maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Maemo 5 / Fremantle (https://talk.maemo.org/forumdisplay.php?f=40)
-   -   Flash: worth revisiting with Sept 2011 security updates? (https://talk.maemo.org/showthread.php?t=77439)

JohnLF 2011-09-21 23:04

Flash: worth revisiting with Sept 2011 security updates?
 
Just seen the following about major security updates to Adobe Flash: -
http://nakedsecurity.sophos.com/2011...lnerabilities/ which indicates 6 vulnerabilities patched including one critical one seen used in the wild.

I was wondering if it was worth the effort to re-badger Nokia into supplying an update to fix this flawed piece of software, i.e. provide us with an official Flash v10?

Thoughts on a postcard please...

tzsm98 2011-09-21 23:22

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Quote:

Originally Posted by JohnLF (Post 1093558)
Just seen the following about major security updates to Adobe Flash: -
http://nakedsecurity.sophos.com/2011...lnerabilities/ which indicates 6 vulnerabilities patched including one critical one seen used in the wild.

I was wondering if it was worth the effort to re-badger Nokia into supplying an update to fix this flawed piece of software, i.e. provide us with an official Flash v10?

Thoughts on a postcard please...

It is certainly worth a try. I am doubtful of the success.

Radicalz38 2011-09-22 00:08

Re: Flash: worth revisiting with Sept 2011 security updates?
 
An abandoned thing will always be abandoned. It's more like 3% chance nokia would provide us flash update now. If ever they still plan on retaining flash on their devices they would probably do it on the new generation gadgets. You could already see things happening.


If nokia could even provide update on their side what more for other 3rd party stuffs?

onethreealpha 2011-09-22 00:37

Re: Flash: worth revisiting with Sept 2011 security updates?
 
an interesting idea given the nokia is still legally obligated in a number of countries to contiue support for the N900, including addressing bugfixes and security patches. (yeah yeah i know all about the "wontfix" list)

The n9 doesn't come with flash support, nokia having focussed in full html5 support, along with the whole micro sim, and simplistic UX (for simple people), one might assume the N9 was targetting I-Phone users.

the big issue here is that now, with adobe flash 11 providing "full" support to Android and IOS along with WP7, I question if the decision to leave it off the N9 was another attempt by some at Nokia to further limit it's success in some markets?

I'd guess that nokia will save their Flash investment for the upcoming windows phone handsets and forget the rest.... :(

Tedri Mark 2011-09-22 01:47

Re: Flash: worth revisiting with Sept 2011 security updates?
 
I think the upcoming flashplayer 11 molehill/stage3d content might turn the tide on the whole anti flash backlash...

gerbick 2011-09-22 01:56

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Quote:

Originally Posted by Tedri Mark (Post 1093620)
I think the upcoming flashplayer 11 molehill/stage3d content might turn the tide on the whole anti flash backlash...

I doubt it. Mind you, I'm all about seeing Molehill/Stage3D and improved StageVideo in Flash Player 11, but I'm sure people will say something negative, continue hope for HTML5 as being a full-blown replacement (btw, Pandora's HTML5 player exposes the *.m4a audio files and they can be downloaded without issue) and that everything around Adobe Flash is a waste of time.

JohnLF 2011-09-23 08:29

Re: Flash: worth revisiting with Sept 2011 security updates?
 
I'm not overly hopeful about this either, but I'm thinking if it's considered a critical update by Adobe, and Nokia are still obligated to supporting the N900 then there is an outside chance, especially given the fact that they recently gave a small update regarding the security certificates.

Anyway, I have raised a bug, https://bugs.maemo.org/show_bug.cgi?id=12437 and emailed security@maemo.org as per Andre Klapper's suggestion.

I'm not holding my breath... lol

zdanee 2011-09-23 08:54

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Yeah. New Nokia update. They would likely remove Flash player thus solving the security issue :)
Anyone remember the FireWire security hole? The one when sysadmins were advised to pour hot glue into their servers fw ports because a modified iPod could hack all its way into any system :)

attila77 2011-09-23 10:22

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Quote:

Originally Posted by zdanee (Post 1094370)
Yeah. New Nokia update. They would likely remove Flash player thus solving the security issue :)

That's less funny than it seems, because it *is* the most likely/easiest solution if push came to shove, as apparently a new round of certifications is out of the question.

And, the usual rant - if Adobe really think it's critical, they are more than welcome to release a patch, through Nokia or whatever channel they please, there is nothing stopping them.

towhatend 2011-09-23 10:40

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Hm, the version we got already have some security problems, http://www.adobe.com/support/securit...apsb10-14.html is some of them. I donīt think Nokia will care.

Joseph9560 2011-09-23 11:07

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Quote:

Originally Posted by zdanee (Post 1094370)
Yeah. New Nokia update. They would likely remove Flash player thus solving the security issue :)
Anyone remember the FireWire security hole? The one when sysadmins were advised to pour hot glue into their servers fw ports because a modified iPod could hack all its way into any system :)

Probably Nokia will give some prize for such a great idea. They can surely do this one if situation warrants.

zdanee 2011-09-23 11:19

Re: Flash: worth revisiting with Sept 2011 security updates?
 
I'd probably be stoned it I'd make a new thread titled "Flash 10 for N900 is alive", just to write in the first post:

http://img842.imageshack.us/img842/382/nopes.jpg

vetsin 2011-09-23 12:02

Re: Flash: worth revisiting with Sept 2011 security updates?
 
maybe we do have the right to demand a security update from nokia. it is security after all, not just feature request. and not every N900 here's more than a year old or past their warranty period. bought mine this year so i think i still deserve some security update.
so THANK YOU JohnLF for filing a bug report. :)

towhatend 2011-09-23 12:08

Re: Flash: worth revisiting with Sept 2011 security updates?
 
If Nokia should even consider an update I really think we need to provide all of the critical bugs we have in our version of Adobe Flash, as we know flash isn't the most secure application in the world...
http://www.adobe.com/support/securit...apsb09-01.html
http://www.adobe.com/support/securit...apsa09-03.html
http://www.adobe.com/support/securit...apsb10-06.html
http://www.adobe.com/support/securit...apsb09-19.html
http://www.adobe.com/support/securit...apsb09-10.html
http://www.adobe.com/support/securit...apsb10-22.html
http://www.adobe.com/support/securit...apsa10-03.html
http://www.adobe.com/support/securit...apsb10-16.html
http://www.adobe.com/support/securit...apsa10-01.html
http://www.adobe.com/support/securit...apsb11-21.html
http://www.adobe.com/support/securit...apsb11-18.html
http://www.adobe.com/support/securit...apsb11-13.html
http://www.adobe.com/support/securit...apsb11-12.html
http://www.adobe.com/support/securit...apsb11-07.html
http://www.adobe.com/support/securit...apsa11-02.html
http://www.adobe.com/support/securit...apsb11-05.html
http://www.adobe.com/support/securit...apsa11-01.html
http://www.adobe.com/support/securit...apsb11-02.html
http://www.adobe.com/support/securit...apsb10-26.html
http://www.adobe.com/support/securit...apsa10-05.html
http://www.adobe.com/support/securit...apsb08-24.html

vetsin 2011-09-23 12:11

Re: Flash: worth revisiting with Sept 2011 security updates?
 
the mere number of bugs you listed should be compelling enough (didn't check them one by one though :)). i just hope nokia listens...

end2begin 2011-09-28 08:24

Re: Flash: worth revisiting with Sept 2011 security updates?
 
If Nokia listens. But to whom should Nokia listen then? Whom will tell Nokia this? Or should Nokia read all the threads on this forum too to get some idea about with all is important and what is not?

prankster 2011-09-28 08:44

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Quote:

Originally Posted by end2begin (Post 1097881)
If Nokia listens. But to whom should Nokia listen then? Whom will tell Nokia this? Or should Nokia read all the threads on this forum too to get some idea about with all is important and what is not?

council is the only source to get to nokia adobe team !:)

JohnLF 2011-10-05 00:03

Re: Flash: worth revisiting with Sept 2011 security updates?
 
I am just catching up on posts, forgot to mention I emailed "security@maemo.org" as requested and got a bounceback stating the email address was not recognised.

That sounds promising doesn't it...?

demolition 2011-10-05 00:45

Re: Flash: worth revisiting with Sept 2011 security updates?
 
I have a feeling part of the no flash v > 9 thing is some driver problem as well so it might be quite a hornet's nest! Might be wrong though.

Nokia do have an obligation to ensure that
(a) the device works as advertised (i.e. maintain the multimedia capabilities)
(b) users are as secure as possible
- so some action is required.

For those of us still in contract and warranty, it's something worth pursuing and we have a leg to stand on re: the above. Nokia's email support is shambollic, to say the least so we need to look into how else to contact them. Anyway, in the morning!

Mentalist Traceur 2011-10-10 04:02

Re: Flash: worth revisiting with Sept 2011 security updates?
 
Month later (EDIT: Sorry, a week later-ish. I'm stupid. Saw the month number and associated 10 with september for a minute), no updates. Anyone call someone in Nokia (though from the stories on this forum I suspect most of their support people don't even know what the N900 is, let alone any details about it), or keep hammering away at other e-mail based support vectors? Community council has contact information to other Nokians as I understand it, right? Any chance someone's asked them to bring this up since then?

zdanee 2011-10-10 13:49

Re: Flash: worth revisiting with Sept 2011 security updates?
 
I've wrote a mail to Nokia Hungary also, maybe we should start bugging them in large volumes. In May they told me MeeGo will come to N900 (even thou they already told everyone they will drop the project altogether, so they kinda lied to me, not that it's surprising). I wrote that my phone is still covered by warranty and that includes software support, so now I wait and see what happens :)

Edit: Answer from Nokia Hungary: my message has been forwarded to the developers...


All times are GMT. The time now is 02:36.

vBulletin® Version 3.8.8