If your business depends on Flash, have an exit plan ready
davidverhasselt.com
davidverhasselt.com
I thought flex was great. I really did. The funny thing is I used to do a bunch of cold fusion work back in the day so I already had firsthand experience with Adobe's complete lack of interest in supporting a developer platform. All I have to say is "allaire homesite", most CFdevs should remember.
Nevertheless I got involved a handful of huge flex applications. This was back when it was Apollo, so 07/08. Firefox was gaining traction but not much, Jquery didn't really exist and google was for searching, not web browsing.
These apps looked beautiful, every pixel was accounted for, they were responsive(ish) and, the best part, when they were done they were DONE (mostly). No more trying to support IE5.5 or IE6. Flex was something you could sell to an enterprise shop.
Then native technologies finally caught up. The IPhone, perhaps rightly so, gave a huge middle finger to Adobe. Then JQuery, then Bootstrap comes into the picture and... amazingly... the shit actually works. Seriously, this is not expected behavior when dealing with html/css/js libraries.
Flex was really just a means to an end. For devs like me it meant I didn't have to code another $#@! table layout or drop-down-select or menu-navigation or accordion.
On one hand I feel the industry caught up to Flex and the better player (native support) won. I feel that I shouldn't personally blame Adobe on this one. On the other hand I know that Adobe has killed off so much through their process of atrophy-driven-development that I can't help but want to point a (very specific) finger at them.
Eh, yeah, at this point when I hear Adobe I walk away, I can't blame them for everything, but I've lost all faith in their ability to deliver.
People learning html/js/css today have no idea how incredible they have it. They don't even have to think about IE compatibility!
I used a lazy evaluation strategy for my life: in 2007 after it became clear to me how ... well, awful ... the webdev technologies were, I switched fields for a few years. And hey, presto, now in 2013 everything works. And works well! I can be a web developer with about 1/3rd of the effort it would've taken me in '07.
EDIT: Actually, after spending a few minutes remembering what those times were like, I'd say nowadays it's a lot more than 3x easier. It's now at least 10x easier to write webapps, if not 30x.
The vast majority of one's time was spent hacking around various unexpected behaviors and incompatibilities.
I wonder too if being around before jQuery took the prize has something to do with why I hesitate with new technologies, especially when so many try to fill the same need. Had I not picked jQuery I would have had to rewrite everything in whatever had caught on.
So yes, you're absolutely right; they are so lucky to have missed those dreary times.
But there are new areas that inspire a kill-me-now reaction. If you've tried to do anything serious with controlling HTML5 audio via JavaScript, for example -- it's a nightmarish maze of different commands and event names and varying functionalities and crashing bugs that vary from browser to browser and version to version.
All that data binding and event bubbling was convenient for the developer, but you certainly paid a price for it at runtime. Most of the Flex apps I encountered during that time period (even very simple ones) just seemed to run so sluggishly. That type of user experience might have been okay for internal corporate type applications but I never really found it suitable for the web. And of course on top of that you had to deal with the SWF loading times too.
Flash/Flex definitely had its time in the spotlight but I can see why it ended up dying out.
It's frustrating, Adobe make really useful products that hover on the edge of greatness - Director, Flash, Coldfusion, Air - then somehow seem to lose interest right before they break through. I mean, if Adobe had of lifted even one finger to work with Apple, then Flash might have had a bright future in front of it. As it stands, Adobe stood stupidly chewing their cud in usual fashion until El Jobsy gave up.
In some ways, I regret every one of the many hours I have put into learning Adobe dev platforms; on the brightside, their BS pushed me straight into the arms of OSS.
True. Another problem is, they now seem to not care about users either, with the possible exception of large design studios.
The CC subscriptions are fucking over customers who used to skip a version or two (now they have to constantly pay up or they lose their CC programs), and they also fuck people that don't need all of CC but a few choice programs (you either fit with their pre-defined bundles or you're screwed if you need access to only a few programs: after 2 programs, it gets cheaper to buy the whole suite, even if you don't need it).
I'd appreciate a full_suite_price/number_of_components base pricing for a single program (with a slightly larger weight for star programs like Photoshop and Premierre), instead of the current "need 3-4 programs? Sorry, you have to rent the whole thing").
Plus the non-US Creative Cloud pricing is a joke. The formula seems to be: take the US price, add any local taxes (legit) and hike it another 30-40% just because.
>It's frustrating, Adobe make really useful products that hover on the edge of greatness - Director, Flash, Coldfusion
Hmm, all of those were made my Macromedia (Cold Fusion by Allaire and then Macromedia).
True, although they maintained a lot of momentum after the acquisition. But maybe that's the answer - perhaps Adobe slowly starved the dev platform teams to death whilst rolling in all the filthy lucre from the design products.
What sucks is that for media creation apps, Adobe still has untouchable quality. Nothing even comes close (sorry Gimp, RIP Freehand), except maaaybe Final Cut or Vegas for simple editing.
It's still in early-early-early-beta but it's the first product I looked at and thought "woah, there's something that is actually interesting in the design space".
I've seen other awesome specialist "arty" apps like this, but nothing for general use. Photoshop has incredible breadth and depth, I've been using it for 15 years and I still stumble across hidden corners.
Corel Draw is the only app I've ever seen seriously compete, and it wasn't really in the same league - I could be wrong, I never spent a long time with it. Gimp really is a toy by comparison. (Sorry Gimp.)
PS: Been playing around with Flash since Flash 4! (was a wee little kid back then). Pretty much learning programming from actionScript. So it really does break my heart to see that Adobe is letting it die
I don't disagree with the author as we are now 90% html5, and 10% flash, but the flash version has worked without issue over the last 200 updates to the flash plugin. I have a feeling our app is going down some C++ code path that is never going to get modified because it is a giant shit pile that no one understands. The good news is that it will probably work forever.
It was in fact a giant and difficult to understand and overly abstracted piece of shit. But it mostly worked and a lot of the horrible abstractions helped it be wildly backward compatible.
If there's a better solution I'd love to hear it, since this wouldn't work on iOS devices afaik.
http://caniuse.com/#search=web%20audio
If you want a nice abstraction library, check out howler http://goldfirestudios.com/blog/104/howler.js-Modern-Web-Aud...
as for IE support, well, there's not really that much risk in using soundmanager/flash if you still need to support 7 and 8, is there? I even discovered that old MS even exposed some nice windows media activex controls that you can use to do simple sound playing stuff without loading up a flash plugin, if you're that serious about backwards compatibility.
Forget a year from now. You can start using this stuff today, and by the time you release a year from now, things will be even better.
http://www.theguardian.com/technology/2011/nov/09/adobe-flas...
http://www.adobe.com/devnet/air.html
I used it myself for a small project a year ago and was well pleased. I find that Flash has such a PR stigma now that developers don't even admit to using it. I unbundled an app I use occasionally just the other day cause it smelled a little Flash-ey...what do you know, it was!
They actually have trusted customers that they share the Flash source code with: Google and Mozilla both have it, for instance.
And it's not an easy call to make: keep in mind how many computers have Flash installed. If open sourcing the project would double the rate that vulnerabilities get found and exploited, that's a real problem for Adobe.
Trusted partners already have the Flash code and report security issues.
Basically, open source makes it easier to find security bugs, but that's no help if you already have your hands full with the ones you can find yourself. I don't know if Flash is in that state, but it kind of sounds like it.
It's already dead, it just hasn't hit the ground yet.
Imagine that the features that make Flash useful were added to browsers without the need for a plugin. That's what's been happening. The process hasn't completed yet, but it will, give it time. It takes time because standards bodies move slowly etc. etc.
At that point, who prefers Flash to the standard? Nobody. Not developers, not users, not even Adobe -- who is only in it to sell software, which they can sell just as well if the output is HTML as if the output is SWF. It even benefits them to kill Flash (the plugin), because then they don't have to maintain it anymore. Everyone would be happy to have Mozilla do that part instead.
So you say, fine, open source Flash, make that the standard everyone is converging on so we don't have to wait. Ignore for a moment the probable licensing issues Adobe would have in doing that if they've licensed anything from anyone for use in Flash. Ignore the wailing you would hear from Hollywood if the "DRM"/obfuscation they think they get from Flash were to be made transparent by releasing the source code. Who actually wants the plugin?
The features that Flash provides would work better if they were properly integrated into the browser. But doing that requires you to rewrite the code as part of the browser instead of a plugin -- which you want to do anyway because as we all know the Flash plugin is a dungeon of sorrow and despair. But if you have to rewrite it in any event then what good is having it? You just throw it away and start over as you would anyway.
So Flash is dead. All that releasing the code would get you is to extend the period of time that we spend lugging around its corpse in the passenger's seat pretending it might wake up again. If you really want to do something productive, find a feature in Flash that isn't in HTML and submit a patch implementing it to Mozilla and Chromium. Shipping code wins -- implement it and people will use it, and implement it the same in two major browsers and the other will follow and standardize it. The sooner that happens the sooner Flash can disappear and make everyone the happier for it.
No, I don't see any benefit in it as a standard. I only said it's the only way for Flash to exist in the future. It doesn't mean it has to be used with that. In vast majority of cases Flash now is used to decode video. HTML5 video suffers from crooked companies like Apple and MS who refuse to adopt open standards. When situation will improve, Flash will surely hit the ground for good. And to clarify, I don't think there is a point for Flash to continue.
Things like the new Generator framework for Photoshop and the entire Edge initiative show that they care more than they have in the past. They just don't care about the dated platform you're using.
More than likely, Adobe determined that it was much easier to secure a known slow path for shaders on the CPU than a fast GPU path. As a security-conscious user, I think I prefer that they adopted a quick fix that might have incurred a performance cost rather than put everyone else at continued risk for an indeterminate amount of time.
Here are a few options:
* They were trying to intentionally hide this change to spite you * They were avoiding unintentional disclosure of the attack vector for this vulnerability (indeed, none of the CVEs that I could find for this month's Adobe Flash update describe the attack) * The security hand didn't talk to the changelog hand * The security team worked independently of the perf team, and perhaps this case wasn't thoroughly tested or the regression not detected
And so on, and so forth. Let's be honest, there are lots of reasons we can imagine why Adobe did this, but imagining things doesn't make them true.
Today I learned: "never fix" means they will never ever solve the problem when it's used on a bug report submitted due to a performance regression on what might have been a zero-day vulnerability with in-the-wild attacks:
> Adobe is aware of reports that CVE-2013-0633 is being exploited in the wild in targeted attacks designed to trick the user into opening a Microsoft Word document delivered as an email attachment which contains malicious Flash (SWF) content. The exploit for CVE-2013-0633 targets the ActiveX version of Flash Player on Windows. > > Adobe is also aware of reports that CVE-2013-0634 is being exploited in the wild in attacks delivered via malicious Flash (SWF) content hosted on websites that target Flash Player in Firefox or Safari on the Macintosh platform, as well as attacks designed to trick Windows users into opening a Microsoft Word document delivered as an email attachment which contains malicious Flash (SWF) content.
Yes, that's a reasonable reaction.
The bug report was written a few days after the release of the player that contained the crippling. Note that we had to find out through other ways than a changelog in Flash what was wrong. The Adobe worker said they had to disable JIT compilation because of a security issue and didn't have the time to fix it before the release.
A month after the bug report was created, he implied through asking for votes and by apparently talking to management, that he'll try to get it fixed in a future release. We waited another month and now he closed the bug, added "NeverFix", and gave alternatives that are a joke.
If that isn't a NeverFix, I don't know what is. If you know have inside information on this, please do share.
I'm no expert in lower level tech but I used one of their tools to compile libjpeg to AS3 bytecode. I was able to write a file uploader half in AS3 and half in C. Faster than any other uploader I've ever used with the ability to reliably compress jpegs before sending from the client machine.
Unfortunately, I don't think they ever completely open sourced the work they did and it was a lab project so they don't support it (though it's been a long time since I looked).
They managed to compile the Citadel Demo at some point: http://www.unrealengine.com/flash/
R.I.P Adobe and Flash
Instead they got acquired by ClearSlide.
1.http://www.youtube.com/watch?v=1vP692sCbw4
Note, there are ways to make a Flash game(swf) not work outside of a given domain that would be at least semi-difficult to remove since it generally follows the same-origin rules of XMLHttpRequest. If you test for that in your actionscript, export-to-swf with obfuscation enabled and make sure the string is obfuscated so it can't be found in a hex-editor even if the export-obfuscation was reversed, a flash game hosted at http://www.nintendo.co.jp/ will not run anywhere else and it'd be kinda difficult to alter that behavior.