Neat, but not that impressive.
Neat, but not that impressive.
There have been so many vulnerabilities in Adobe Flash one has to wonder if they're deliberate. It's not a large body of code, after all.
Oh, of course it is. A complete scripting runtime engine (ActionScript), support for a boatload of video streaming formats including realtime communication, ...
Firefox clocks in at a healthy ~50 MB, as does Google Chrome, for the offline installers - Chrome expands to ~360MB app size, and Firefox to ~180MB (both current versions on OS X 10.11). I won't even get started on the RAM usage - a typical 10-tab session can easily munch happily through 4 GB RAM and more (especially when there are lots of ads).
It's a pity that a 3-year-old netbook (or cellphone) is basically unusable because browsers creep up so much in featuritis :(
Thank goodness that nightmare is over.
The Flash runtime is big, the API surface is huge and Adobe doesn't feel like it pours a lot of resources into maintenance today. The tech was nice but it should be banned from browsers today.
You shouldn't need any kind of blocking for that, the browser should block it out of the box.
Seems like a single occurrence of "eval" should both fail that automatic review AND be blocked by default in all browsers using default security settings.
I think this just shows that ad networks shouldn't be using js at all. Just dumb images. (Yes I know, no tracking then which makes it useless yada yada - deal with it)
You're not wrong, but there are difficult customers with money to consider.
In google's case I can see the conflict - they both make a browser and live off ads. But apart from that minor issue I don't see why browser vendors don't just block "eval()"?
(Also, they have started blocking flash, thank god - so maybe this will all be a thing of the past soon)
My point is: online ads should become what bus stop ads have always been. You buy a space and display a dumb image. Did it work? You have to do your own A/B testing in half the city. What was it worth? You have to trust those you buy ad space from on how many people read their paper or pass by their bus stop.
Edit: Wikipedia article explains - you can call functions by name with that "filter" thing.
This should be pretty easily blockable though - if you block "eval" then just block most of the obscure jsfuck constructs too.
Obviously what I've just said doesn't help solve any problems here, but thought I'd throw it in there anyway :)
[1] https://docs.angularjs.org/api/ng/type/$rootScope.Scope#$eva...