Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>At least Microsoft does not bundle Silverlight with IE (but it will apparently bundle Flash..).

If I remember correctly, Flash is only enabled for a set of whitelisted sites. But, as we see, someone will probably chain that to some other vulnerability.



It's definitely safer with a whitelist, however it is still riskier than not shipping Flash at all. A limited exploit might get around the whitelist, and then use any second exploit of Flash to break completely through.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: