Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

131–140 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#131
post #90

Earlier quoted context omitted.

Most software that's as complex as Flash is probably similarly full of bugs. Most of those vulnerabilities reek of huge development teams toiling over a codebase whose foundation was written in the late 90s and had features and fixes duct taped ever since.

Do Chrome and Safari have as bad a track record? Flash has been insecure since originally launched.

no, maybe not as bad, but JIT can be played pretty hard. I think the difference is that they are better structured and more transparent. I would definitely NOT put my hands on flash code, must be a mess!

Re: Two more Flash 0-days emerge in Hacking Team leak

#132
post #9

Earlier quoted context omitted.

A lot of advertising networks use it to deliver advertisements. Whether it is simple inertia at this point, or because the networks can get a better fingerprint using flash, I don't know. Also, it used to be the case that Flash had better DRM controls on it, but I'm pretty sure that reason is no longer the case since Encrypted Media Extensions got rolled out. However, that doesn't explain why Facebook's on-site video…

Facebook appears to have moved to an html player in the last few days.

Not for everyone, apparently. I'm still being prompted to install a plugin.

Not only that, but images flagged as "gif" also prompt me to install flash (amazing how oddly these new features get implemented!).

Re: Two more Flash 0-days emerge in Hacking Team leak

#133

Earlier quoted context omitted.

Bug bounties are sensible, but price-matching seems too easy to game. How can the company know a bid is serious, and not just fake to be matched? "Oh, sure, so-and-so offered $200k for this bug." (For that matter, while reputation is certainly a thing, what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix? Do the typical contracts to sell 0…

How about an escrow contract using a third party and bitcoin? You could call it silk road 3 Its really not that hard to be taken for a ride if you have the resource adobe does.

If you know a company is legally obligated to pay up to $x, and that they have $x, you can offer to pay $x/1.1 in collusion/partnership with the bug-seller, for a share of the proceeds. You can outlaw the collusion, but setting up this kind of mechanic seems like a bad idea.

Re: Two more Flash 0-days emerge in Hacking Team leak

#134
post #106

For me there are generally 3 steps to the process of watching a youtube video. 1. Get the video id. Retrieve HTML containing youtube /watch?v= urls or other urls that contain the video id. Extract the urls from the HTML or other markup garbage. 2. Retrieve the video. Feed the /watch?v= url to a script that does some "find and replace" on the absurdly long googlevideo urls. Below I have given an example of such a scri…

Why are your functions named with numbers and why aren’t you using youtube-dl (https://rg3.github.io/youtube-dl/)?

Re: Two more Flash 0-days emerge in Hacking Team leak

#136

What are the people doing now who formerly developed Flash? Are they all diesel mechanics and baristas or what? I wouldn't even considering calling back a candidate why had Macromedia on their work history.

> I wouldn't even considering calling back a candidate why had Macromedia on their work history.

And I wouldn't even sort of consider hiring or even working with anyone that thinks work experience in a language makes them a liability.

Re: Two more Flash 0-days emerge in Hacking Team leak

#137
post #66
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

You think that any other software you use is any better? Flash gets it rough because it's widely used and independent of the browser (for the most part). If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people. If you're the kind of person that's going to get specifically targeted, then you should…

Flash gets it rough because it's horribly-written software full of security holes. It's demonstrably worse than most anything else out there.

Re: Two more Flash 0-days emerge in Hacking Team leak

#138
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

Should we also ask what Microsoft has to say about their consistent streak of serious security problems in IE and Windows?

To be fair, Microsoft started taking security extremely serious years ago

Re: Two more Flash 0-days emerge in Hacking Team leak

#139
post #66

Earlier quoted context omitted.

You think that any other software you use is any better? Flash gets it rough because it's widely used and independent of the browser (for the most part). If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people. If you're the kind of person that's going to get specifically targeted, then you should…

Flash gets it rough because it's horribly-written software full of security holes . It's demonstrably worse than most anything else out there.

Every piece of software you use is on a constant month-to-month patch train. Chrome, Windows, Firefox, Quicktime, Adium, hell even OpenSSL updates for security-critical bugs about once a month now. Flash is nothing special. All your software is insecure.

Re: Two more Flash 0-days emerge in Hacking Team leak

#140
post #64
post #52

Earlier quoted context omitted.

This is like asking why people still use cash when there are so many other easier to use & manage payment options. The simple answer is there are far too many edge cases where it's still required - any single one doesn't sound like a good answer.

Cash is still the most anonymous way to pay for something also, at least for most people.

[deleted]
Post reply on HN