Flash Vulnerabilities Affect Thousands of Sites
An anonymous reader sends us to The Register for this security news. The problem is compounded by the fact that some of the most popular Web development tools for generating SWF produce files containing the recently disclosed vulnerabilities. "Researchers from Google have documented serious vulnerabilities in Adobe Flash content which leave thousands of websites susceptible to attacks that steal the personal details of visitors. A web search reveals more than 500,000 vulnerable applets on major corporate, government and media sites. Removing the vulnerable content will require combing through website directories for SWF files and then testing them one by one. Updates in the Adobe software that renders SWF files in browsers are also likely, but they probably wouldn't quell the threat completely... No patch in sight from Adobe, that's the price to pay for depending on proprietary solutions."
With respect to the "No patch in sight from Adobe" part, of course. If such a flaw was discovered by security researchers in firefox, they could do better than merely report the problem, it is within their power to correct the code and issue a third party patch/update if mainstream won't act. The vulnerability may not intrinsically be due to the proprietary nature (though external code audits might arguably occur to help, but I wouldn't guarantee it), but solving those problems cannot be done in a proprietary system except by the vendor.
The community might ignore such a patch, and it might not even happen that often, but if things were generally dire enough in a projects mainstream, a new leadership could fork the project and that is not unheard of in projects. Of course, it's common for distributions to apply security updates to their packages before upstream merges them, so it isn't *that* strange.
Not related to security, but the current version of the flash plugin, for example, breaks compatibility with linux opera and konqueror due to Xembed, and packagers hands are kind of tied in terms of what to do about it. Of course, can also point out the ATI drivers, which suffer greatly from problems and are dealt with in a way that doesn't work.
XML is like violence. If it doesn't solve the problem, use more.
A cat can't teach a dog to bark.
Unless the Reg article is being misleading, it doesn't look like much more than "XSS is possible in Flash apps". If that's the case, it's less a case of a "vulnerability" as Flash giving developers a hammer, and the devs bashing in their own fingers with it. As in JavaScript, as in PHP, as in CGI, as in any language that accepts input from outside-- never trust the input!
Or am I missing something?
Information wants to be free.
Entertainment wants to be paid.
You just want to be cheap.
I believe most Flash is done wrong simply because the site designers value form over content.
Useful or pertinent information (if it is manifest at all) usually has the appearance of being inserted as an afterthought. That's why the sites I visit most often tend to be based primarily on simple markup such as HTML, which despite its various drawbacks is at least easy to maintain (and therefore more likely to be maintained), and does not have the noli-me-tangere character of a cast-bronze SWF presentation.
I apologise for coming across as a luddite, but it is distinctly tiresome to be subject to the whim of some mentally adolescent graphics designer poking glitzy, time-consuming displays in my eye rather than allowing the information I'm looking for to be easily found. Which is why I think Flashblock is the best thing since unsliced bread.