Criticism Adobe Flash Player




1 criticism

1.1 usability
1.2 privacy
1.3 security
1.4 vendor lock-in
1.5 apple controversy





criticism
usability

in browsers, prior flash versions have had uninstalled before updated version installed. however, of version 11.2 windows, there automatic updater options. linux partially supported, adobe cooperating google implement via chrome web browser on linux platforms.


mixing flash applications html leads inconsistent behavior respect input handling (keyboard , mouse not working in html-only document). done in web sites , can lead poor user experience site.


the february 20, 2014 update 12.0.0.70 introduced reported bug, producing green video sound only. defect related hardware acceleration , may overcome disabling hardware acceleration via adobe settings in firefox (accessed right clicking within video) or in internet explorer (within tools settings). defect may related used graphics hardware, amd radeon hd video cards, , similar visual defects have occurred in earlier flash updates, same workaround.


privacy

flash player supports persistent local storage of data (also referred local shared objects), can used http cookies or web storage in web applications. local storage in flash player allows websites store non-executable data on user s computer, such authentication information, game high scores or saved games, server-based session identifiers, site preferences, saved work, or temporary files. flash player allow content originating same website domain access data saved in local storage.


because local storage can used save information on computer later retrieved same site, site can use gather user statistics, similar how http cookies , web storage can used. such technologies, possibility of building profile based on user statistics considered potential privacy concern. users can disable or restrict use of local storage in flash player through settings manager page. these settings can accessed adobe website or right-clicking on flash-based content , selecting global settings .


local storage can disabled entirely or on site-by-site basis. disabling local storage block content saving local user information using flash player, may disable or reduce functionality of websites, such saved preferences or high scores , saved progress in games.


flash player 10.1 , upward honor privacy mode settings in latest versions of chrome, firefox, internet explorer, , safari web browsers, such no local storage data saved when browser s privacy mode in use.


security

adobe security bulletins , advisories announce security updates, adobe flash player release notes not disclose security issues addressed when release closes security holes, making difficult evaluate urgency of particular update. version test page allows user check if latest version installed, , uninstallers may used ensure old-version plugins have been uninstalled installed browsers.


in february 2010, adobe officially apologized not fixing known vulnerability on year. in june 2010 adobe announced critical vulnerability in recent versions, saying there reports vulnerability being actively exploited in wild against both adobe flash player, , adobe reader , acrobat. later, in october 2010, adobe announced critical vulnerability, time affecting android-based mobile devices. android users have been recommended disable flash or make on demand. subsequent security vulnerabilities exposed android users, such 2 critical vulnerabilities published in february 2013 or 4 critical vulnerabilities published in march 2013, of lead arbitrary code execution.


symantec s internet security threat report states remote code execution in adobe reader , flash player second attacked vulnerability in 2009. same report recommended using browser extensions disable flash player usage on untrusted websites. mcafee predicted adobe software, reader , flash, primary target attacks in 2010. adobe applications had become, @ least @ point, popular client-software targets attackers during last quarter of 2009. kaspersky security network published statistics third quarter of 2012 showing 47.5% of users affected 1 or more critical vulnerabilities. report highlighted flash player vulnerabilities enable cybercriminals bypass security systems integrated application.


steve jobs criticized security of flash player, noting symantec highlighted flash having 1 of worst security records in 2009 . adobe responded pointing out symantec global internet threat report 2009, found flash player had second lowest number of vulnerabilities of internet technologies listed (which included both web plug-ins , browsers).


april 7, 2016, adobe released flash player patch zero-day memory corruption vulnerability cve-2016-1019 used deliver malware via magnitude exploit kit. vulnerability exploited remote code execution.


vendor lock-in

flash player 11.2 not play kinds of content unless has been digitally signed adobe, following license obtained publisher directly adobe.


this move adobe, abandonment of flex apache criticized way lock out independent tool developers, in favor of adobe s commercial tools.


this has been resolved of january 2013, after adobe no longer requires license or royalty developer. premium features classified general availability, , can freely used flash applications.


apple controversy

in april 2010, steve jobs, @ time ceo of apple inc. published open letter explaining why apple not support flash on iphone, ipod touch , ipad. in letter blamed problems openness , stability, security, performance, , touchscreen integration of flash player reasons refusing support it. claimed when 1 of apple s macintosh computers crashes, more not cause can attributed flash, , described flash buggy . adobe s ceo shantanu narayen responded saying, if flash [is] number 1 reason macs crash, m not aware of, has apple operating system.


steve jobs claimed large percentage of video on internet supported on ios, since many popular video sharing websites such youtube have published video content in html5 compatible format, enabling videos playback in mobile web browsers without flash player.








Comments

Popular posts from this blog

1940-1941 Pontiac Torpedo

1920–1923 List of 1920s jazz standards

Sovereign Building Zollinger-Harned Company Building