5 ms·
Has there ever been a piece of software more riddled with security holes than Flash? The Java runtime? Windows XP?
by webwielder 13y ago
Has there ever been a piece of software more riddled with security holes than Flash? The Java runtime? Windows XP?
- deleted 13y ago[deleted]
- joosters 13y agoAdobe Acrobat is another possible contender.
- Slackwise 13y agoFlash, Java, and XP are entire platforms with many moving parts. They are also the most popular platforms and the most exposed through the most-est-est popular platform— the web. There are plenty of bug riddled pieces of software out there. Plenty of platforms. Most are probably unknown or not popular enough to be scrutinized. These 3 are the most popular, most used, and most targeted. You will see them in tech news more than any other pieces of software. If you read vulnerability and security blogs, you'll be exposed to a whole, new, enormous, and wonderful world of bug ridden software. It's easy to say these kinds of things in hindsight. In their time, these systems became popular because they filled a void [1]. Now we look back and say "What were we thinking?", but it was harder to say back when the web browser was still a document system with minimal programmability. In all reality, the craft of software engineering is still truly new to the world, and constantly, rapidly, changing. Unlike the material world with the limitations of space and resources, the abstract land of organizing information and information that works on information is a very hard problem to solve—if it's even "solvable" at all. [1]: Well, okay, XP was kinda' forced onto the world.
- mnem 13y agoFlash is more popular than the browsers they run in?
- higherpurpose 13y agoYes it is. Flash is one entity that runs across several browsers. By definition it's more popular than each one of them. If there's a bug in Chrome, it affects only 30 percent of the browsing market - the Chrome market. If there's a bug in Flash, it affects 95 percent of the browsing market. That's why it would've been much better if Adobe open sourced Flash a long time ago, because then each browser could do their own implementation of Flash, just like they do with many other open specs today, and then if there was a bug in Chrome's Flash, it would've only affected the Chrome market. It's too late to open source Flash now, but we're doing that instead with alternatives like the HTML5 video tag and WebGL (for animations).
- vinayan3 13y agoFlash is the most distributed piece of software in the world. A few years ago it was installed on 1 billion devices. A very nice security target.
- ubercow13 13y agoi was under the impression that this was only true of flash before they implemented an internal sandbox into the runtime, which was quite a while ago now. is that not the case?