Live data from Hacker News

Google releases a fix for flash, before Adobe

securitywatch.pcmag.com

11–20 of 32 posts

Re: Google releases a fix for flash, before Adobe

#11

So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability? What if they have detected black hats exploiting the vulnerability. Should they sit on a fix? What if they were building their own implementation of a programming language or tool. For example, what…

This is obviously a matter of opinion, so here is mine: Patches and information pertaining a vulnerability should be released in a coordinated way or as soon as there is evidence that information about the vulnerability is already public. By public I mean that has escaped the closed circle of the vendor, and in the case of a reported vulnerabilty, also the reporter.

If you find out a vulnerability is being exploited in the wild, and already have a patch or technical description, you should release it. If one of the two parts commits a mistake and releases information about the vulnerability (like, for example, a patch that can be reverse-engineered), then all other involved parts should release what they have.

If they don't have a patch or if they aren't ready to release it, which seems to be the case here, Adobe should at least release technical details. These can be used to mitigate the impact of the vulnerability on unpatched hosts.

Re: Google releases a fix for flash, before Adobe

#12
post #7

Earlier quoted context omitted.

Just to be clear: while reasonable people can disagree about patch and disclosure timing, the point that this article makes isn't a fringe point. Virtually every vulnerability researcher goes through some kind of elaborate dance with vendors to coordinate the safest reasonable release of bugs and patches. So it's not as if there's an widely accepted principal of "patch as quickly as possible". There are tens, probabl…

I’m idly imagining a massive Google HoneyFarm with browsers that examine payloads from known “harmful sites” and spam or phishing emails. The moment one of the vulnerabilities is found “in the wild," the patch is automatically pushed into the wild, Adobe be damned.

If Google wanted to spend a lot of effort just to hot-foot one of the harder working teams in software security they could indeed build a system whose primary function was to put pressure on Adobe.

Re: Google releases a fix for flash, before Adobe

#13
post #7

So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability? What if they have detected black hats exploiting the vulnerability. Should they sit on a fix? What if they were building their own implementation of a programming language or tool. For example, what…

Just to be clear: while reasonable people can disagree about patch and disclosure timing, the point that this article makes isn't a fringe point. Virtually every vulnerability researcher goes through some kind of elaborate dance with vendors to coordinate the safest reasonable release of bugs and patches. So it's not as if there's an widely accepted principal of "patch as quickly as possible". There are tens, probabl…

Just this year there have been several Flash or Flash/Acrobat vulnerabilities that were seen in the wild and Adobe said the patch was two weeks out.

I would not be surprised if over half of this year's weeks fall under the case of having a vulnerability they have issued an advisory for and have yet to patch.

Re: Google releases a fix for flash, before Adobe

#14
post #13
post #7

Earlier quoted context omitted.

Just to be clear: while reasonable people can disagree about patch and disclosure timing, the point that this article makes isn't a fringe point. Virtually every vulnerability researcher goes through some kind of elaborate dance with vendors to coordinate the safest reasonable release of bugs and patches. So it's not as if there's an widely accepted principal of "patch as quickly as possible". There are tens, probabl…

Just this year there have been several Flash or Flash/Acrobat vulnerabilities that were seen in the wild and Adobe said the patch was two weeks out. I would not be surprised if over half of this year's weeks fall under the case of having a vulnerability they have issued an advisory for and have yet to patch.

I'm sure Google is not doing stuff like this for fun. I'm just saying the point the article is making is not crazytalk.

Re: Google releases a fix for flash, before Adobe

#15
post #12

Earlier quoted context omitted.

I’m idly imagining a massive Google HoneyFarm with browsers that examine payloads from known “harmful sites” and spam or phishing emails. The moment one of the vulnerabilities is found “in the wild," the patch is automatically pushed into the wild, Adobe be damned.

If Google wanted to spend a lot of effort just to hot-foot one of the harder working teams in software security they could indeed build a system whose primary function was to put pressure on Adobe.

I’m confused by the relationship between your statement and my imaginary HoneyFarm.

First, how would a system that searches for exploits in the wild then releases patches for those vulnerabilities have a primary purpose of “putting pressure on Adobe?” Its primary purpose is to protect the users of its products from an exploit.

Second, help me understand why I should care about how hard Adobe’s team works. Are you saying they deserve our sympathy? Or implying that since they are smart and working hard, we cannot expect any better results than they are getting?

Re: Google releases a fix for flash, before Adobe

#16
post #12

Earlier quoted context omitted.

If Google wanted to spend a lot of effort just to hot-foot one of the harder working teams in software security they could indeed build a system whose primary function was to put pressure on Adobe.

I’m confused by the relationship between your statement and my imaginary HoneyFarm. First, how would a system that searches for exploits in the wild then releases patches for those vulnerabilities have a primary purpose of “putting pressure on Adobe?” Its primary purpose is to protect the users of its products from an exploit. Second, help me understand why I should care about how hard Adobe’s team works. Are you say…

I think Adobe's team deserves more sympathy than it gets. I'm not making any comment about Adobe- the- company, which I know very little about.

Re: Google releases a fix for flash, before Adobe

#17
post #8
post #3

Earlier quoted context omitted.

not for many, many, many years : http://www.adobe.com/products/player_census/flashplayer/vers... its still by far the single most installed desktop runtime.

> its still by far the single most installed desktop runtime. Flash is likely the single most installed software in the world. Consider how many Windows, Mac, and Linux desktops and Android devices have Flash.

I wonder how it compares with webkit? There's android, iphone, RIM, and chrome.

Re: Google releases a fix for flash, before Adobe

#20
What BS:

> "Even Google isn't well-served by this; not everyone updates their Chrome version immediately, especially updates like this one which require that you restart the browser (and all running browser instances)."

Protip: Updating Flash requires the same thing. In fact, updating Flash will shut down all kinds of apps you have running, including all Flash-capable browsers and even some Flash-reliant native apps.

Post reply on HN