3 ms·
So, they verified the bug over a year ago and haven't pushed out the fix because it's slated for an as-of-yet unreleased point upgrade? Confidence inspiring.
by brandon 17y ago
So, they verified the bug over a year ago and haven't pushed out the fix because it's slated for an as-of-yet unreleased point upgrade?
Confidence inspiring.
- bshep 17y ago"The dog ate my homework but I have a copy at home which I can bring some other day"
- mmastrac 17y agoOne thing I read from this is that Adobe isn't agile enough to ship security or crasher fixes more than once a year. No process for out-of-band fixes? Not something I like to hear from the developer of a plugin on most computers.
- wmf 17y agoThey ship security updates every few months: http://www.adobe.com/support/security/#flashplayer http://www.adobe.com/support/security/#flashplayer
- ahk 17y agoPossibly all the folks actually capable of fixing the bugs quickly have quit or were laid off. If Adobe has only second tier developers left that would explain this kind of situation.
- catch23 17y agomaybe the flash performance problems are also slated for an unreleased point upgrade too. Maybe that's why Windows had all those security problems -- they were all slated for an unreleased point upgrade.
- gecko 17y agoI know you're kidding, but that's actually happened to us before. There are a large number of bugs in .NET's mail handling that, if you call Microsoft, they'll say they've fixed for an upcoming point release. And, to be honest, I do believe them, insofar as there is some repository, somewhere, where a programmer at MS checked in a fix. It just doesn't do a lot of good to you if you're trying to ship software now instead of next year.
- sosuke 17y agoThey did at least say they messed up on that. "The mistake we made was marking this bug for "next" release, which is the soon to be released Flash Player 10.1, instead of marking it for the next Flash Player 10 security dot release." The 0.1.0 releases are for actual player upgrades and the 0.0.1 releases are for security fixes. The 10.1 release is actually a pretty big upgrade to the player that will be out some time near the CS5 release that features iPhone native app export, woot! Besides that, I reviewed the Flash Crash code and the situation that causes this bug and it doesn't seem like a common situation where you load a single unique URL that sends two different Flash version files (7/8) when requested one after another. I know my own QA department would be tickled pink if they could recreate this problem in any of my applications but even then I'd first say "who the hell would do something so crazy, this isn't on the top of my pile of stuff to do, I'm still working on making the player run well on the Mac, awesome bug though we'll get to it later"
- llimllib 17y ago(seems to be a she)
- brandon 17y agoThe bug is capable of completely locking up modern browsers (to say nothing of the situation back in 2008 when the issue was discovered). Esoteric or not, this should have been on the very top of the work pile and dropped into a security patch immediately. Yes, they admitted a mistake, but they wouldn't have done so if their actions had been at all defensible.
- deleted 17y ago[deleted]
- zb 17y ago> who the hell would do something so crazy People trying to crack other people's browsers, that's who.
- mtsmith85 17y agoThis may come across as some amount of fanboy-itis, apologies in advance for that. But, I wonder if this is the kind of "lazy-ness" that Jobs was referring to with Flash. Not necessarily lazy in the sense of not doing anything, but lazy in the sense of inability to keep "control" and an eye on your major properties (Apple qualities.)
- philwelch 17y agoThis actually makes them look even worse if they're honest. "We haven't been able to fix this bug because we're bad programmers"--understandable but shitty. "We have fixed this bug, but no one knows that because of our byzantine release policies--oh, but for all you know we're lying through our teeth and using vaporware to cover ourselves"--now that pisses me off.