Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.
I actually just filed a complaint on their forums.
http://community.ubnt.com/t5/UniFi-Wireless/BUG-Adobe-Flash-...
51–60 of 193 posts
Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.
I actually just filed a complaint on their forums.
http://community.ubnt.com/t5/UniFi-Wireless/BUG-Adobe-Flash-...
Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.
We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.
Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.
A lot of advertising networks use it to deliver advertisements. Whether it is simple inertia at this point, or because the networks can get a better fingerprint using flash, I don't know. Also, it used to be the case that Flash had better DRM controls on it, but I'm pretty sure that reason is no longer the case since Encrypted Media Extensions got rolled out. However, that doesn't explain why Facebook's on-site video…
Honestly, one of the biggest reasons to run an ad blocker is the significantly reduced attack surface.
Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.
I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.
As for consequences, the best thing most of us could do is disable Flash from the browser. I’ve done it since YouTube defaulted to HTML5 video and never looked back since.
Flash is decades old, not that big, and still has use-after-free vulnerabilities? Tools for catching those have been widely available for years. That makes one suspect those vulnerabilities aren't there by accident. We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.
Earlier quoted context omitted.
I'm as grossed out by HT as the next message board nerd, but they didn't develop these bugs; modern industrial software development did. All HT did was weaponize them. These guys aren't the sharpest tools in the shed, so I think you can safely assume other people weaponized these, or worse bugs, as well.
HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…
First, they were incompetent enough to not correctly develop their software.
Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) These companies are effectively outsourcing security testing and remediation of their software, then whinging that independent developers don't work for free.
Earlier quoted context omitted.
HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…
Why don't you 100% blame the people at fault: Adobe / the original developers. First, they were incompetent enough to not correctly develop their software. Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) T…
(For that matter, while reputation is certainly a thing, what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix? Do the typical contracts to sell 0-days involve continued payment based on the amount of time the bug remains unfixed?)
Earlier quoted context omitted.
A significant portion of the web using community (including myself) stopped using flash 6-12 months ago, when all the zero-days became a monthly occurrence. The plugin is no longer strategic for adobe, they've stopped any forward-looking development on it, and are now in the mode of whack-a-mole reactive security patching. I have not once every missed having flash on my system. It's not just the case that the web is…
> The plugin is no longer strategic for adobe, they've stopped any forward-looking development on it, and are now in the mode of whack-a-mole reactive security patching. [citation needed]
http://www.cbsnews.com/news/adobe-abandons-flash-player-on-m...
http://www.telegraph.co.uk/technology/news/8879783/Adobe-aba...