Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

51–60 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#51
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

Ubiquiti products require it for some functionality, and they're wildly popular for Wifi and wireless ISPs right now.

I actually just filed a complaint on their forums.

http://community.ubnt.com/t5/UniFi-Wireless/BUG-Adobe-Flash-...

Re: Two more Flash 0-days emerge in Hacking Team leak

#52
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

This is like asking why people still use cash when there are so many other easier to use & manage payment options. The simple answer is there are far too many edge cases where it's still required - any single one doesn't sound like a good answer.

Re: Two more Flash 0-days emerge in Hacking Team leak

#53
Flash is decades old, not that big, and still has use-after-free vulnerabilities? Tools for catching those have been widely available for years. That makes one suspect those vulnerabilities aren't there by accident.

We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.

Re: Two more Flash 0-days emerge in Hacking Team leak

#54
post #9
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

A lot of advertising networks use it to deliver advertisements. Whether it is simple inertia at this point, or because the networks can get a better fingerprint using flash, I don't know. Also, it used to be the case that Flash had better DRM controls on it, but I'm pretty sure that reason is no longer the case since Encrypted Media Extensions got rolled out. However, that doesn't explain why Facebook's on-site video…

Which is what makes these exploits so insidious: sneak an infected advertisement onto one network, even briefly, and you're now targeting who knows how many Internet users visiting legitimate, trusted websites.

Honestly, one of the biggest reasons to run an ad blocker is the significantly reduced attack surface.

Re: Two more Flash 0-days emerge in Hacking Team leak

#56
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

Their clientele isn’t security wary people. Plus they don’t have any serious competition in most of their products so it can’t hurt them either way. So they’ll probably issue a generic statement and move on with their lives.

As for consequences, the best thing most of us could do is disable Flash from the browser. I’ve done it since YouTube defaulted to HTML5 video and never looked back since.

Re: Two more Flash 0-days emerge in Hacking Team leak

#57
post #53

Flash is decades old, not that big, and still has use-after-free vulnerabilities? Tools for catching those have been widely available for years. That makes one suspect those vulnerabilities aren't there by accident. We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.

Flash is big - video, audio, animation, browser hooks, filesystem access, etc. - and while Flash has been around for decades the code in the current iteration mostly hasn't been.

Re: Two more Flash 0-days emerge in Hacking Team leak

#58
post #5

Earlier quoted context omitted.

I'm as grossed out by HT as the next message board nerd, but they didn't develop these bugs; modern industrial software development did. All HT did was weaponize them. These guys aren't the sharpest tools in the shed, so I think you can safely assume other people weaponized these, or worse bugs, as well.

HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…

Why don't you 100% blame the people at fault: Adobe / the original developers.

First, they were incompetent enough to not correctly develop their software.

Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) These companies are effectively outsourcing security testing and remediation of their software, then whinging that independent developers don't work for free.

Re: Two more Flash 0-days emerge in Hacking Team leak

#59
post #58

Earlier quoted context omitted.

HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…

Why don't you 100% blame the people at fault: Adobe / the original developers. First, they were incompetent enough to not correctly develop their software. Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) T…

Bug bounties are sensible, but price-matching seems too easy to game. How can the company know a bid is serious, and not just fake to be matched? "Oh, sure, so-and-so offered $200k for this bug."

(For that matter, while reputation is certainly a thing, what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix? Do the typical contracts to sell 0-days involve continued payment based on the amount of time the bug remains unfixed?)

Re: Two more Flash 0-days emerge in Hacking Team leak

#60

Earlier quoted context omitted.

A significant portion of the web using community (including myself) stopped using flash 6-12 months ago, when all the zero-days became a monthly occurrence. The plugin is no longer strategic for adobe, they've stopped any forward-looking development on it, and are now in the mode of whack-a-mole reactive security patching. I have not once every missed having flash on my system. It's not just the case that the web is…

> The plugin is no longer strategic for adobe, they've stopped any forward-looking development on it, and are now in the mode of whack-a-mole reactive security patching. [citation needed]

About four years back Adobe committed to HTML5 on mobile platforms, and noted they would only provide bug fixes and security patches.

http://www.cbsnews.com/news/adobe-abandons-flash-player-on-m...

http://www.telegraph.co.uk/technology/news/8879783/Adobe-aba...

Post reply on HN