Live data from Hacker News

Google releases a fix for flash, before Adobe

securitywatch.pcmag.com

1–10 of 32 posts

Re: Google releases a fix for flash, before Adobe

#4
post #2

[deleted]

Apple and MS are pushing plugin-free browsers for their mobile browsers. Safari and IE both allow plugins on their desktops browsers (hence why Flash works on both). Even on Windows 8, you can still use plugins in the non-Metro version of IE 10.

Re: Google releases a fix for flash, before Adobe

#5
Google probably didn't do it for fun but rather because it was being exploited in the wild and they were unwilling to delay protection for their users. As a user I appreciate this. Adobe needs to get their patch cycle and updating to Google's level ASAP.

Re: Google releases a fix for flash, before Adobe

#6
So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability?

What if they have detected black hats exploiting the vulnerability. Should they sit on a fix?

What if they were building their own implementation of a programming language or tool. For example, what if they found a bug in JS that could be used to exploit browsers. Arethey allowed to fix the implementation in V8 or must they sit on it until everyone else patches JS in their browsers?

(These are sincere questions, not rhetoric. I am not a security professional, and I am fully aware that some things are more complicated in practice than they may appear from the comfort of an arm chair.)

Re: Google releases a fix for flash, before Adobe

#7

So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability? What if they have detected black hats exploiting the vulnerability. Should they sit on a fix? What if they were building their own implementation of a programming language or tool. For example, what…

Just to be clear: while reasonable people can disagree about patch and disclosure timing, the point that this article makes isn't a fringe point. Virtually every vulnerability researcher goes through some kind of elaborate dance with vendors to coordinate the safest reasonable release of bugs and patches.

So it's not as if there's an widely accepted principal of "patch as quickly as possible". There are tens, probably even hundreds, of terribly severe remote code execution bugs known to major vendors and not yet patched. Patching takes time and money. It's not instantaneous.

It is somewhat widely accepted that if people are actively exploiting a vulnerability, it should be disclosed. But if there were known exploits for this vulnerability, chances are Adobe wouldn't be sitting on the fix.

Re: Google releases a fix for flash, before Adobe

#8
post #3
post #2

[deleted]

not for many, many, many years : http://www.adobe.com/products/player_census/flashplayer/vers... its still by far the single most installed desktop runtime.

> its still by far the single most installed desktop runtime.

Flash is likely the single most installed software in the world. Consider how many Windows, Mac, and Linux desktops and Android devices have Flash.

Re: Google releases a fix for flash, before Adobe

#9
This is another area of the disclosure debate that will never get solved.

The only new thing here is the staggered updates. This article takes the stance that this is a bad practice, and operates off of the assumption that malicious users will use the patch to create an exploit. The flip side is, of course, that there already is an exploit in the wild and now chrome users are safe.

The reality of the situation is that both are true. Someone malicious already has the 0day and someone is going to reverse engineer the patch. You'll never know which is the better option short of scanning every single.swf, trafficked over every protocol on the internet to do a statistical analysis of the incidence rate prior to releasing the patch as well as attempting to predict how many new malicious swfs will pop up after the patch before adobe releases. Oh and predict the patch application rate, as well as the probability of exploited users along the long tail.

Oh, and thats only if your definition of "best" is least users compromised.

What about the relative value of targets as a factor in determining which patch release strategy is the better option. The RSA attack used a flash exploit embedded in an xls. Is 500 patched boxes at a hypothetical-RSA averting an attack worth 500,000 grandmas slow on the upgrade train compromised?

Welcome to the world of responsible disclosure. Its easy to understand how to maximize damage, minimizing it damn tricky.

Re: Google releases a fix for flash, before Adobe

#10
post #7

So is the argument that Google should leave the vulnerability unpatched in its own browser until Adobe get around to patching it in their plugin for other browsers, so as not to publicize the existence of a vulnerability? What if they have detected black hats exploiting the vulnerability. Should they sit on a fix? What if they were building their own implementation of a programming language or tool. For example, what…

Just to be clear: while reasonable people can disagree about patch and disclosure timing, the point that this article makes isn't a fringe point. Virtually every vulnerability researcher goes through some kind of elaborate dance with vendors to coordinate the safest reasonable release of bugs and patches. So it's not as if there's an widely accepted principal of "patch as quickly as possible". There are tens, probabl…

I’m idly imagining a massive Google HoneyFarm with browsers that examine payloads from known “harmful sites” and spam or phishing emails.

The moment one of the vulnerabilities is found “in the wild," the patch is automatically pushed into the wild, Adobe be damned.

Post reply on HN