Google releases a fix for flash, before Adobe
securitywatch.pcmag.com
Google releases a fix for flash, before Adobe
1–10 of 32 posts
Re: Google releases a fix for flash, before Adobe
#2Re: Google releases a fix for flash, before Adobe
#3[deleted]
its still by far the single most installed desktop runtime.
Re: Google releases a fix for flash, before Adobe
#4[deleted]
Re: Google releases a fix for flash, before Adobe
#5Re: Google releases a fix for flash, before Adobe
#6What if they have detected black hats exploiting the vulnerability. Should they sit on a fix?
What if they were building their own implementation of a programming language or tool. For example, what if they found a bug in JS that could be used to exploit browsers. Arethey allowed to fix the implementation in V8 or must they sit on it until everyone else patches JS in their browsers?
(These are sincere questions, not rhetoric. I am not a security professional, and I am fully aware that some things are more complicated in practice than they may appear from the comfort of an arm chair.)
Re: Google releases a fix for flash, before Adobe
#7So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability? What if they have detected black hats exploiting the vulnerability. Should they sit on a fix? What if they were building their own implementation of a programming language or tool. For example, what…
So it's not as if there's an widely accepted principal of "patch as quickly as possible". There are tens, probably even hundreds, of terribly severe remote code execution bugs known to major vendors and not yet patched. Patching takes time and money. It's not instantaneous.
It is somewhat widely accepted that if people are actively exploiting a vulnerability, it should be disclosed. But if there were known exploits for this vulnerability, chances are Adobe wouldn't be sitting on the fix.
Re: Google releases a fix for flash, before Adobe
#8[deleted]
not for many, many, many years : http://www.adobe.com/products/player_census/flashplayer/vers... its still by far the single most installed desktop runtime.
Flash is likely the single most installed software in the world. Consider how many Windows, Mac, and Linux desktops and Android devices have Flash.
Re: Google releases a fix for flash, before Adobe
#9The only new thing here is the staggered updates. This article takes the stance that this is a bad practice, and operates off of the assumption that malicious users will use the patch to create an exploit. The flip side is, of course, that there already is an exploit in the wild and now chrome users are safe.
The reality of the situation is that both are true. Someone malicious already has the 0day and someone is going to reverse engineer the patch. You'll never know which is the better option short of scanning every single.swf, trafficked over every protocol on the internet to do a statistical analysis of the incidence rate prior to releasing the patch as well as attempting to predict how many new malicious swfs will pop up after the patch before adobe releases. Oh and predict the patch application rate, as well as the probability of exploited users along the long tail.
Oh, and thats only if your definition of "best" is least users compromised.
What about the relative value of targets as a factor in determining which patch release strategy is the better option. The RSA attack used a flash exploit embedded in an xls. Is 500 patched boxes at a hypothetical-RSA averting an attack worth 500,000 grandmas slow on the upgrade train compromised?
Welcome to the world of responsible disclosure. Its easy to understand how to maximize damage, minimizing it damn tricky.
Re: Google releases a fix for flash, before Adobe
#10So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability? What if they have detected black hats exploiting the vulnerability. Should they sit on a fix? What if they were building their own implementation of a programming language or tool. For example, what…
Just to be clear: while reasonable people can disagree about patch and disclosure timing, the point that this article makes isn't a fringe point. Virtually every vulnerability researcher goes through some kind of elaborate dance with vendors to coordinate the safest reasonable release of bugs and patches. So it's not as if there's an widely accepted principal of "patch as quickly as possible". There are tens, probabl…
The moment one of the vulnerabilities is found “in the wild," the patch is automatically pushed into the wild, Adobe be damned.