Hacker News new | ask | show | jobs
by nye2k 3685 days ago
Compared to what?

I'd argue that the Flash security argument is just a regurgitation of headlines people are reading. Every prolific web technology has a large number of CVE's.

2 comments

In 2015, Flash had the largest number of CVEs of all web technologies: https://www.cvedetails.com/top-50-products.php?year=2015
Yes, they do. The problem is that Flash adds a layer of risk and the associated costs of risk management onto the web stack.

Adobe does not bear the cost of maintaining flash integrations, and doesn't bear the cost of the liability for shipping these vulnerabilities. If a user gets hosed because of Flash in Internet Explorer, Firefox, or Chrome, they blame their browser.

This externalization of the costs of securing the product, coupled with externalizing the cost of maintaining browser integrations means that it is harder to build a secure browser.

Flash needs to die, and with a very narrow subset of functionalities, it is no longer needed. Best to let it go so that we can have one less vulnerable client downloading and executing untrusted on our computers.