I don't understand what they are thinking - it used to be such a progressive company.
I don't know about US Government, but many Governments and sensitive organisations are still using VMware, and this isn't likely to change.
I lul'd.
If you're running an update to date flash, that means you're probably running it in a sandbox and probably have silent auto updates turned on. That's good enough for most people.
If you're the kind of person that's going to get specifically targeted, then you should not only reconsider running flash on your computer, but any other program written in an unsafe language.
Or, you know, segregate your data.
I certainly HOPE most software I use can do better than this: http://www.cvedetails.com/vulnerability-list/vendor_id-53/pr...
To be certain, Flash gets a lot of attention because of its install base - but it's been a never-ending FOUNTAIN of RCE bugs for much of the last decade.
Flash has been insecure since originally launched.
Compare FF, Safari, IE, Chrome. Same number of bugs per yet but Chrome has 10x less code execution bugs (ie, 10x less likely for your machine to be owned by unknown bugs)
Flash runs in a low-priv environment is nearly every major browser, includes application-specific exploit mitigations, and it silently auto-updates, just like Chrome. It's all a matter of the Flash install base: it's in 90%+ of browsers and it's running the same-ish codebase in all of them, making it a relatively stable platform to develop exploits for. That's it! It's more a factor of market share and not "security."
Every document reader, HTML renderer, JavaScript engine, browser, media player, etc that you use is the same -- a house of cards built on poor memory management :-/.
> Chrome pushes out a dozen or more fixes
> for remotely exploitable vulnerabilities
> every 2 weeks.
That equates to 288 remotely exploitable vulnerabilities in Chrome per year.Here is a chart from the same source with a timeline of sorts: http://www.cvedetails.com/product/15031/Google-Chrome.html?v...
Your statement about Chrome is clearly way off, and that's what your parent was addressing. He never said Chrome was bug-free. And he was right to say that Chrome is way ahead of the other browsers (according to these stats, at least).
Edit: those stats show Chrome is better in terms of CVE severity, not number of annual CVEs.
Shit, this is the most accurate description of modern software that I've seen so far.
it's not awesome
month rows 10 7
2015-07 35 28 29
2015-06 14 7 7
2015-05 17 10 10
2015-04 22 19 19
2015-03 11 7 9
2015-02 19 19 19
2015-01 12 9 11
2014-12 6 5 5
2014-11 19 16 18
2014-10 3 3 3
2014-09 12 11 12
2014-08 8 7 7
2014-07 3 0 2
2014-06 6 1 3
2014-05 5 0 5
2014-04 4 1 2
2014-03 4 2 2
2014-02 4 3 4
2014-01 2 2 2
[...]
2015 has not been kind to them, but it's been a continuous trickle of remote severity 10s every month for a year and a halftruncated because it took too much space; full results: https://gist.github.com/anonymous/763e28612b74d3a1817a
NB: only months with at least one cve event show up, but given adobe's focus on security, it wasn't really necessary to fill in months with 0 events to get the point across
download each screen full of results from the cve site into a single directory and run this script: https://gist.github.com/anonymous/990bfe126d273ef84134
"It is time for Adobe to announce the end-of-life date for Flash and to ask the browsers to set killbits on the same day. — Alex Stamos (@alexstamos) July 12, 2015"
On Windows, you get a pop-up to update manually, which just sends you to their website so you need to download and run the installer by yourself.
If you don't update manually, Flash will wait 45 days before triggering an automatic update. I never waited that long, so I don't know whether it's "silent" or not.
As for consequences, the best thing most of us could do is disable Flash from the browser. I’ve done it since YouTube defaulted to HTML5 video and never looked back since.
Just look at the news for the past years and there's only 1 conclusion: uninstall Flash or accept increased risk of catching a virus.