Post: Isn't this a bit over the top?
Isn't this a bit over the top? →
Posted Sunday 23rd December 2007 18:52 GMT
In Serious Flash vulns menace at least 10,000 websites
This is a bit of a scare story isn't it? Flash itself isn't vulnerable to XSS attacks - it is the fact JavaScript can connect to Flash. JavaScript is the problem here, and I completely disagree with a previous comment saying that JavaScript is secure. A .swf file, with JavaScript disabled, cannot access anything on the user's computer apart from Local Shared Objects, Flash's secure version of cookies. A .swf file with 'Allow Script Access' disabled is exactly the same.
It sounds like this security issue is a vulnerability that Flash can trigger, but that it is just as likely an html page using JavaScript could. It is also a bit dubious that we're encouraged to purchase the book to find out the real deal.
Finally, criticising Flash for being responsible for over the top, waste of time animations is wrong! It is the designers, those who use Flash, who create these issues. Just as there are many examples of poor implementation, there are many examples of how Flash makes using the internet a more streamlined, enjoyable experience.
It is a pity this article seems to have focused on Flash and then brought out lots of out dated criticisms, losing focus on what would actually have been useful i.e. what the actual security issue is! What is the issue that makes already published .swf files vulnerable? Surely this is an issue where a .swf file has been produced specifically for these nefarious purposes and then triggers the trouble. I guess we have to wait and see.
Anyway - Merry Christmas!
Most read
Popular Whitepapers
- A Smart Path to Virtualization
Virtualization and Flexible Computing - Real-world server consolidation with Hyper-V
35 HP ProLiant DL385 servers onto 5 Dell PowerEdge M610 blade servers running Hyper-V - Business-Critical Applications
The Benefits of Intel Xeon Processors and Windows Server 2008 R2 for Business-Critical Apps - Virtualize at the speed of your business
The Dell guide to virtualization - A Cure for Server Sprawl
Dell Global Infrastucture Consulting helps DeKalb Medical - Staying committed to server refresh reduces cost
Can a server refresh help your company?