ Adobe is a business. They need to move on too. When companies like Microsoft or Adobe, for example, let users hang on for too long to legacy software, it hurts everyone.
Nobody is asking them to build new features, just fix security issues. And Flash is still a supported platform by their designing tools like Animate.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#38Completely disabled Flash in my main browser (Firefox) a couple months ago. The occasional video player doesn't have a HTML5 fallback, but otherwise it's all good.
All plugins are blocked unless I right click on the area where they appear on-screen and click "Run this plugin". Over time I've found myself needing to do that less and less.
Re: “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”
#39I'm a bit confused about the title of this post. The actual title of the blog post is "Security Updates Available for Adobe Flash Player (APSB16-08)". The current HN link text is “Adobe is aware of a report that CVE-2016-1010 is being actively exploited”. I can't help but think that the HN post has that title to give the impression that Adobe knows about an issue and isn't fixing it. But isn't this blog post an annou…
I think the intention here is to make people realize they should have disabled Flash a long time ago and use it only for a limited number of critical whitelisted websites (like banking sites built on Air). If you do otherwise, you're increasing the risk of being a victim of a malicious attack.