Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

31–40 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#31

Earlier quoted context omitted.

What websites use it? I've not encountered a single incompatible website recently, and haven't had flash installed for a long time now.

twitch.tv

You can play streams with: livestreamer

http://docs.livestreamer.io/

And chat trough their irc server.

Re: Two more Flash 0-days emerge in Hacking Team leak

#34
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

YouTube's Flash player still works a lot better than the HTML5 one. Their HTML5 one desynchs the audio occasionally, cuts off the audio before the video ends, doesn't support a real right click -> copy video URL (all it can do is give a popup with the URL), and still has other small bugs. The Flash one has none of these problems.

It seems to be the case in general for most sites that offer HTML5 alternatives that the Flash version is much more solid. Maybe using HTML5 video in these domains is inherently error-prone, maybe it isn't, but in practice it almost always gets screwed up.

Plus people still use flash games and sites like Newgrounds.

Re: Two more Flash 0-days emerge in Hacking Team leak

#35
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

Twitch. Which happens to amuse me, which I like to waste time. But .. they seem unwilling to move away from Flash (the only thing I found was a ~3 year old support thread that wants to .. support HLS. Yay. Not that's not helpful)

Re: Two more Flash 0-days emerge in Hacking Team leak

#37
post #10
post #4

guess it's time to disable flash for a few weeks...

I've been running without Flash for a couple of years now. The only thing I can't do that I would like to be able to do is to watch Facebook videos. Other than that, not having Flash installed is not a problem for me.

Facebook doesn't use HTML5? Why?!

Re: Two more Flash 0-days emerge in Hacking Team leak

#40
post #5
post #2

Hacking Team developed digital smallpox, and failed to safeguard it. Thanks.

I'm as grossed out by HT as the next message board nerd, but they didn't develop these bugs; modern industrial software development did. All HT did was weaponize them. These guys aren't the sharpest tools in the shed, so I think you can safely assume other people weaponized these, or worse bugs, as well.

HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again?

Say you discover a very powerful attack on AES which allows you under many circumstances to recover the key:

1. do you have an ethical obligation to warn affected parties?

2. If you don't and instead secretly sell this decryption capability to governments and/or private actors, do you have an obligation to ensure that this capability isn't used illegally or unethically?

3. What due diligence is required to protect a vulnerability of this scale?

Post reply on HN