Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

121–130 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#121
post #84
post #77

Earlier quoted context omitted.

Their latest controller (v4?) removed the Flash requirement for both video (playback) and main (maps) IIRC. Do they still have leftover areas that require Flash?

v4 is a long way from being a stable release

wtf are you complaining for? You don't like flash and they are removing it.

Re: Two more Flash 0-days emerge in Hacking Team leak

#122
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

How about making police raid homes and forcefully uninstall Flash Player?

Re: Two more Flash 0-days emerge in Hacking Team leak

#123
post #84
post #77

Earlier quoted context omitted.

Their latest controller (v4?) removed the Flash requirement for both video (playback) and main (maps) IIRC. Do they still have leftover areas that require Flash?

v4 is a long way from being a stable release

Ah, I was under the impression that they've officially moved it out of the 'beta' naming

Re: Two more Flash 0-days emerge in Hacking Team leak

#124
post #94
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

If there were actually a government body that cared about "cyber"-security, they'd be hauled up in front of it. They're basically an infosec Bhopal - creating a toxic mess that other people have to clean up over a period of decades.

In essence there are not critical US systems running on Flash and so the defensive side of NSA don't care. And the offensive side is just happy to let it rot, as that means more opportunities for them.

Re: Two more Flash 0-days emerge in Hacking Team leak

#125
post #87

Earlier quoted context omitted.

I do not disagree. In fact, I personally have a problem with all non-vendor vulnerability sales, for the same reason. I just think we should be clear that exploit developers, brokers, and users don't actually create vulnerabilities; software companies do. I also think people should give Adobe a little bit of a break --- not much of one, but a little. Adobe got monstrously successful off a codebase that largely predat…

Macromedia/Adobe has had 15 years to respond to the news that Internet security matters. 15 years.

15 years ago a pretty sizable chunk of the industry thought heap overflows weren't exploitable for code execution, so I don't think that's the right interval.

Re: Two more Flash 0-days emerge in Hacking Team leak

#126
post #92

Earlier quoted context omitted.

YouTube's HTML5 video player has always been a shit-show, and I don't understand why. Vimeo has had an excellent HTML5 video player for many years, and there's at least a few third-party HTML5 video players that are pretty good as well.

Speak for yourself. YouTube's HTML5 video player has always been stellar for me.

Are you sure you're actually using the HTML5 player? I am being 100% serious when I say I've never met someone before who thinks YouTube's HTML5 player is good.

Among the various issues I've seen:

* Sometimes refuses to play anything, without showing any errors, requiring a reload of the page.

* Occasional poor performance.

* Audio/video desynchronization

* Scrubbing the video often causes it to get stuck, refusing to play, until I scrub it again

* Videos often take longer to start playing than with the flash player.

* Fullscreen is sometimes broken

* Switching from regular mode to "theater" mode sometimes leaves the video playing in its original size, anchored to the corner of the now-larger black area that it should be playing in.

I think it's gotten a little better recently (i.e. I see issues less often), but it's still far from great.

And before you ask, I've seen these issues in both Safari and Chrome.

Re: Two more Flash 0-days emerge in Hacking Team leak

#127
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

you probably can lookup news archives of the last ~15 years for that

Re: Two more Flash 0-days emerge in Hacking Team leak

#128
post #127
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

you probably can lookup news archives of the last ~15 years for that

:) I was at a security meeting, I've heard the same reply. I am really not sure why it's still so used though.

Re: Two more Flash 0-days emerge in Hacking Team leak

#129
post #127
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

you probably can lookup news archives of the last ~15 years for that

[deleted]
Post reply on HN