Live data from Hacker News

Two more Flash 0-days emerge in Hacking Team leak

theregister.co.uk

81–90 of 193 posts

Re: Two more Flash 0-days emerge in Hacking Team leak

#81
post #28

Earlier quoted context omitted.

What websites use it? I've not encountered a single incompatible website recently, and haven't had flash installed for a long time now.

BBC iPlayer is flash-only

Not just iPlayer - the main BBC website - including news/weather/sport - requires Flash to display all video content on desktops.

Re: Two more Flash 0-days emerge in Hacking Team leak

#82
post #51

Earlier quoted context omitted.

Ubiquiti products require it for some functionality, and they're wildly popular for Wifi and wireless ISPs right now. I actually just filed a complaint on their forums. http://community.ubnt.com/t5/UniFi-Wireless/BUG-Adobe-Flash-...

What ubnt products require flash? airOS works fine for me without flash.

Unifi 3.x requires flash to manage devices on a map. It's the main screen you see when you log in.

Unifi 4.x is still beta and I'm not sure if it still requires flash (Though for Ubnt stable means beta, beta means alpha, alpha is unlikely to even run.)

Last I checked AirControl did too (managing many AirOS devices)

Re: Two more Flash 0-days emerge in Hacking Team leak

#83
post #53

Flash is decades old, not that big, and still has use-after-free vulnerabilities? Tools for catching those have been widely available for years. That makes one suspect those vulnerabilities aren't there by accident. We need public disclosure of the code check-in that created the bug, with names. People need to be fired for this.

Work on a massive decades old software project and get ready to have your eyes opened. All the automated static and dynamic software analyzers catch only the easiest flaws, but can catch the more serious ones only if you're skilled and lucky.

Firing people for software bugs is the stupidest thing I've heard in a while. Everyone writes horrific software flaws. Everyone. The best of the best programmers just write less of them. Firing people for bugs is a job perk that will only motivate any good developers to find a less stupid employer as soon as possible.

Re: Two more Flash 0-days emerge in Hacking Team leak

#84
post #77
post #51

Earlier quoted context omitted.

Ubiquiti products require it for some functionality, and they're wildly popular for Wifi and wireless ISPs right now. I actually just filed a complaint on their forums. http://community.ubnt.com/t5/UniFi-Wireless/BUG-Adobe-Flash-...

Their latest controller (v4?) removed the Flash requirement for both video (playback) and main (maps) IIRC. Do they still have leftover areas that require Flash?

v4 is a long way from being a stable release

Re: Two more Flash 0-days emerge in Hacking Team leak

#85

does Chrome and Firefox automatically update the Flash? I can't turn it off because...well lot of video sites made for men that are not Youtube or Twitch but more popular than Vimeo ever will be, requires flash.

Use youtube-dl, or mpv with youtube-dl. It can fetch videos from many adult sites without using flash.

Re: Two more Flash 0-days emerge in Hacking Team leak

#86
post #74
post #6

Serious question: why are people still using Flash? I'm surprised by the number of websites that use it.

I can think of one use case where Flash still makes sense: Live video A lot of people seemed to be surprised this is the case but tell me what single live streaming protocol is supported across all browsers without a plugin? With Flash you can stream HLS (HTTP Live Streaming) to a Flash player in full browsers while just directly loading the same HLS playlist in mobile browsers via native players (iOS / Android). Thi…

Yes except if you want 1080p60 you just won't be able to use Flash because even on fast computers the CPU overhead is killer.

Re: Two more Flash 0-days emerge in Hacking Team leak

#87
post #5

Earlier quoted context omitted.

I'm as grossed out by HT as the next message board nerd, but they didn't develop these bugs; modern industrial software development did. All HT did was weaponize them. These guys aren't the sharpest tools in the shed, so I think you can safely assume other people weaponized these, or worse bugs, as well.

HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…

I do not disagree. In fact, I personally have a problem with all non-vendor vulnerability sales, for the same reason.

I just think we should be clear that exploit developers, brokers, and users don't actually create vulnerabilities; software companies do.

I also think people should give Adobe a little bit of a break --- not much of one, but a little. Adobe got monstrously successful off a codebase that largely predates the concept of software security. It's a nightmare problem for them, and they are working on it. They should work harder.

Re: Two more Flash 0-days emerge in Hacking Team leak

#88
post #46

Earlier quoted context omitted.

Twitch without Flash has been available for a while now, if you were willing to use VLC + an IRC client. Twitch HTML5 chat went live on June 30th, HLS was prior to that. I'd say they're open to ditching Flash.

VLC for HLS I assume (and I only stumbled upon the '/hls' suffix for any url to support that by accident/in that ticket, which still doesn't seem to be officially closed). IRC for chat is absolutely new to me and would actually be quite nice..

http://getchatty.sourceforge.net/

Re: Two more Flash 0-days emerge in Hacking Team leak

#89

Earlier quoted context omitted.

A significant portion of the web using community (including myself) stopped using flash 6-12 months ago, when all the zero-days became a monthly occurrence. The plugin is no longer strategic for adobe, they've stopped any forward-looking development on it, and are now in the mode of whack-a-mole reactive security patching. I have not once every missed having flash on my system. It's not just the case that the web is…

> The plugin is no longer strategic for adobe, they've stopped any forward-looking development on it, and are now in the mode of whack-a-mole reactive security patching. [citation needed]

Citation needed comments are lazy and useless.

Re: Two more Flash 0-days emerge in Hacking Team leak

#90
post #78
post #66

Earlier quoted context omitted.

You think that any other software you use is any better? Flash gets it rough because it's widely used and independent of the browser (for the most part). If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people. If you're the kind of person that's going to get specifically targeted, then you should…

"You think that any other software you use is any better?" I certainly HOPE most software I use can do better than this: http://www.cvedetails.com/vulnerability-list/vendor_id-53/pr... To be certain, Flash gets a lot of attention because of its install base - but it's been a never-ending FOUNTAIN of RCE bugs for much of the last decade.

Most software that's as complex as Flash is probably similarly full of bugs. Most of those vulnerabilities reek of huge development teams toiling over a codebase whose foundation was written in the late 90s and had features and fixes duct taped ever since.
Post reply on HN