Facebook's new chief security officer wants to set a date to kill Flash
theverge.com
theverge.com
On the other hand, once Flash is dead, I worry that the invasive crap that made Flash so obnoxious will simply be re-engineered in HTML5 and Javascript, resulting in the same problems of garish pop-ups and autoplaying videos in an implementation that is more difficult to block.
Just look at today's HTML5 transitions and animations. It's not enough to have a normal webpage. Now when you scroll down things have to fade in and out of visibility, images have to rotate and come into view, videos start to autoplay when they come into visibility, parallax diarrhea slows down your computer.
I can't wait till "parallax scroll blocker" and "visual diarrhea disabler" are released as chrome plugins.
How can I block HTML5 videos and audios or at least stop them from playing automatically?
Deleted comment
[0] https://github.com/brion/ogv.js
[1] https://hpto.yahoo.com/review/mobile/npte/a-haunted.html
<video src="url" autoplay>
<audio src="url" autoplay>Deleted comment
Deleted comment
I mean, they had one simple thing to do: prevent code from escaping the sandbox. So how is it possible that they have repeatedly failed at that one task?
<wear-tinfoil-hat>Never attribute to malice what can be explained by incompetence, as the saying goes. But after so many years, I'm beginning to wonder: is it really incompetence, or has some TLA agency convinced them not to do a good job? </wear-tinfoil-hat>
First, to be fair, "Flash" is 2 complete Virtual Machines: ActionScript 2 and ActionScript 3. I expect it to have an increased attack surface.
Second, many things that Flash does (graphics, 3D, video decoding, audio decoding, etc) pretty quickly get you to unmanaged APIs in the OS.
Third, Flash can be suprisingly tricky to escape. Mark Dowd did an absolutely insane series of steps to have code that was valid bytecode, that retained control of a pointer, and to properly setup the memory space for jumping. This isn't necessarily "easy" by any stretch. The full write up is here: http://www.inf.fu-berlin.de/groups/ag-si/compsec_assign/Dowd...
This isn't to give Adobe a complete pass, but there is a lot going on here. Still, the time for Flash is past and I cannot wait for it to die
When's the last time a JavaScript exploit was found? I know the Pwn2Own contests manage to bust out of the sandbox now and then, but this seems exceedingly rare compared to the near monthly super critical Flash updates.
Not so crazy, http://mozilla.github.io/shumway/ -and Gnash before- does it (to a certain extent) now.
The primary uses that I see, day to day, for Flash are:
1. Video players (which should be done natively)
2. Ads (which is an awful use case)
3. Fancy, but broken, font replacement (less so lately)
4. Weird, unnecessary utility, like copying text to the clipboard.
I don't see any reason to reimplement Flash in Javascript when all of these use cases can be better done in native HTML/Javascript already (1-3), or just not done at all (4). It seems like a huge amount of engineering effort to maintain an old technology that even its creator is migrating away from.
There's a lot of Flash games and applications out there that would be completely inaccessible to people were it not for the Flash player.
For example, the Homestar Runner site is built entirely on Flash, and while movie rips of this exist, there's small, subtle interactive elements only possible in the Flash version. http://www.homestarrunner.com/
When Flash is dead a large part of the web goes dark, and that's a tragedy.
I'd claim the opposite: There's (at least) one less runtime needed when executing Flash within JS. Also, no extra graphic, audio, video, … stack that is executed alongside the browser stack.
There's a lot of legacy stuff that will never be reimplemented. For this content, you can use e.g. Mozilla's Shumway[1].
The JavaScript document.execCommand() clipboard APIs are available in Firefox 41+, Chrome, Safari, and IE. More discussion (in the issue tracker for ZeroClipbboard, a popular Flash clipboard utility):
This one was among my favorites for a time: http://www.dofus.com/en
Facebook has had a lot of vulnerabilities, maybe someone should ask them to set a kill date?
Let's compare Adobe's diligence of patching to another company's. How about Mozilla?
Adobe usually patches a RCE exploit within 72 hours of discovery. Mozilla seem to take anywhere from one to three months.
Firefox RCE exploit found on January 20, 2015: https://community.rapid7.com/community/metasploit/blog/2015/...
Firefox RCE exploit found on February 25, 2015: https://msisac.cisecurity.org/advisories/2015/2015-018.cfm
Firefox RCE exploit found on March 1, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-3...
Firefox RCE exploit found on April 22, 2015: https://msisac.cisecurity.org/advisories/2015/2015-046.cfm
Firefox RCE exploit found on May 12, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-5...
Did you hear about any of those Firefox RCE exploits? Probably not.
We only hear about Flash RCE exploits because those are the ones which happen to get exploited in the wild the most. This is not because browsers are always more secure than Flash; it is because hackers know that if they succeed in finding a RCE exploit in Flash, they will be able to target the 97% of desktop users with Flash installed rather than just the 44% who use Chrome or the 15% who use Firefox. It's the same reason Windows users have always had far more exploits actively used against them than Mac users. Should we set a kill date for Windows because of that?
As long as we are making asinine suggestions, how about browsers set a kill date for Facebook, after which no one can access the site? Facebook's rampant video piracy problem harming small publishers on YouTube [1] is orders of magnitude more financially damaging to its victims than MegaUpload ever was. At bare minimum, it would be appropriate to warn users that they are about to visit a malicious piracy hub with a red full-screen "Are you sure you want to go here?" page, and perhaps provide a list of suggestions of alternative social networks to switch to.
Source?
The RCE exploits were all fixed within hours or days (or already fixed when reported). The updates were pushed within days or a few weeks.
Sign of the times.
EDIT: Well, I did.