Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

181–190 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#181
post #106

For me there are generally 3 steps to the process of watching a youtube video. 1. Get the video id. Retrieve HTML containing youtube /watch?v= urls or other urls that contain the video id. Extract the urls from the HTML or other markup garbage. 2. Retrieve the video. Feed the /watch?v= url to a script that does some "find and replace" on the absurdly long googlevideo urls. Below I have given an example of such a scri…

holy crap that is convoluted I simply use mplayer and javascript oneliner extracting direct mp4 link from YouTubeCenter plugin = streaming video in mplayer without downloading.

Q: "... why aren't you using youtube-dl?"

A: "holy crap that is convuluted"

I do not use Python nor a Javascript-enabled web browser to download video.

Both are big, convoluted, slow(!) and unnecessary.

But I do agree with using mplayer for playback.

Re: Two more Flash 0-days emerge in Hacking Team leak

#182
post #4

guess it's time to disable flash for a few weeks...

A significant portion of the web using community (including myself) stopped using flash 6-12 months ago, when all the zero-days became a monthly occurrence. The plugin is no longer strategic for adobe, they've stopped any forward-looking development on it, and are now in the mode of whack-a-mole reactive security patching. I have not once every missed having flash on my system. It's not just the case that the web is…

>A significant portion of the web using community (including myself) stopped using flash 6-12 months ago

That seems unlikely. Maybe HN users, but that's not really representative of web users overall

Re: Two more Flash 0-days emerge in Hacking Team leak

#183

Important PSA for Skype Users: Open up "Internet Options" (yes, the ones in internet explorer), security tab, and add https://apps.skype.com to the "Restricted Sites" list. Skype will still work fine, however there will be no advertisements. This is important because Microsoft seems to use a lot of Flash advertisements without checking them (I've had plenty of "MICROSOFT VERIFIED DRIVER FIXING" ads come up inside of…

Skype on Windows has ads? Is that a recent thing? The Mac version doesn't, or not yet, anyway.

The OS X version now has ads, but only on certain pages. Highly annoying. This was one of the historical differentiators.

Re: Two more Flash 0-days emerge in Hacking Team leak

#184
post #94
post #23

I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.

If there were actually a government body that cared about "cyber"-security, they'd be hauled up in front of it. They're basically an infosec Bhopal - creating a toxic mess that other people have to clean up over a period of decades.

Can we get Adobe declared a Superfund clean up site?

Re: Two more Flash 0-days emerge in Hacking Team leak

#185

Earlier quoted context omitted.

HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…

1. Yes. 2. If one is the kind of person that thinks that the answer to 1 is no then probably the answer to 2 is no too (sorry if this sounds harsh). 3. Probably an effort proportional to the competitive advantage it gives to you.

Why not an effort proportional to the damage to affected parties if such an exploit were to be stolen?

Re: Two more Flash 0-days emerge in Hacking Team leak

#186
post #53

Flash is decades old, not that big, and still has use-after-free vulnerabilities? Tools for catching those have been widely available for years. That makes one suspect those vulnerabilities aren't there by accident. We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.

People need to be fired for this

This comment was heavily voted down a day or so ago (not by me, I voted it up). But just now I'm reading about yet another zero-day, this time against Java.

So the question is, when are we going to get disgusted, sick and tired of all this sloppy code? When will "heads will roll for this" revert to being a meaningful punishment instead of just a historic cliche?

Enough is enough! If there are no consequences there will be no improvement.

Re: Two more Flash 0-days emerge in Hacking Team leak

#188
post #180

Earlier quoted context omitted.

All such comments about not working flash player on youtube make me think of some kind of adobe shills maybe? Or PEBCK. Unless you have some super lame vidoe card I do not see how one can not make HTML5 player work. My experience: HTML5 player works really well on youtube, been using it for at least a year (well possibly +- couple months) exclusively. No problems after configuration, machine is quite old q6600 cpu th…

Fine. I cannot argue about _your_ experience. _My_ experience is different. One of my computers is really old Pentium M laptop (9y old) and HTML5 barely works at 240p. Not only that, it has limited set of resolutions at the first place. Flash works just fine 480p resolution. It looks also much better at lower bitrates (to _my_ taste) than HTML5 in Firefox > make me think of some kind of adobe shills maybe Delusions o…

It was far less personal than that, I generaly only lurk on HN, but your post one that struck a nerve finaly, after many similar posts here and in /..

Also 9 year old is quite a frac cry from your initial post of "(3y+) machines", 9 year old machine almost guaranteed has absolutely no support in hardware for modern codecs. So no wonder has strong limitations on resolution. Still flash working better than HTML5 players is still suspicious to me, I still believe with correct configuration reverse should be true, as flash is basically just another layer in between screen and bits on the net. Though possibly not applicable in all cases.

Re: Two more Flash 0-days emerge in Hacking Team leak

#189
post #180

Earlier quoted context omitted.

Fine. I cannot argue about _your_ experience. _My_ experience is different. One of my computers is really old Pentium M laptop (9y old) and HTML5 barely works at 240p. Not only that, it has limited set of resolutions at the first place. Flash works just fine 480p resolution. It looks also much better at lower bitrates (to _my_ taste) than HTML5 in Firefox > make me think of some kind of adobe shills maybe Delusions o…

It was far less personal than that, I generaly only lurk on HN, but your post one that struck a nerve finaly, after many similar posts here and in /.. Also 9 year old is quite a frac cry from your initial post of "(3y+) machines", 9 year old machine almost guaranteed has absolutely no support in hardware for modern codecs. So no wonder has strong limitations on resolution. Still flash working better than HTML5 player…

9y old machines is what many people (not gamers, enthusiasts etc.) have; 3+ y old include underpowered Celeron 847, AMDs (way weaker than your monstrous Q6600) and even on these machines Flash works better. _My_ _actual_ observations.

> Still flash working better than HTML5 players is still suspicious to me,

Do you write programs for life or what? It is not a problem with HTML5 players, it a problem the way they are written. Flash is an older product, with better support of legacy or underpowered products.

> I still believe with correct configuration reverse should be true

Yes, the correct configuration is "more powerful CPU".

Re: Two more Flash 0-days emerge in Hacking Team leak

#190
post #83

Earlier quoted context omitted.

Work on a massive decades old software project and get ready to have your eyes opened. All the automated static and dynamic software analyzers catch only the easiest flaws, but can catch the more serious ones only if you're skilled and lucky. Firing people for software bugs is the stupidest thing I've heard in a while. Everyone writes horrific software flaws. Everyone. The best of the best programmers just write less…

All the automated static and dynamic software analyzers catch only the easiest flaws In a 64-bit environment, at least for development purposes, why can't every single malloc() cause an allocation from new memory page(s)? Then free() removes the page(s) from accessible virtual memory. Too much overhead for production, but it would sure catch a lot of use-after-free bugs during development. Is nobody doing something l…

Wait, you mean like _CRTDBG_DELAY_FREE_MEM_DF which will just mark freed blocks as freed and inaccessible? https://msdn.microsoft.com/en-us/library/5at7yxcs.aspx
Post reply on HN