Earlier quoted context omitted.
Most software that's as complex as Flash is probably similarly full of bugs. Most of those vulnerabilities reek of huge development teams toiling over a codebase whose foundation was written in the late 90s and had features and fixes duct taped ever since.
Do Chrome and Safari have as bad a track record? Flash has been insecure since originally launched.
Two more Flash 0-days emerge in Hacking Team leak
131–140 of 193 posts
Re: Two more Flash 0-days emerge in Hacking Team leak
#132Earlier quoted context omitted.
A lot of advertising networks use it to deliver advertisements. Whether it is simple inertia at this point, or because the networks can get a better fingerprint using flash, I don't know. Also, it used to be the case that Flash had better DRM controls on it, but I'm pretty sure that reason is no longer the case since Encrypted Media Extensions got rolled out. However, that doesn't explain why Facebook's on-site video…
Facebook appears to have moved to an html player in the last few days.
Not only that, but images flagged as "gif" also prompt me to install flash (amazing how oddly these new features get implemented!).
Re: Two more Flash 0-days emerge in Hacking Team leak
#133Earlier quoted context omitted.
Bug bounties are sensible, but price-matching seems too easy to game. How can the company know a bid is serious, and not just fake to be matched? "Oh, sure, so-and-so offered $200k for this bug." (For that matter, while reputation is certainly a thing, what stops a security researcher from selling the same 0-day to several different buyers, and then selling it to the company to fix? Do the typical contracts to sell 0…
How about an escrow contract using a third party and bitcoin? You could call it silk road 3 Its really not that hard to be taken for a ride if you have the resource adobe does.
Re: Two more Flash 0-days emerge in Hacking Team leak
#134For me there are generally 3 steps to the process of watching a youtube video. 1. Get the video id. Retrieve HTML containing youtube /watch?v= urls or other urls that contain the video id. Extract the urls from the HTML or other markup garbage. 2. Retrieve the video. Feed the /watch?v= url to a script that does some "find and replace" on the absurdly long googlevideo urls. Below I have given an example of such a scri…
Re: Two more Flash 0-days emerge in Hacking Team leak
#135Re: Two more Flash 0-days emerge in Hacking Team leak
#136What are the people doing now who formerly developed Flash? Are they all diesel mechanics and baristas or what? I wouldn't even considering calling back a candidate why had Macromedia on their work history.
And I wouldn't even sort of consider hiring or even working with anyone that thinks work experience in a language makes them a liability.
Re: Two more Flash 0-days emerge in Hacking Team leak
#137I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.
You think that any other software you use is any better? Flash gets it rough because it's widely used and independent of the browser (for the most part). If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people. If you're the kind of person that's going to get specifically targeted, then you should…
Re: Two more Flash 0-days emerge in Hacking Team leak
#138I would like to hear what Adobe have to say about their streak of serious security problems. Not only that, but they should face some consequences for that neglect. At least be forced to publish a working spec for Flash.
Should we also ask what Microsoft has to say about their consistent streak of serious security problems in IE and Windows?
Re: Two more Flash 0-days emerge in Hacking Team leak
#139Earlier quoted context omitted.
You think that any other software you use is any better? Flash gets it rough because it's widely used and independent of the browser (for the most part). If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people. If you're the kind of person that's going to get specifically targeted, then you should…
Flash gets it rough because it's horribly-written software full of security holes . It's demonstrably worse than most anything else out there.
Re: Two more Flash 0-days emerge in Hacking Team leak
#140Earlier quoted context omitted.
This is like asking why people still use cash when there are so many other easier to use & manage payment options. The simple answer is there are far too many edge cases where it's still required - any single one doesn't sound like a good answer.
Cash is still the most anonymous way to pay for something also, at least for most people.