6 ms·
Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree i
by velcro 11y ago
Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits.
If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014):
- Internet Explorer 366 total vulnerability issues (314 high severity)
- Google Chrome 235 total vulnerability issues (154 high severity)
- Adobe Flash 207 total vulnerability issues (169 high severity)
- Mozilla Firefox 190 total vulnerability issues (86 high severity)
- Oracle Java 161 total vulnerability issues (69 high severity)
[source] https://nvd.nist.gov/ https://nvd.nist.gov/
- yRetsyM 11y agoYes, but Flash alone doubles the attack vector of a browser - that's nothing to be sneezed at. I think it's particularly poignant when you look at the high severity metric.
- tiplus 11y agoI am not sure the attack vector argument is 100% valid here, as flash replacement technologies constantly add attack vectors to modern browsers, too. Many traditional Flash features are now covered by webGL accelerated browser functionality, like accelerated 2D canvas elements. My guess would be that this browser-gpu bridge creates a whole zoo of GPU driver related security issues which attackers might focus on once flash is completely obsolete. (My money is on a remote code execution vulnerability in the Firefox Adobe DRM module.)
- deleted 11y ago[deleted]
- onion2k 11y agoSo Flash is second in terms of number of high severity bugs and first in terms of the percentage of bugs that are high severity, only being beaten by Internet Explorer. By your evidence the hate for Flash is quite justifiable.
- philh 11y agoIt's second to IE in both those metrics, but "percentage of bugs that are high severity" seems like a strange thing to be measuring in any case.
- jfoster 11y agoPerhaps it's intended as a proxy for overall quality.
- ild 11y agoFlash bugs are more important because the are crossbrowser. I will still use Flash though on older computers, because it needs less resources for video.
- stevenh 11y agoRemote code execution exploits were found in Firefox at least once per month during the first half of 2015. The only reason we didn't hear about these cataclysmic exploits is because it wasn't Flash. January 20, 2015: https://community.rapid7.com/community/metasploit/blog/2015/03/23/r7-2015-04-disclosure-mozilla-firefox-proxy-prototype-rce-cve-2014-8636 https://community.rapid7.com/community/metasploit/blog/2015/... February 25, 2015: https://msisac.cisecurity.org/advisories/2015/2015-018.cfm https://msisac.cisecurity.org/advisories/2015/2015-018.cfm March 1, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-39/ https://www.mozilla.org/en-US/security/advisories/mfsa2015-3... April 22, 2015: https://msisac.cisecurity.org/advisories/2015/2015-046.cfm https://msisac.cisecurity.org/advisories/2015/2015-046.cfm May 12, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-50/ https://www.mozilla.org/en-US/security/advisories/mfsa2015-5... Hackers search for remote code execution exploits in Flash first and foremost because they know a successful Flash exploit will reach the highest number of targets (90% or more on the desktop) whereas only 44% of desktop machines are running Chrome and 15% are running Firefox. Hackers seeking out and exploiting RCE bugs in Firefox is unheard of for the same reason malware targeting Macs has been virtually unheard of over the past decade: It's not that OS X is more secure; it's simply that Windows is a more lucrative target.
- rockdoe 11y agoMozilla seems to take anywhere from 1 to 3 months to fix these severe bugs. Adobe takes days. Source for this complete and utter FUD? Certainly not the links you gave: Jan 11, 2015: Originally reported to Mozilla as a low-severity DoS, which turned out to be already patched in trunk Jan 13, 2015: Firefox 35.0 shipped with patch It's hard to get dates out of the others because the bugs are still hidden, but the "fixed in" is often a security fix update after a release, which means it can't possibly have been > 6 weeks.
- stevenh 11y agoYou're right, I misinterpreted the timeline there.
- halayli 11y agoYou probably missed out on the hacking team leaks. These actions are triggered by the leaks. HT was sitting on a lot of flash 0-day exploits. This leak was the best thing that happened to the web.
- paublyrne 11y agoThey do get more bad press than perhaps others should. There is already a perception about Flash that it is not a great product, which feeds into this. Reasons are varied. - Performance has not been good on Macs (my 2007 Macbook Pro literally burned my legs when running anything flashy) - Flash updates mechanism seems a little spammy. - Long-term perception of Adobe as a maker of a somewhat buggy, somewhat bloated software - Steve Jobs' public denigration - Backlash against proprietary standards being used on the web The best thing about click to play Flash is it puts a stop to autoplay videos on the less reputable sites I occasionally and shamefully glance at for sports news.
- visarga 11y ago... and makes pages load faster.
- Mimu 11y agoI don't think the hate comes from bugs or exploits. I think people hate flash because it is laggy, slow, make things move in your screen you don't want, widely use for ads or to shit on the user experience, etc. Granted most of it might be bad programming, but I still think he comes from here rather than exploits.
- kristopolous 11y agoClearly all this crap will still happen in a flash free world.
- vbezhenar 11y agoTuring-complete machine running untrusted code is a nightmare for security. There always be bugs and exploits, it's just a matter of time and effort to find them. JavaScript enabled by default is already bad enough. We don't need Flash, Java, ActiveX or anything similar turned on by default. So it's a good move from security viewpoint. Less attack surface.
- proactivesvcs 11y agoI have a lot of experience of end users and they are forever telling me that they get so many different "Update this", "Update that" windows that they can no longer distinguish real from fake. Some of them have been tricked by fake web site pop-ups as a result, others ignore legitimate update messages. I do not blame them. Internet Explorer and Google Chrome get updated in a way that most end users find to be simple to understand, particularly with Chrome. Firefox is also quite good in this regard. All of them are reliable - it is rare, IME, to come across a Windows Update, Firefox or Chrome instance which is silently failing to update. Or not even bothering to prompt to update. Flash, however often I install it, just doesn't seem to auto-update reliably. Quite often it only does so after a user log on/reboot, which doesn't happen much in the days of standby. Even on brand new, fresh Windows installs (so we know the OS/Flash isn't broken), I test Flash from time to time and it just doesn't prompt to update at all on some occasions. This is what makes Adobe's poor track record exponentially worse - that their software update mechanism is crap at best. I was gobsmacked when Microsoft declared they were going to start updating Flash via Windows Update. Gobsmacked and so very relieved. It felt like they'd walked into Adobe's office, grabbed their fire extinguishers and told them "You are so useless that when there's a fire, WE will come and put it out, since you don't seem able to. We are sick of our offices getting burned down because of your idle incompetence." I won't even address Oracle's Java. Bundling malware with their updater is tantamount to crime.
- Coding_Cat 11y agoFlash also comes with McAffee (or some other bundleware). I wouldn't be surprised if the reason why they haven't made a proper auto-updater is because of that. That they'd miss out on those miniscule profits they get from that.
- kijin 11y agoYeah, I've been wondering why Adobe sticks to a "visit our website and manually download the new version" update model in this day and age. I think you found the answer. If you keep ignoring the update prompt, Flash will quietly update itself after 45 days. That's long enough for every interested party to pwn your machine.
- jafingi 11y agoSo by disabling Flash by default, Mozilla can theoretically reduce vulnerabilities by half :-) Seems like a good choice to me! Also, getting rid of the constant update dialogs and crapware installed with Flash will improve the overall user experience.
- richardw 11y agoCost/benefit seems higher for Flash/Java than browsers. You really need a browser, but you don't really need a [fancy thing that can't be done in JS]. As another commenter said, it doubles your attack surface and for little benefit. Flash game enthusiasts would probably disagree, but most of us can probably do without it given the risk.
- syntheticnature 11y agoAs an enthusiast for a handful of flash games, it is increasingly tempting to make a VM just for running them. Even then, with all the progress in Javascript, it's questionable whether I should bother.
- richardw 11y agoThere are a couple flash games I'd like to keep as well, but mentioning that didn't seem to strengthen my point :) I've since found a few work-related apps that need it. Hiss.
- braythwayt 11y agoYes but Flash vulnerabilities are incremental vulnerabilities. So just counting high severity vulnerabilities, the chart is IE: 314. IE with Flash: 483. Chrome: 154: Chrome with Flash: 323. Firefox: 86. Firefox with Flash: 255. And of course, you can add a third column for Java and a fourth column for browser with Flash and Java. I have no idea what their bugs-per-line-of-code are, perhaps they have the finest code on the planet. But from a surface area perspective, installing Flash makes you more vulnerable, period. And it really is not necessary, whereas it’s not like you can browse the web in pure Flash and not install a browser.
- anon1385 11y ago>But from a surface area perspective, installing Flash makes you more vulnerable, period. So does turning on Javascript. Yet the popular opinion these days is that disabling Javascript makes you a luddite. Mozilla even hid the option for it in Firefox.
- DavideNL 11y ago> If you run the popular browsers/plugins against the National Vulnerability Database... That's misusing statistics, you can't determine how secure something is by just summing up the number of vulnerabilities - equally weighing/comparing browsers with a plugin etc. By the way, Apple's opinion on Flash in 2010: Third, there’s reliability, security and performance. Symantec recently highlighted Flash for having one of the worst security records in 2009. We also know first hand that Flash is the number one reason Macs crash. We have been working with Adobe to fix these problems, but they have persisted for several years now. We don’t want to reduce the reliability and security of our iPhones, iPods and iPads by adding Flash. Source: https://www.apple.com/hotnews/thoughts-on-flash/ https://www.apple.com/hotnews/thoughts-on-flash/
- ArtDev 11y agoFlash is blocked on Apple devices due to business reasons, nothing more.
- oldmanjay 11y agoFlash is not blocked, it is simply not present. Also, considering the track record of Flash on Android, your opinion is not supported by historical fact. It is very clear that Adobe is not on the ball to anyone who pays attention.
- doodpants 11y agoFlash was never "blocked" on Apple devices. Rather, Safari on iOS simply doesn't support plugins. You can't install Java, Silverlight, or Unity 3D plugins either.
- ssalazar 11y agoSure, and one of those business reasons is keeping bloated, buggy software that is ill-suited to mobile devices away from their phone's user experience.
- zimbatm 11y agoAnother point that hasn't been raised yet: Flash is a much smaller software than a browser, how come it has more bugs ? It certainly speaks for it's internal code quality.
- belorn 11y agoIn general, plugins are supposed to improve a product by adding or enhancing existing features. Flash however enables websites to break out of the HTML, CSS and JS environments and their security constraints, which should mean that flash have a larger responsibility regarding security. If Flash lived under the constraints of the browser own security, then flash bugs would barely register as news worthy.
- bzbarsky 11y agoThe bigger question is how many of those were 0-days: vulnerabilities that were public before a version of the software with the fix had shipped.