{"id":14,"date":"2015-07-13T21:58:51","date_gmt":"2015-07-13T21:58:51","guid":{"rendered":"http:\/\/www.paidparanoid.net\/site\/?p=14"},"modified":"2015-07-14T15:26:48","modified_gmt":"2015-07-14T15:26:48","slug":"mobile-code-or-i-hate-you-flash-i-hate-you","status":"publish","type":"post","link":"https:\/\/www.paidparanoid.net\/site\/?p=14","title":{"rendered":"Mobile code &#8212; or I hate you flash, I hate you!"},"content":{"rendered":"<p>If one good thing has come out of the recent Hacking Team hack (apart from a fairly scummy company getting their come-uppance and failing to initiate their own internal kill processes), it&#8217;s a salutary warning on the issues with mobile code. In particular, the issues with our old friend, Adobe Flash.<\/p>\n<p>3 o-day vulnerabilities in Flash have been released in 2 weeks, and the frequent upgrade cycle can&#8217;t be helping with not introducing other issues. Yet we still see a huge number of sites (and even better, security tools) using it. Among the best was the US Senate debate on cybersecurity requiring you to load flash to watch it &#8212; while there were 0-day flash vulnerabilities in the wild).<\/p>\n<p>Cisco, for all that I&#8217;ve spent a lot of time working with and promoting their products, requires flash for functions in the console of ISE. It&#8217;s time for this to stop; HTML5 is available, and we can use more secure (in fact, I&#8217;m not sure we can use less secure unless it&#8217;s Java) methods to present data. Flash WWW sites have been irritating for years &#8212; now they&#8217;re irritating and dangerous. Yet if industry leaders and vendors continue to REQUIRE Flash to effectively use their products, how fast can we actually get rid of it?<\/p>\n<p>On a more personal note, I&#8217;ve been endorsing running a flash-blocker, click-to-flash, or some sort of browser plug-in for years. \u00a0It&#8217;s even more pressing these days &#8212; just do it. Once you&#8217;ve done it, think before you click on that flash video elf-bowling game!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If one good thing has come out of the recent Hacking Team hack (apart from a fairly scummy company getting their come-uppance and failing to initiate their own internal kill processes), it&#8217;s a salutary warning on the issues with mobile code. In particular, the issues with our old friend, Adobe Flash. 3 o-day vulnerabilities in [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[2],"tags":[3],"_links":{"self":[{"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=\/wp\/v2\/posts\/14"}],"collection":[{"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=14"}],"version-history":[{"count":1,"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=\/wp\/v2\/posts\/14\/revisions"}],"predecessor-version":[{"id":15,"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=\/wp\/v2\/posts\/14\/revisions\/15"}],"wp:attachment":[{"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=14"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=14"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.paidparanoid.net\/site\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=14"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}