4 ms·
I'm really surprised that those here don't seem to be placing much importance on the numerous security holes that Flash has brought to all platforms. The first
by Dbug 17y ago
I'm really surprised that those here don't seem to be placing much importance on the numerous security holes that Flash has brought to all platforms. The first serious one I'd heard of wasn't fixed for like a year and a half? How do people get the notion that a vulnerability that isn't see use in mass-scale exploits doesn't matter? The holes exploited selectively can certainly be a serious threat to industry or government.
To the developers that feel no choice but to use Flash, I suggest you make sure your sites use Javascript from a minimal number of domains because cautious users aren't going to enable them in NoScript when a dozen show up.
It might also help that any domains needed beyond that of the site have names which give away their function.
Surfing as securely as possible includes enabling added functionality very selectively. Make sure that when you test your sites they're usable to people running Firefox with NoScript, with little or no granting of permissions.