Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

171–180 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#171
post #120
post #78

Earlier quoted context omitted.

"You think that any other software you use is any better?" I certainly HOPE most software I use can do better than this: http://www.cvedetails.com/vulnerability-list/vendor_id-53/pr... To be certain, Flash gets a lot of attention because of its install base - but it's been a never-ending FOUNTAIN of RCE bugs for much of the last decade.

data: I grabbed all 500+ records and counted, by month, those with severity 10 (column 10) and severity >= 7 (column 7). Rows is the # of cve records for that month. it's not awesome month rows 10 7 2015-07 35 28 29 2015-06 14 7 7 2015-05 17 10 10 2015-04 22 19 19 2015-03 11 7 9 2015-02 19 19 19 2015-01 12 9 11 2014-12 6 5 5 2014-11 19 16 18 2014-10 3 3 3 2014-09 12 11 12 2014-08 8 7 7 2014-07 3 0 2 2014-06 6 1 3 201…

Vulnerabilities increase and usage decreases. I wonder if an economically sensible decision should be to EOL Flash soon. Are they still doing any money out of it?

Re: Two more Flash 0-days emerge in Hacking Team leak

#172
post #5

Earlier quoted context omitted.

I'm as grossed out by HT as the next message board nerd, but they didn't develop these bugs; modern industrial software development did. All HT did was weaponize them. These guys aren't the sharpest tools in the shed, so I think you can safely assume other people weaponized these, or worse bugs, as well.

HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…

1. Yes.

2. If one is the kind of person that thinks that the answer to 1 is no then probably the answer to 2 is no too (sorry if this sounds harsh).

3. Probably an effort proportional to the competitive advantage it gives to you.

Re: Two more Flash 0-days emerge in Hacking Team leak

#173

Earlier quoted context omitted.

I was going to agree with you, but I've just double-checked, and you CAN access video content on the BBC sites on a desktop (MacOS X Safari) by setting your User-Agent to iPad. However, it's important that you've removed Flash completely from your system (using Flash Uninstaller), rather than just disable Flash (hoping to use Click-To-Flash). For some reason, they detect Flash by some kind of file-path-detection code…

What horrible browser lets a website inspect the filesystem without permission?

Browsers give away far too much information: https://panopticlick.eff.org/

Re: Two more Flash 0-days emerge in Hacking Team leak

#174
post #164

Earlier quoted context omitted.

Yes, I'm using the HTML5 player. This is easily verified by clicking the right mouse button on the video and seeing the HTML5 context menu. I have no problems with it at all and it's easily superior to the Flash player in performance and resource usage. It also seamlessly plays 1080p 60FPS video without any issues. As for the issues you're experiencing - are you sure you have GPU acceleration turned on? I'm using Chr…

> and it's easily superior to the Flash player in performance and resource usage. Not on older (3y+) machines.

All such comments about not working flash player on youtube make me think of some kind of adobe shills maybe? Or PEBCK. Unless you have some super lame vidoe card I do not see how one can not make HTML5 player work. My experience: HTML5 player works really well on youtube, been using it for at least a year (well possibly +- couple months) exclusively. No problems after configuration, machine is quite old q6600 cpu that is 5-6 years old and GF220, which is also quite old now. Full hd video ON Linux (!), Firefox no problems (though possibly just 30fps, not sure if I ever try 60fps). And people complain all over the place about HTML5 youtube on Linux.

Re: Two more Flash 0-days emerge in Hacking Team leak

#175
post #161

Earlier quoted context omitted.

No they don't. Chrome is designed from the ground up for security. It has the same number of bugs as other software of it's size but the type of bugs are much less severe. Compare FF, Safari, IE, Chrome. Same number of bugs per yet but Chrome has 10x less code execution bugs (ie, 10x less likely for your machine to be owned by unknown bugs) http://i.imgur.com/rVgu7Fs.png

The chart you just linked (which doesn't show a timescale) shows Chrome with over 300 exploitable bugs. I doubt the denial of service label, that just usually means that a bug wasn't fully investigated. So, again, how is this different from Flash? Chrome is riddled with vulnerabilities (and Safari is too). Flash runs in a low-priv environment is nearly every major browser, includes application-specific exploit mitiga…

> a house of cards built on poor memory management :-/.

Shit, this is the most accurate description of modern software that I've seen so far.

Re: Two more Flash 0-days emerge in Hacking Team leak

#176
post #10
post #4

guess it's time to disable flash for a few weeks...

I've been running without Flash for a couple of years now. The only thing I can't do that I would like to be able to do is to watch Facebook videos. Other than that, not having Flash installed is not a problem for me.

Swap the "www" in the URL for "m" on a video page and you'll get a low resolution HTML5 video!

Re: Two more Flash 0-days emerge in Hacking Team leak

#177
post #94

Earlier quoted context omitted.

If there were actually a government body that cared about "cyber"-security, they'd be hauled up in front of it. They're basically an infosec Bhopal - creating a toxic mess that other people have to clean up over a period of decades.

In essence there are not critical US systems running on Flash and so the defensive side of NSA don't care. And the offensive side is just happy to let it rot, as that means more opportunities for them.

But "thanksfully" they've switched to WordPress on the Whitehouse site and hired the maintainer , so they are improving netsec on THAT front. :) Which is actually a good thing for hosters worldwide.

Re: Two more Flash 0-days emerge in Hacking Team leak

#178
post #70

Earlier quoted context omitted.

How do you get the video to play with HTML5?

Works out of the box on Safari 8 with no Flash installed. Edit: proof: http://i.imgur.com/myfsoNv.png

It's using HLS, so not really HTML5 but an Apple specific proprietary extension.

The HTML5 solution is usually to run DASH via a JS demuxer utilizing MSE.

Re: Two more Flash 0-days emerge in Hacking Team leak

#179
post #70

Earlier quoted context omitted.

How do you get the video to play with HTML5?

Works out of the box on Safari 8 with no Flash installed. Edit: proof: http://i.imgur.com/myfsoNv.png

Wonder if they'll ever ad support for Firefox.

Re: Two more Flash 0-days emerge in Hacking Team leak

#180
post #164

Earlier quoted context omitted.

> and it's easily superior to the Flash player in performance and resource usage. Not on older (3y+) machines.

All such comments about not working flash player on youtube make me think of some kind of adobe shills maybe? Or PEBCK. Unless you have some super lame vidoe card I do not see how one can not make HTML5 player work. My experience: HTML5 player works really well on youtube, been using it for at least a year (well possibly +- couple months) exclusively. No problems after configuration, machine is quite old q6600 cpu th…

Fine. I cannot argue about _your_ experience. _My_ experience is different. One of my computers is really old Pentium M laptop (9y old) and HTML5 barely works at 240p. Not only that, it has limited set of resolutions at the first place. Flash works just fine 480p resolution. It looks also much better at lower bitrates (to _my_ taste) than HTML5 in Firefox

> make me think of some kind of adobe shills maybe

Delusions or paranoia may be?

Post reply on HN