back to article FLASH MUST DIE, says Facebook security chief

Newly-minted Facebook security chief Alex Stamos has called for Adobe Flash to be taken out behind the shed by a shotgun-wielding world. The former Yahoo! security head joined Menlo Park this year and over the weekend said in two Tweets that it is time the death knell chimed for the Adobe's much-hacked tool. "It is time for …

  1. Anonymous Coward
    Anonymous Coward

    Fixed

    After this latest debacle, I simply un-installed Flash from my machines. Done, over, gone.

  2. Anonymous Coward
    Devil

    A message from Mozilla

    If you carry out a plugin check it says:

    All versions of Adobe’s Flash Player plugin are currently vulnerable.

    They need to add:

    And always will be.

    1. This post has been deleted by its author

    2. big_D Silver badge

      Re: A message from Mozilla

      Mine doesn't... Oh, wait, I don't have Flash installed.

  3. Mark 85

    I've killed it on all my home machines (at the office, in the process of killing it). So.. are we missing anything by not having it? So far, I haven't seen anything except some news sites that want Flash.

    1. Anonymous Coward
      Anonymous Coward

      The BBC insists on it when accessed from a platform capable of running it - just as one would expect of a popular 5eyes-government-agency operated watering-hole.

      1. Dr Paul Taylor

        BT Wholesale ADSL speed checker

        At least the BBC iplayer is delivering sound or video. I complained to (not about) my ISP about my broadband speed and they gave me some testing instructions, in particular to run the BT Wholesale Broadband Performance Test at speedtest.btwholesale.com. This is a crappy program that seems to have been written by some schoolkid and insists that Flash be installed, apparently so that it can show its progress bar, and in the end displays its results in a form that can't be cut-and-pasted back into an email to the ISP. It's all very well refusing to install Flash, permit Javascript, etc, but the Web is increasingly full of this kind of crap programming and some of the stuff is actually essential.

  4. Michael Thibault
    Megaphone

    Bring out the dead! Bring out the dead!

  5. Anonymous Coward
    Anonymous Coward

    Better yet... Death to Facebook.

    Because it deserves to die.

  6. Michael Thibault
    Trollface

    Who knew? Who knew!? Who knew it could be so easy?

    http://fpdownload.macromedia.com/get/flashplayer/current/support/uninstall_flash_player_osx.dmg

    http://download.macromedia.com/get/flashplayer/current/support/uninstall_flash_player.exe

    (This is a public service message.)

    1. Anonymous Coward
      Anonymous Coward

      Shouldn't there be another "s" in each of those?

      (This is also a public service message.)

    2. DropBear

      Yeah wouldn't it be nice. Except even though I have Flash set to "Ask to activate" I have to activate it literally dozens of times every day, to access content or services I'm absolutely NOT willing forego. Security is always secondary to actual functionality, and while I would certainly prefer to be less vulnerable, uninstalling flash will not happen a long as I'm forced to use it or accept being locked out.

  7. Anonymous Coward
    Anonymous Coward

    There needs to be fines or jailtime....

    Nothing else will work... The level of complacency in web security is extraordinary at every level, every week.. Beeb, Twitch, just about every online learning system... Some platforms even insist on Java, WTF???

    1. LaeMing
      Trollface

      Re: There needs to be fines or jailtime....

      Maybe if enough routers were configured to actively block flash content...

  8. king of foo

    Ads, a-ah...

    So far as I can tell, flash is mostly used for adverts nowadays (by el reg to boot)

    Ming: Get off my planet!

    Steven 'Flash' Gordon: The sooner, the better.

    1. Michael Wojcik Silver badge

      Re: Ads, a-ah...

      Mostly. Not exclusively.

      Flash is absolutely critical for a large corpus of electronic literature, for example. That may not be important to most people, but it is very important to a significant number of people. And those people are capable of using Flash only with trusted sources.

      Stamos is Yet Another security-fundamentalist ass who believes that everyone must adhere to his personal threat model. These people are just as bad as the crap development organizations that produce vulnerable software in the first place.

  9. Charlie Clark Silver badge
    Stop

    "Nobody takes the time to rewrite their tools and upgrade to HTML5 because they expect Flash forever. Need a date to drive it."

    Policy by tweets… don't you just love it? :-/ And who's going to pay them to do this? Facebook perhaps?

    Where's the cross-platform solution for media rights holders?

  10. Anonymous Coward
    Anonymous Coward

    Videos stored in Facebook

    I trawl Facebook Timeline pages for posts with videos. That used to extract posted URLs that referenced various video storage sites like Vimeo, YouTube, or Facebook.

    This week it stopped working for videos stored on Facebook servers. They now have encoded tag parameters dedicated to "SWF" that have no obvious interpretation from which to derive an independent URL.

  11. sevkeifert

    conversion is the key

    If you want to kill flash, create a FLA -> HTML5 converter. Then developers only need to compile the source files.

    Of course, there are SWF to HTML5 converters, though they are really a lossy hack and don't always work very well.

    At this point, why doesn't Adobe just allow an option to recompile FLA sources to native HTML5? Macromedia used to allow compiling to Java in the early days of the web. Then people might still use Flash for the IDE. No one ever cared about the binary format the data was saved as.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like