Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

61–70 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#61
post #58

Earlier quoted context omitted.

HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…

Why don't you 100% blame the people at fault: Adobe / the original developers. First, they were incompetent enough to not correctly develop their software. Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) T…

> Why don't you 100% blame the people at fault: Adobe / the original developers.

I agree Adobe is at fault for producing insecure software.

Blame is not a limited resource, there is always extra blame to go around. If I am driving recklessly and my brakes fail due to a manufacturing error, both I and the car company are at fault for the accident. One can always, as HT has done, make a bad situation worse but behaving in a reckless and unethical matter.

>Adobe should give you 110% of the highest bid you get for any 0-day.

This! This so hard.

Re: Two more Flash 0-days emerge in Hacking Team leak

#62
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

I think the truth is, technology that supplants it is still not there yet. Sockets, sound, video...

And there's still a truckload of fun games available only in flash form, which makes flash relevant even if the number of new stuff coming out in it dwindles.

Re: Two more Flash 0-days emerge in Hacking Team leak

#63
post #58

Earlier quoted context omitted.

Why don't you 100% blame the people at fault: Adobe / the original developers. First, they were incompetent enough to not correctly develop their software. Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) T…

Bug bounties are sensible, but price-matching seems too easy to game. How can the company know a bid is serious, and not just fake to be matched? "Oh, sure, so-and-so offered $200k for this bug." (For that matter, while reputation is certainly a thing, what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix? Do the typical contracts to sell 0…

I'd care a lot more if Adobe, et al, weren't repeatedly screwing up. A couple million dollar bounties and forcing them to pay to internalize their negative externalities will help create the proper internal focus on shipping secure software. Reputation doesn't show up as a line-item.

And if a security dev resells, who cares? The company still got the 0-day and still gets it fixed asap. It's far better than our current situation where these can persist for years.

Re: Two more Flash 0-days emerge in Hacking Team leak

#64
post #52
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

This is like asking why people still use cash when there are so many other easier to use & manage payment options. The simple answer is there are far too many edge cases where it's still required - any single one doesn't sound like a good answer.

Cash is still the most anonymous way to pay for something also, at least for most people.

Re: Two more Flash 0-days emerge in Hacking Team leak

#66
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

You think that any other software you use is any better? Flash gets it rough because it's widely used and independent of the browser (for the most part).

If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people.

If you're the kind of person that's going to get specifically targeted, then you should not only reconsider running flash on your computer, but any other program written in an unsafe language.

Or, you know, segregate your data.

Re: Two more Flash 0-days emerge in Hacking Team leak

#67
post #31

Earlier quoted context omitted.

twitch.tv

You can play streams with: livestreamer http://docs.livestreamer.io/ And chat trough their irc server.

I don't think that's needed, i'm looking at Twitch right now (via the normal way) - and i don't have Flash installed.

Re: Two more Flash 0-days emerge in Hacking Team leak

#68
post #44
post #39

Earlier quoted context omitted.

What is news?

Isn't the record of infinite vulnerabilities in Flash widely known by everybody?

So if it is so widely known, why no action was taken by anyone to stop them from undermining Internets security?

Also not everyone knows how bad Flash is for their security, only few geeks care about reading cve-s. So until it goes to mainstream media not enough people will care.

Re: Two more Flash 0-days emerge in Hacking Team leak

#70

Earlier quoted context omitted.

Twitch. Which happens to amuse me, which I like to waste time. But .. they seem unwilling to move away from Flash (the only thing I found was a ~3 year old support thread that wants to .. support HLS. Yay. Not that's not helpful)

Twitch works just fine with HTML5 these days, including chat.

How do you get the video to play with HTML5?
Post reply on HN