Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

91–100 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#92
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

YouTube's Flash player still works a lot better than the HTML5 one. Their HTML5 one desynchs the audio occasionally, cuts off the audio before the video ends, doesn't support a real right click -> copy video URL (all it can do is give a popup with the URL), and still has other small bugs. The Flash one has none of these problems. It seems to be the case in general for most sites that offer HTML5 alternatives that the…

YouTube's HTML5 video player has always been a shit-show, and I don't understand why. Vimeo has had an excellent HTML5 video player for many years, and there's at least a few third-party HTML5 video players that are pretty good as well.

Re: Two more Flash 0-days emerge in Hacking Team leak

#93

Earlier quoted context omitted.

The BBC site will use non-flash videos if you browse it on an iPad, but they don't seem smart enough to serve these to you if you use a desktop browser with flash disabled. Presumably they could implement a non-flash fallback for users but unfortunately they just haven't bothered. I tried to cheat by modifying my User-Agent to pretend to be an iPad but had no luck...

I was going to agree with you, but I've just double-checked, and you CAN access video content on the BBC sites on a desktop (MacOS X Safari) by setting your User-Agent to iPad. However, it's important that you've removed Flash completely from your system (using Flash Uninstaller), rather than just disable Flash (hoping to use Click-To-Flash). For some reason, they detect Flash by some kind of file-path-detection code…

That's irritating! I'll have to take a closer look at what they are doing, as I'd like to keep flash around on a click-to-run basis.

I'm surprised that websites can do any kind of file path detection on a client...

Re: Two more Flash 0-days emerge in Hacking Team leak

#94
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

If there were actually a government body that cared about "cyber"-security, they'd be hauled up in front of it. They're basically an infosec Bhopal - creating a toxic mess that other people have to clean up over a period of decades.

Re: Two more Flash 0-days emerge in Hacking Team leak

#96
post #90
post #78

Earlier quoted context omitted.

"You think that any other software you use is any better?" I certainly HOPE most software I use can do better than this: http://www.cvedetails.com/vulnerability-list/vendor_id-53/pr... To be certain, Flash gets a lot of attention because of its install base - but it's been a never-ending FOUNTAIN of RCE bugs for much of the last decade.

Most software that's as complex as Flash is probably similarly full of bugs. Most of those vulnerabilities reek of huge development teams toiling over a codebase whose foundation was written in the late 90s and had features and fixes duct taped ever since.

"Probably"? Complex as Flash? Whatever it have a big or small team, was started in the late 90s or whatever it causes problems now. So use whatever excuses you like, Flash is still a security concern with opportunity for more 0-day exploits(just one firm have two in the drawer, how many more there are?).

Re: Two more Flash 0-days emerge in Hacking Team leak

#97
post #68
post #44

Earlier quoted context omitted.

Isn't the record of infinite vulnerabilities in Flash widely known by everybody?

So if it is so widely known, why no action was taken by anyone to stop them from undermining Internets security? Also not everyone knows how bad Flash is for their security, only few geeks care about reading cve-s. So until it goes to mainstream media not enough people will care.

Apple dropped it and it was a large, if not the largest, reason for work on sandboxing plugins.

Re: Two more Flash 0-days emerge in Hacking Team leak

#99
post #53

Flash is decades old, not that big, and still has use-after-free vulnerabilities? Tools for catching those have been widely available for years. That makes one suspect those vulnerabilities aren't there by accident. We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.

Flash is big - video, audio, animation, browser hooks, filesystem access, etc. - and while Flash has been around for decades the code in the current iteration mostly hasn't been.

Being big is not an excuse for being terrible at security. If they can't secure a big thing, then maybe they should stop building them so big?

Re: Two more Flash 0-days emerge in Hacking Team leak

#100
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

Should we also ask what Microsoft has to say about their consistent streak of serious security problems in IE and Windows?
Post reply on HN