Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.
Two more Flash 0-days emerge in Hacking Team leak
91–100 of 193 posts
Re: Two more Flash 0-days emerge in Hacking Team leak
#92Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.
YouTube's Flash player still works a lot better than the HTML5 one. Their HTML5 one desynchs the audio occasionally, cuts off the audio before the video ends, doesn't support a real right click -> copy video URL (all it can do is give a popup with the URL), and still has other small bugs. The Flash one has none of these problems. It seems to be the case in general for most sites that offer HTML5 alternatives that the…
Re: Two more Flash 0-days emerge in Hacking Team leak
#93Earlier quoted context omitted.
The BBC site will use non-flash videos if you browse it on an iPad, but they don't seem smart enough to serve these to you if you use a desktop browser with flash disabled. Presumably they could implement a non-flash fallback for users but unfortunately they just haven't bothered. I tried to cheat by modifying my User-Agent to pretend to be an iPad but had no luck...
I was going to agree with you, but I've just double-checked, and you CAN access video content on the BBC sites on a desktop (MacOS X Safari) by setting your User-Agent to iPad. However, it's important that you've removed Flash completely from your system (using Flash Uninstaller), rather than just disable Flash (hoping to use Click-To-Flash). For some reason, they detect Flash by some kind of file-path-detection code…
I'm surprised that websites can do any kind of file path detection on a client...
Re: Two more Flash 0-days emerge in Hacking Team leak
#94I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.
Re: Two more Flash 0-days emerge in Hacking Team leak
#95Re: Two more Flash 0-days emerge in Hacking Team leak
#96Earlier quoted context omitted.
"You think that any other software you use is any better?" I certainly HOPE most software I use can do better than this: http://www.cvedetails.com/vulnerability-list/vendor_id-53/pr... To be certain, Flash gets a lot of attention because of its install base - but it's been a never-ending FOUNTAIN of RCE bugs for much of the last decade.
Most software that's as complex as Flash is probably similarly full of bugs. Most of those vulnerabilities reek of huge development teams toiling over a codebase whose foundation was written in the late 90s and had features and fixes duct taped ever since.
Re: Two more Flash 0-days emerge in Hacking Team leak
#97Earlier quoted context omitted.
Isn't the record of infinite vulnerabilities in Flash widely known by everybody?
So if it is so widely known, why no action was taken by anyone to stop them from undermining Internets security? Also not everyone knows how bad Flash is for their security, only few geeks care about reading cve-s. So until it goes to mainstream media not enough people will care.
Re: Two more Flash 0-days emerge in Hacking Team leak
#98Re: Two more Flash 0-days emerge in Hacking Team leak
#99Flash is decades old, not that big, and still has use-after-free vulnerabilities? Tools for catching those have been widely available for years. That makes one suspect those vulnerabilities aren't there by accident. We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.
Flash is big - video, audio, animation, browser hooks, filesystem access, etc. - and while Flash has been around for decades the code in the current iteration mostly hasn't been.
Re: Two more Flash 0-days emerge in Hacking Team leak
#100I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.