Saturday, February 27, 2010

Flash updated - download pronto; here is what to do and why

A new version of Flash was released by Adobe.

After you download the news version of Flash, be sure to follow its installation instructions.

While Microsoft and Apple have decided not to support Flash on their latest mobile platforms - iPad, iPhone, iPod Touch, Windows 7 Phone - they both pre-install it on computers you buy from them.

If you run Firefox, be sure to learn about white listing web sites and using NoFlash.  It gives you extra security and protection from Flash-based memory leaks and stability problems.

The price you pay for that safety is less convenience.  You have to teach it what web sites you personally trust by giving it their domain names.  Until you do that, it will eschew loading any JavaScript, Flash, or Java code from that web site.

Fortunately, when you  visit such a site,  NoFlash will offer you a chance to trust that domain.  If you choose to do so, it will reload the page, this time loading the now-trusted content.

If you are run Windows, you are still at an extraordinarily high risk from the plugin that comes with Adobe Acrobat Reader.  The Acrobat Reader plugin is optional, but installed by default.  Disable or uninstall that plugin if you have it.   It is very bad news.  It makes your web browser a lot less stable and incredibly dangerous.  At best, all it does is offer a tiny bit of convenience. This is an incredibly bad trade-off and most people will never use that convenience either.  So disabling the Acrobat Reader plug-in makes sense on Windows.


If you use a Mac, you probably use Safari fairly often too.   There is a WebKit plug-in for Safari named ClickToFlash. It only restricts Flash.  JavaScript and Java are allowed to run. This allows most web 2.0 sites to run fine.

It also spares you the need to reload the whole web page, even if you do want to see a Flash movie on it.  You just click the Flash component you want to see, and it loads it.

Firefox 3.6 has two excellent capabilities built-in:  letting you check for updates to plug-ins, and

No matter which of these safety measures you use, you need to do keep your plug-ins in each web browser up-to-date or else disabled.

Otherwise you dramatically increase the risk of your computer and/or your web browser getting silently taken over permanently by hackers via malware - just by looking at a web site.

Even trustworthy sites attack you via infected syndicated content (ads, comics, news feeds), hacker-corrupted SQL databases on the sites, or malicious user-contributed content like comments and forum posts.  This should be science fiction, but it happens to tens of thousands computers today.

Adobe Acrobat Reader is unnecessary on the Macintosh.  Acrobat is used to display PDF files.  PDF files are a wonderful invention.  They let you create documents that contain text and graphics which display in small, convenient, self-contained, portable flies.  The files work cross platform.

Why is Acrobat Reader unecessary on the Macintosh?

Because Apple built the ability to display PDF files incredibly quickly on the Macintosh right into the operating system, Acrobat Reader is available for the Mac but necessary and not installed by default.  Apple includes an application program with each Macintosh called Preview.

Preview is very very fast because the Macintosh is designed to display any graphics incredibly quickly (3D, images, HTML, SVG, etc.) in general, and PDF in particular.

Does Preview leave support out for anything that Acrobat Reader includes support for?  Yes, stuff almost never used by anybody in PDF files:  embedded JavaScript, 3D graphics, and electronic forms. I found that Acrobat Reader is unnecessary on the Macintosh and stopped installing it.  Consequently, my web browsers run faster and more reliably.  I was safe from the increasingly commonplace attacks via Acrobat Reader plug-in long before they became a problem.


Normally, this hacking just happens to PCs running Windows.  But, if you have an arsonist in your neighborhood, you do not wait until your own house catches fire to buy a smoke detector and a fire extinguisher, do you?

Crooks can change their profile without notice. They can do this for several reasons.  It boils down to which is the easiest, safest, most rewarding prey.  After all, they are predators.   Human beings and their assets are these criminals' prey.  It is almost never personal.  They just want your stuff.

Unlike the predators you see at the zoo, these cybercriminal human predators are largely shifting from going after individual targets to attacking the hugest groups they can with each attack.

Here are some of the reasons crooks, cyber and otherwise, can change their targets.
  • improved safety of their preferred hunting grounds; Windows adds a new safety measure every several years or so - though only a fraction of Windows users install it, this might someday frustrate a hacker and cause them to switch targets
  • too much competition from other crooks ; new cybercrooks are piling in all the time
  • increasingly effective law enforcement in their favorite hunting grounds; this does not look like it is going to be a factor - selective law enforcement is illegal, and historically prosecution of typical overseas attackers is weak
  • increase in prey quantity, rewards, or safety of hunting elsewhere draws them to that area; predators are driven by varied mixes of:  hunger, laziness, ambition, and bravery - this applies to humans just like it does for species... human behavior is like many species in one because our personalities, and to a lesser degree cultures, are drastically different from each other
  • evolutionary advantages; cybercriminals and black hat hackers are evolving incredibly quickly, aided by the rich financial rewards they obtain from their victims - it funds whole underground economies: credit-card stealing carders, information-stealing hackers, identity thieves who want to establish themselves in a new country and/or rob its inhabitants, slacker companies who would rather copy designs rather than invent their own... you are not just fighting bad luck, you are fighting the nouveau underworld of organized crime
  • end of war; when conflicts end, the warriors who fought them are suddenly without a job and blessed with unusual skills and tools for besting the average person in attacks - sometimes they turn to a life of crime, at least for a while - perhaps, they even join human gangs and become career criminals
Yeah, so even if you feel safe right now you are not going to necessarily be that way next week.  Maybe you were not even safe last week.

So prepare this week for the attack you hope never comes.  Being prepared disuades attackers, and foils them if they do make a go at you.  Double win for you; double frustration for them!

That way you win, they lose.

Labels: , , , , , , ,

0 Comments:

Post a Comment

<< Home