Industry moves in to finish off Flash after Hacking Team exploit revelations
The first casualty of the attack on the now infamous Hacking Team may not be the Italian spyware vendor itself, as many undoubtedly hope, but rather Adobe Flash, which is now officially blocked in FireFox after the discovery of a third zero-day vulnerability in the trove of internal data pilfered through the breach. And the industry’s frustration with the media player is only widening.
Adobe Systems Inc.’s ubiquitous runtime has long struggled with severe security issues that have compromised more consumers than anyone can count over the years along with a number of high-profile corporate victims. The most notable of the bunch is encryption powerhouse RSA, which saw hackers exploit a zero-day vulnerability just like the one uncovered today back in 2011 to steal sensitive data pertaining to one of its most widely used products.
Flash’s security woes have contributed a great deal of momentum to the shift towards alternatives set forth by the late Steve Jobs’ famous decision to avoid adding support for the player on iOS due to poor mobile performance, power efficiency and, of course, vulnerability to attacks. The new bugs may provide the final boost needed to push the software into irrelevance.
The third and latest vulnerability that emerged this morning is the straw that broke the camel’s back. Codenamed CVE-2015-5123 by the Trend Micro Inc. researchers who discovered it, the flaw enables hackers to exploit the part of Flash used to manipulate the presentation of Bitmap objects in order to completely take over a system, which makes it just as severe as the previous two loopholes that have been uncovered from the Hacking Team’s leaked internal records over the past week.
Adobe already released a security advisory for the bug when Trend Micro raised the alarms, but not before the backlash could start. Mozilla Corp. fired the first shot after updating its popular browser this morning to disable Flash by default, which promptly spawned a wave of how-to guides in the tech sphere on removing the player from platforms that still support it.
Facebook Inc.’s recently appointed chief security officer, Alex Stamos, went a step further and called on Adobe itself to take action by announcing an end-of-life date for Flash. The company may very be forced to do so at this point, if nothing else than to save face, since the fate of its once dominant media player now appears all but sealed.
Photo via Brian Klug
Since you’re here …
… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.
If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.