Earlier quoted context omitted.
"You think that any other software you use is any better?" I certainly HOPE most software I use can do better than this: http://www.cvedetails.com/vulnerability-list/vendor_id-53/pr... To be certain, Flash gets a lot of attention because of its install base - but it's been a never-ending FOUNTAIN of RCE bugs for much of the last decade.
data: I grabbed all 500+ records and counted, by month, those with severity 10 (column 10) and severity >= 7 (column 7). Rows is the # of cve records for that month. it's not awesome month rows 10 7 2015-07 35 28 29 2015-06 14 7 7 2015-05 17 10 10 2015-04 22 19 19 2015-03 11 7 9 2015-02 19 19 19 2015-01 12 9 11 2014-12 6 5 5 2014-11 19 16 18 2014-10 3 3 3 2014-09 12 11 12 2014-08 8 7 7 2014-07 3 0 2 2014-06 6 1 3 201…
Two more Flash 0-days emerge in Hacking Team leak
171–180 of 193 posts
Re: Two more Flash 0-days emerge in Hacking Team leak
#172Earlier quoted context omitted.
I'm as grossed out by HT as the next message board nerd, but they didn't develop these bugs; modern industrial software development did. All HT did was weaponize them. These guys aren't the sharpest tools in the shed, so I think you can safely assume other people weaponized these, or worse bugs, as well.
HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…
2. If one is the kind of person that thinks that the answer to 1 is no then probably the answer to 2 is no too (sorry if this sounds harsh).
3. Probably an effort proportional to the competitive advantage it gives to you.
Re: Two more Flash 0-days emerge in Hacking Team leak
#173Earlier quoted context omitted.
I was going to agree with you, but I've just double-checked, and you CAN access video content on the BBC sites on a desktop (MacOS X Safari) by setting your User-Agent to iPad. However, it's important that you've removed Flash completely from your system (using Flash Uninstaller), rather than just disable Flash (hoping to use Click-To-Flash). For some reason, they detect Flash by some kind of file-path-detection code…
What horrible browser lets a website inspect the filesystem without permission?
Re: Two more Flash 0-days emerge in Hacking Team leak
#174Earlier quoted context omitted.
Yes, I'm using the HTML5 player. This is easily verified by clicking the right mouse button on the video and seeing the HTML5 context menu. I have no problems with it at all and it's easily superior to the Flash player in performance and resource usage. It also seamlessly plays 1080p 60FPS video without any issues. As for the issues you're experiencing - are you sure you have GPU acceleration turned on? I'm using Chr…
> and it's easily superior to the Flash player in performance and resource usage. Not on older (3y+) machines.
Re: Two more Flash 0-days emerge in Hacking Team leak
#175Earlier quoted context omitted.
No they don't. Chrome is designed from the ground up for security. It has the same number of bugs as other software of it's size but the type of bugs are much less severe. Compare FF, Safari, IE, Chrome. Same number of bugs per yet but Chrome has 10x less code execution bugs (ie, 10x less likely for your machine to be owned by unknown bugs) http://i.imgur.com/rVgu7Fs.png
The chart you just linked (which doesn't show a timescale) shows Chrome with over 300 exploitable bugs. I doubt the denial of service label, that just usually means that a bug wasn't fully investigated. So, again, how is this different from Flash? Chrome is riddled with vulnerabilities (and Safari is too). Flash runs in a low-priv environment is nearly every major browser, includes application-specific exploit mitiga…
Shit, this is the most accurate description of modern software that I've seen so far.
Re: Two more Flash 0-days emerge in Hacking Team leak
#176guess it's time to disable flash for a few weeks...
I've been running without Flash for a couple of years now. The only thing I can't do that I would like to be able to do is to watch Facebook videos. Other than that, not having Flash installed is not a problem for me.
Re: Two more Flash 0-days emerge in Hacking Team leak
#177Earlier quoted context omitted.
If there were actually a government body that cared about "cyber"-security, they'd be hauled up in front of it. They're basically an infosec Bhopal - creating a toxic mess that other people have to clean up over a period of decades.
In essence there are not critical US systems running on Flash and so the defensive side of NSA don't care. And the offensive side is just happy to let it rot, as that means more opportunities for them.
Re: Two more Flash 0-days emerge in Hacking Team leak
#178Earlier quoted context omitted.
How do you get the video to play with HTML5?
Works out of the box on Safari 8 with no Flash installed. Edit: proof: http://i.imgur.com/myfsoNv.png
The HTML5 solution is usually to run DASH via a JS demuxer utilizing MSE.
Re: Two more Flash 0-days emerge in Hacking Team leak
#179Re: Two more Flash 0-days emerge in Hacking Team leak
#180Earlier quoted context omitted.
> and it's easily superior to the Flash player in performance and resource usage. Not on older (3y+) machines.
All such comments about not working flash player on youtube make me think of some kind of adobe shills maybe? Or PEBCK. Unless you have some super lame vidoe card I do not see how one can not make HTML5 player work. My experience: HTML5 player works really well on youtube, been using it for at least a year (well possibly +- couple months) exclusively. No problems after configuration, machine is quite old q6600 cpu th…
> make me think of some kind of adobe shills maybe
Delusions or paranoia may be?