Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>At least Microsoft does not bundle Silverlight with IE (but it will apparently bundle Flash..).

If I remember correctly, Flash is only enabled for a set of whitelisted sites. But, as we see, someone will probably chain that to some other vulnerability.



It's definitely safer with a whitelist, however it is still riskier than not shipping Flash at all. A limited exploit might get around the whitelist, and then use any second exploit of Flash to break completely through.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: