Jump to content

Facebook's new chief security officer wants to set a date to kill Flash


Recommended Posts

Posted

What are the chances of this actually happening?

 

Source: The Verge

 

Alex Stamos, the recently appointed chief security officer at Facebook, has called on software company Adobe to announce an "end-of-life date for Flash." In a pair of tweets sent over the weekend, Stamos echoed a number of recent complaints from the security community that the software has become the vector for just too many hacking vulnerabilities.

 

Last week, a 400GB cache of files stolen from spyware company Hacking Team revealed a major vulnerability in Flash that allowed hackers to execute malicious code on a target's machine via a website. Although Adobe quickly issued a patch to fix the problem, Hacking Team's internal memos describe the flaw as "the most beautiful Flash bug for the last four years," suggesting it had been known about — and used — for some time previously. This is far from an isolated incident: two additional vulnerabilities for Flash were found in the same 400GB trove in the following days, and earlier this year, Adobe was forced to release emergency security updates in both February and January.

 

Stamos is not calling for Adobe to immediately pull the plug on Flash, of course, but instead, for Adobe to announce an eventual retirement date for the software, giving websites the time to move to more secure technology like HTML5. Flash has been suffering from shrinking relevance in recent years, with former strongholds like Facebook games collapsing (see the burnout of Zynga), and YouTube moving away from the technology (in January this year this company deprecated Flash in favor of HTML5). Still, the transition would be difficult for smaller companies and if it really is time for Flash to die, it's likely to be a long, painful struggle.

 

http://vgy.me/oCQhHX.png

Posted

Saw this on twitter last night funny enough.

 

I think a lot more big companies need to get behind it and do this to pull the plug once and for all.

 

That being said no doubt we would come across some magical software package that only works with that junk

Posted
It needs to be done. I can't think of anything that can't be done with other technologies now, so there's no "need" for Flash any more. Not to mention, Flash developers can still use the software and export HTML5/WebGL/Javascript versions instead of swf now too.
Posted

As glorious as it will be on the day this happens (and it will eventually happen, hopefully in the next few years) I know the victory will be hollow as there will still be some poorly designed education software sitting on all our networks that requires it to work.

 

I'd hope that the browsers decide to just skip Adobe and state a date they'll stop supporting Flash, and for companies like Microsoft and Apple release updates to all their browsers that stops it working. Google have done it with NPAPI support so why not Flash.

Posted
Was thinking earlier, while their at it, they can happily kill off Java/Shockwave/Air too :)

 

Shockwave and Air are junk, agreed. Whilst I don't really have much love for Java as a language it does have it's uses - they just shouldn't be in the browser.

 

golden_hammer.png

Posted

Surely out the two, Java is worse than Flash? Oracle have really had to lock down Java, whereas Adobe haven't locked down Flash as such.

 

Plus - you could argue Microsoft's approach of updating/patching Flash via Automatic Updates is the way to go for all common plugins, including Java, Adobe Reader and others (if installed), it makes a great deal of sense.

 

I'm not quite sure why the security chief is so concerned about killing off Flash - just code Facebook not to use Flash at all and that's it, problem solved.

Posted

 

I'm not quite sure why the security chief is so concerned about killing off Flash - just code Facebook not to use Flash at all and that's it, problem solved.

 

Because to the normal end user, who wasn't aware of these tweets or whatever pressure Facebook and others put on Adobe (or browser developers), then it looks like it was actually adobe/google/someone else and not Facebook who caused Facebook to be unable to support Flash and therefore all those lovely games they have on their site stop working. It's a pretty good PR move from all perspectives, everyone who knows anything about Flash hates it so it gets praise from them for a good move by Facebook and anyone who doesn't know about Flash will believe the inevitable "Adobe stopped Flash due to security issues so we're not supporting it now, sorry" story that Facebook brings out.

Posted
Because to the normal end user, who wasn't aware of these tweets or whatever pressure Facebook and others put on Adobe (or browser developers), then it looks like it was actually adobe/google/someone else and not Facebook who caused Facebook to be unable to support Flash and therefore all those lovely games they have on their site stop working. It's a pretty good PR move from all perspectives, everyone who knows anything about Flash hates it so it gets praise from them for a good move by Facebook and anyone who doesn't know about Flash will believe the inevitable "Adobe stopped Flash due to security issues so we're not supporting it now, sorry" story that Facebook brings out.

 

I somewhat I agree with you - we are very much in a transition period between HTML5 and Flash, but the uptake in HTML5 has been extremely slow (in my view), with developers taking years to convert their websites if not at all.

 

The problem with HTML5 is that it hasn't even reached version 1, whereas Adobe at least have Flash versions, which makes it easier for developers. As a result (by logic), HTML5 could be changing all the time, which could be a costly nightmare for developers.

 

The other issue is that all modern browsers support different revisions/versions of HTML5, so making something cross-browser/multi-platform compatible is also a problematic issue.

 

If the Facebook security chief was right, this would have happened already.. but maybe this is just it; they're a security expert, and not a programmer, so don't maybe fully appreciate the challenges and indeed the costs for smaller companies to update their websites accordingly. Facebook, Google and Microsoft obviously don't have these issues and have the resources to quickly turn things around.

Posted
HTML5 is now stable and released. They've moved on to HTML5.1 now. @Michael

 

That's good to know, but (according to Wikipedia) HTML5 work started on January 22nd 2008 and was completed on October 28th 2014.

 

That's 6 years of development work just to get to version 1? That's a bit of a joke if you ask me. It's no wonder developers haven't taken it seriously and moved from Flash based websites.

 

It'll probably now take some websites many months, if not years just to be HTML 5.0 compliant.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...