Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

141–150 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#141
post #94

Earlier quoted context omitted.

If there were actually a government body that cared about "cyber"-security, they'd be hauled up in front of it. They're basically an infosec Bhopal - creating a toxic mess that other people have to clean up over a period of decades.

In essence there are not critical US systems running on Flash and so the defensive side of NSA don't care. And the offensive side is just happy to let it rot, as that means more opportunities for them.

The thorn in the side of removing Flash has been VMware, who, in their latest vSphere 6 release, clearly made the point that "Flash is the future", with announcements towards deprecating their alternative clients.

I don't understand what they are thinking - it used to be such a progressive company.

I don't know about US Government, but many Governments and sensitive organisations are still using VMware, and this isn't likely to change.

Re: Two more Flash 0-days emerge in Hacking Team leak

#142
post #94
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

If there were actually a government body that cared about "cyber"-security, they'd be hauled up in front of it. They're basically an infosec Bhopal - creating a toxic mess that other people have to clean up over a period of decades.

>They're basically an infosec Bhopal

I lul'd.

Re: Two more Flash 0-days emerge in Hacking Team leak

#143
post #58

Earlier quoted context omitted.

Why don't you 100% blame the people at fault: Adobe / the original developers. First, they were incompetent enough to not correctly develop their software. Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) T…

Bug bounties are sensible, but price-matching seems too easy to game. How can the company know a bid is serious, and not just fake to be matched? "Oh, sure, so-and-so offered $200k for this bug." (For that matter, while reputation is certainly a thing, what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix? Do the typical contracts to sell 0…

> what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix?

People willing to pay 5 or 6-digit sums for a zero-day are likely... not nice. One wouldn't double-cross them willy-nilly. Multiple-sale to multiple third-parties scenarios are likely happening every day, but selling to developers could be considered an act of sabotage against all buyers, so there is no incentive really.

Re: Two more Flash 0-days emerge in Hacking Team leak

#144
post #122
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

How about making police raid homes and forcefully uninstall Flash Player?

Why waste money on police raids when you can exploit Flash to put "malware" on their computer that uninstalls Flash?

Re: Two more Flash 0-days emerge in Hacking Team leak

#145
post #99

Earlier quoted context omitted.

Flash is big - video, audio, animation, browser hooks, filesystem access, etc. - and while Flash has been around for decades the code in the current iteration mostly hasn't been.

Being big is not an excuse for being terrible at security. If they can't secure a big thing, then maybe they should stop building them so big?

They have stopped building Flash.

Re: Two more Flash 0-days emerge in Hacking Team leak

#146

Earlier quoted context omitted.

Speak for yourself. YouTube's HTML5 video player has always been stellar for me.

Are you sure you're actually using the HTML5 player? I am being 100% serious when I say I've never met someone before who thinks YouTube's HTML5 player is good. Among the various issues I've seen: * Sometimes refuses to play anything, without showing any errors, requiring a reload of the page. * Occasional poor performance. * Audio/video desynchronization * Scrubbing the video often causes it to get stuck, refusing t…

I am not the person you are replying to but I do not have flash installed on my system. I have to do an occasional reload but I've never had to do anything else you have mentioned.

For reference, I use chromium (not chrome) on Linux (which does not come with flash bundled).

Re: Two more Flash 0-days emerge in Hacking Team leak

#147
post #66
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

You think that any other software you use is any better? Flash gets it rough because it's widely used and independent of the browser (for the most part). If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people. If you're the kind of person that's going to get specifically targeted, then you should…

Flash "auto updates" are anything but.

On Windows, you get a pop-up to update manually, which just sends you to their website so you need to download and run the installer by yourself.

If you don't update manually, Flash will wait 45 days before triggering an automatic update. I never waited that long, so I don't know whether it's "silent" or not.

Re: Two more Flash 0-days emerge in Hacking Team leak

#148

Earlier quoted context omitted.

Speak for yourself. YouTube's HTML5 video player has always been stellar for me.

Are you sure you're actually using the HTML5 player? I am being 100% serious when I say I've never met someone before who thinks YouTube's HTML5 player is good. Among the various issues I've seen: * Sometimes refuses to play anything, without showing any errors, requiring a reload of the page. * Occasional poor performance. * Audio/video desynchronization * Scrubbing the video often causes it to get stuck, refusing t…

Yes, I'm using the HTML5 player. This is easily verified by clicking the right mouse button on the video and seeing the HTML5 context menu. I have no problems with it at all and it's easily superior to the Flash player in performance and resource usage. It also seamlessly plays 1080p 60FPS video without any issues.

As for the issues you're experiencing - are you sure you have GPU acceleration turned on?

I'm using Chrome and CPU usage is only 45-50% for perfect 1080p 60FPS playback.

Re: Two more Flash 0-days emerge in Hacking Team leak

#149
post #84

Earlier quoted context omitted.

v4 is a long way from being a stable release

wtf are you complaining for? You don't like flash and they are removing it.

ubnt has a habit of not finishing what they start. AirControl 2 is not finished and they're talking about Aircontrol 3. Airvision has been rewritten 3 times in 3 years.

For all I know they're doing Unifi 5 in pure flash. I wouldn't be surprised.

Re: Two more Flash 0-days emerge in Hacking Team leak

#150

https://twitter.com/BrendanEich/status/619876135623618560

My Macbook kernel panics and force-reboots itself because of a bug in some newer Firefox browser feature(s) which are used by a JS-based GBA emulator which was trending on HN yesterday. I can consistently duplicate the kernel panic by resizing the browser window while the emulator is running. I've never in my life experienced such a catastrophic bug from a Flash demo.

At worst, such a devastating bug has a decent chance of harboring its own RCE which has yet to be discovered or disclosed; at best, it's one of the most extreme local DOS attacks that a webpage could possibly launch against a client.

Just because it's much more trendy to bash Adobe than it is to bash Firefox doesn't mean that Firefox's problems are nonexistent.

Firefox RCE found on January 20, 2015: https://community.rapid7.com/community/metasploit/blog/2015/...

Firefox RCE found on February 25, 2015: https://msisac.cisecurity.org/advisories/2015/2015-018.cfm

Firefox RCE found on March 1, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-3...

Firefox RCE found on April 22, 2015: https://msisac.cisecurity.org/advisories/2015/2015-046.cfm

etc.

Pot calling the kettle black.

Post reply on HN