Live data from Hacker News

Adobe issues emergency Flash fix

bbc.com

11–20 of 45 posts

Re: Adobe issues emergency Flash fix

#11

OP is blog spam of this post: https://krebsonsecurity.com/2015/06/emergency-patch-for-adob... Which is highlighting this security release from Tuesday: https://helpx.adobe.com/security/products/flash-player/apsb1...

The BBC is blog spam? Or did the mods change the link without telling us?

Re: Adobe issues emergency Flash fix

#12
post #8
post #3

I uninstalled Flash a few months ago and don't miss it. I mostly use Firefox, but I do keep Chrome around, so I could use Chrome's Flash if I wanted to, but I don't think I have so far. The only site I commonly visit that doesn't work is BBC News, funnily enough. It's a little annoying because it will work if I change the user agent to iPad, but instead I just don't watch BBC News videos.

So Chrome has their own flash written by engineers at Google?

Sort of.

http://www.pcworld.com/article/250455/for_flash_on_linux_chr...

> Adobe and Google have now created a “Pepper” implementation of Flash Player for all x86/64 platforms supported by the Google Chrome browser, Adobe said.

Re: Adobe issues emergency Flash fix

#13

OP is blog spam of this post: https://krebsonsecurity.com/2015/06/emergency-patch-for-adob... Which is highlighting this security release from Tuesday: https://helpx.adobe.com/security/products/flash-player/apsb1...

The BBC is blog spam? Or did the mods change the link without telling us?

The BBC is blog spam yes. It quotes Kreb's article, which happens to be almost exactly the same, except BBC removed links to the advisory, etc.

Edit: in response to TazeTSchnitzel to whom I cannot reply. If BBC included a link to the original post or the actual security advisory I would be less likely to call it blog spam, but I stand by my classification. It is a repost without the sources and with less information (notably a warning to users about the McAfee opt out among other things).

Re: Adobe issues emergency Flash fix

#14

Earlier quoted context omitted.

The BBC is blog spam? Or did the mods change the link without telling us?

The BBC is blog spam yes. It quotes Kreb's article, which happens to be almost exactly the same, except BBC removed links to the advisory, etc. Edit: in response to TazeTSchnitzel to whom I cannot reply. If BBC included a link to the original post or the actual security advisory I would be less likely to call it blog spam, but I stand by my classification. It is a repost without the sources and with less information…

It's not blog spam. That would be needless, spammy content duplication to the same audience. But the BBC has a much wider audience than Krebs.

Re: Adobe issues emergency Flash fix

#15
post #10
post #2

It must be such a weight around Adobe's neck, supporting Flash as it dies. I pity the guy who's job it is to maintain it indefinitely.

Flash will get a second life with WebAssembly.

Given ActionScript is a superset of ECMAScript, it would make more sense to compile it to JS.

Re: Adobe issues emergency Flash fix

#17
post #10
post #2

It must be such a weight around Adobe's neck, supporting Flash as it dies. I pity the guy who's job it is to maintain it indefinitely.

Flash will get a second life with WebAssembly.

If it lives on in an unbreakable, throttleable sandbox, that's not a disaster. It was the leaky native code that was the problem.

Re: Adobe issues emergency Flash fix

#18
Chrome really needs to stop bundling this garbage. Even with whatever Google magic attached to flash, its still a very dangerous plugin, if not the most dangerous. There was just a CVE for the version previous to this one. And the one before that. Its an endless treadmill.

This should be a wake-up call to make flash non-default and, if installed, click-to-play only. Its time we started treating it like Java. Like Java, its clear its owner can't secure it. I imagine its borderline unmaintainable spaghetti code at this point.

Its also very hypocritical of Google, who has taken issue with SSL encryption levels and NPAPI, to be bundling what's essentially the second largest malware vector in browser history, only behind Java. This SHOULD be our wake-up call.

Re: Adobe issues emergency Flash fix

#20
If you don't have Click-to-play enabled for Firefox, you should, and here's how you do it:

Open Firefox and navigate to about:config.

You will be sarcastically warned that you about to void your warranty, just click on the “I’ll be careful, I promise!” button to move on.

Now search for:

    plugins.click_to_play
Next you need to right-click and toggle the setting so that the value is true.

Once you are done restart Firefox.

To test it out, head over to a site with Flash (BBC, ironically, has Flash), you will notice you will have to click on the plugin to activate it.

That’s all there is to it.

I'm sure there's a similar method for Chrome, but I don't have it installed to test.

Post reply on HN