-
Posts
5,626 -
Joined
-
Last visited
Content Type
Profiles
Forums
Events
Everything posted by Palehosefan
-
QUOTE (Y2HH @ Aug 4, 2010 -> 11:49 AM) As a security researcher in the internet security profession, no...I'm afraid flash security isn't overblown at all. It's not just a concern, it's a primary concern as more CRITICAL holes exist in flash than any other application that is seemingly used on a daily basis, with or without a general users knowledge. For example, my parents have no idea that when they browse website that those animated graphics or advertisements are primarily flash driven/executed. Most users have no idea, either. As a developer, I can see why you'd say that security is overblown, but it's not, and it's a concern for many in my profession. I fight with developers about this all the time, and it's always the same story...in the end, they think that what they did is "good enough", and I should just clear it for production use. It's dead on critical, and it's THE biggest hole between end users and the internet in which is exploited, in multiple fashions, sandboxed or not. Sandboxing is merely a method of protecting a subsection of memory from being exploited/read/written by other applications...it does not, however, plug open holes in security, which Flash has more than any other application I've ever known. And Adobe issues new bug fixes to flash on seemingly a daily basis...so whether Apple speeds up it's patch releases or not, it wouldn't matter. Just because Adobe releases a patch, doesn't mean I can clear it for use in production environments...that patch may break more than it fixes, causing the loss of service, causing the loss of money...so no...simply issuing fix after fix doesn't help me...as a matter of fact, it's a hindrance, because every patch needs to be re-vetted and re-tested for production because clearance. They need to fix as many as they can at once...not one a time every other day, such as they do now. This is why companies like Microsoft and Apple have patch schedules outside of insanely critical security breaches. While all of these patches on a daily basis are fine for end users, they are NOT fine for businesses, and they never will be. Most of the issues I see are from bad programming or programmers using Flash in ways that it shouldn't be, such as security login screens. Integrating a Flash piece to a SQL database for instance is asking for trouble. SQL injections are hard enough to control in secure languages such as .NET, much less Flash. Asking a user for any secure information in a Flash piece is outside of the proper scope. Another issue is Flash programmers using things such as uploaders, which is ridiculous and can allow a user to upload any kind of malicious object they want. http://www.publish.com/c/a/Graphics-Tools/...MNL02102009STR3 Another big issues is that outside vendors have been very slow to create a Flash security software tool such as Fortify. Another issue is like you said, Adobe doesn't have a schedule for their security updates like Microsoft and Apple. Most of the issues are programmers not using Flash in it's proper place, but there are built in plugin issues over the years that have caused plenty of headaches such as the Flash Player 10.0 problems I admit. I won't even try to defend Acrobat or PDF files in general, it's a mess. If you need an uploader, database integration, secure logins etc, Flash is NOT the language a developer should be using.
-
QUOTE (Y2HH @ Aug 3, 2010 -> 11:25 AM) HTML 5 isn't done yet, and Flash does indeed have performance issues still, which is why their 10.1 players are still in beta on multiple platforms...they've been working on that for what, 1+ years now and it's still in beta? Give me a break. What Flash has is better tools/programs to use it, since it's been around so long. That's the only thing it has going for it, as time goes on and more and more HTML 5 dev tools come out, HTML 5 development will easily catch up. People forget that before Adobe bought Shockwave -- Adobe itself was trying to kill Flash all the while telling everyone how crappy it was. This is a true story, btw, go look it up. Adobe itself was saying all the same stuff Jobs is saying now before they bought the technology. And last but not least, Flash has almost ZERO security. I'd venture to guess that a majority of web based hacks happen through Flash...they need to fix that once and for all. The fact that they plug 30 holes a week in Flash isn't good enough...secure it already, Adobe shouldn't need years to do it, either... You are correct, HTML5 isn't completed yet, and has an estimated span of a decade before cross-browser rendering differences are solved. Most browsers/phone operating systems already have 10.1 available. However, with the fracture of mobile browsers available now, the issue isn't just a Flash issue. My fiancee's Droid has had 2.2 installed for well over a month now, and I'm still waiting on my Frodo build. Everyone hated on Flash originally, as it was simply a graphic designers tool that could provide the most basic ability to produce a website. However, the product has grown immensely with the release of AS3 several years ago, and has done a fantastic job of taking on the 3-D rendering world. Flash security is WAY overblown. Sandbox security fixed any cross domain scripts from running. The only reason people are griping about it is because the Flash player is installed on 90%+ of machines and has to be updated manually by the user each time. .NET for instance uses the Microsoft Windows Update to update it's security. However, these Flash Player updates aren't any more frequent than say Firefoxes browser updates. Most security breaches come in the form of executables in script, which generally present themselves in executable DLL files or as Javascript code. These are not actually part of the ActionScript language, but rather on the language required to run Flash player and programs in general. Counting on HTML5 and Javascript to be your savior in security issues is like hoping a bear will protect you from a lion. HTML5 isn't going to cause the doom of the Flash language, programs such as Flex have taken the AS3 semi object-oriented level language to new levels and have completely thrown out the graphic design part of the integration that Flash still clings to. HTML5 is a step in the right direction, which is a unified programming language. But this is going to be a very long process, and it's up to other languages to adapt. If Adobe doesn't take steps towards unifying their products with HTML in future releases then they will eventually die out, and should die out. But for now, Flash is a viable option, and is improving with each release. Jobs might want to watch his own back before spouting off ignorance, http://www.csoonline.com/article/448865/ap...time-ipod-touch http://www.infoworld.com/d/security-centra...ant-dns-bug-889 http://www.infoworld.com/t/platforms/patch...curity-bugs-301 http://www.dbtechno.com/apple/2008/06/22/a...ugs-for-safari/ http://www.pcworld.idg.com.au/article/1949...bug-fix_iphone/ As for Jobs complaining about Flash problems, this is fantastic. "Because Apple bundles Flash Player with Mac OS X, it regularly distributes patches for the Adobe software, at times months after the latter has shipped patches. The six-week gap between Adobe's issuing fixes and Apple delivering them this time was similar to the time it took Apple to update Flash in the summer of 2009."
-
QUOTE (Y2HH @ Aug 3, 2010 -> 09:59 AM) If iPhone users want flash that badly (most of us don't), you can jailbreak and have it. Also, Flash games have to be rewritten for touch interfaces so playing them as is won't work very well, unless you like your hand covering the game you are trying to play. Most episodes of online TV shows don't require Flash anymore, either. Not to agree with Jobs, but Flash is a BAD technology and needs to either a) be fixed BIG TIME, or B) go away forever and be replaced by something newer. Flash is slow on desktops, and I've seen it on Android phones...and I'm not impressed...I see quite a bit of slowdown with it, unless everything goes perfectly, which almost never happens. Of course, this isn't the Android's fault...it's Adobe's...they need to seriously learn how to program over there already. In time, I'm sure they will get it to a more real world usable point, but right now it's not there. The problem is, the longer Adobe takes to really make mobile flash efficient the worse it gets for Flash, as so many online video players are also running HTML 5 at this point. If I were Adobe, I'd kick flash production into high gear and really showcase it so they can tell Steve Jobs how wrong he is about it's inefficiency. Flash loads at the same speed as HTML. Every Flash site I have built has been under 400k and is completely run through XML and CSS. Adobe took their time with fixing Flash's CPU hogging nature of the past, but Flash Player 9 was released a few years ago and took care of this outside of the 3-D world, which Flash Player 10 has since taken care of. ActionScript 3 is an actual object-oriented language that is built in the image of Java. There is nothing wrong with the programming from Adobe, it is headed in the same direction as 95% of the other languages out. The main thing holding Flash back is that it is still a plugin, which is what it was always supposed to be. Flash was never meant to be an information-rich content producer, Flash was always supposed to be about the visual experience. The things Flash does well happen to be a nice companion for mobile devices and new TV's. Things like video players, music players, picture galleries, etc have always been Flash's strong suit and will continue to be. Many new TV's will have their menu's in Flash. There's a reason Flash gained tons of market share over the span of Flash's life, and I love the point you make about Flash taking it's time compared to HTML 5. You do realize that HTML 4 was the HTML standard for 9 years!!! before HTML 5 came out? Flash has been consistently improving in programming and in the Flash Player itself. Flash isn't going anywhere, and Apple seeking a monopoly on application software is not going to be a sustaining endeavor. I work with HTML, AJAXX, Javascript, and Flash on a daily basis, and there's still no comparison of a Flash presentation vs. AJaxx or Javascript. Flash wins everytime. However, information and security environments just run better in HTML environments. HTML's Canvas tag will be used for a lot of banners replacing some Flash, however the use of Javascript and CSS will take up the same amount of CPU usage as Flash. Here's a fantastic(long) piece on the subject from another .NET/Flash developer. http://flashworks.wordpress.com/2010/04/29...ure-of-the-web/
-
Happy Birthday! Have a good one.
-
QUOTE (KyYlE23 @ Jul 29, 2010 -> 10:01 AM) i love how Jackie was welcomed and everyone said hello, yet no post from jackie You could say Jackie "Rebuched" everyone.
-
I'll be honest, I'm struggling trying to find a way to root for LeBron and his retarded crew.
-
Filthiest Venues in Pro Sports....
Palehosefan replied to Kyyle23's topic in A and J's Olde Tyme Sports Pub
QUOTE (KyYlE23 @ Jul 26, 2010 -> 08:59 AM) I wonder if the inspectors were surprised when they saw the workers at Lambeau field serving food after blowing their nose and not washing their hands? You guys need to wear Booger Heads when you play Green Bay. -
Nice job, it just sucks (in my eyes) seeing us have a back-up catcher and a 4th OF at #4 and #8. I would have put Jose Martinez on the list over Gartrell. I think Daniel Wagner should have gotten some consideration as well. Terry Doyle is another that could be argued. Yes he's 24 in high A ball, but he was 22 years old when drafted and he's putting up great numbers this year. I could see him ending up in AA this year at 24 years old.
-
Official 2010-2011 NCAA Football Thread
Palehosefan replied to knightni's topic in A and J's Olde Tyme Sports Pub
QUOTE (whitesoxfan101 @ Jul 20, 2010 -> 12:30 AM) Wow that's an absolute disaster for UNC if Austin is suspended. If any or all of the other guys mentioned there are suspended, just make it that much worse. And if a couple to several others schools are involved, get your popcorn ready. I guess a South Carolina guy might be involved in the UNC stuff too, oddly enough. Florida can kiss any statistical reference or credit for the Sugar Bowl goodbye if the Pouncey thing is true too, and you'd think 100 grand will get even more punishment than that. UNC is loaded everywhere but safety at the moment. Losing Deunta Williams would hurt much worse. However, I'm feeling much better that the punishment is going to be minimal for all but one player(Austin). These agents are getting more and more absurd. They should be banned from talking to players until they graduate or declare for the draft. -
QUOTE (Athomeboy_2000 @ Jul 16, 2010 -> 09:20 AM) OMG that is crazy. THat is horrible money I can't believe they didn't just try to re-sign Barnes for 2-4M, but to add 15M in Luxury tax just for Redick? Insane. Otis really, really loves his back-ups I guess.
-
QUOTE (Balta1701 @ Jul 16, 2010 -> 08:56 AM) By the way, spending somewhere between $27 million and $40 million on JJ is as bad as any of the other contracts given out this offseason. You mean paying 34M for Redick for 3 years is bad?
-
QUOTE (Ozzie Ball @ Jul 15, 2010 -> 10:11 PM) Well you don't learn anything from one game, but the early result obviously isn't good. I think this is his third game back and he's 1-13.
-
Haslem sticking with Heat, Fisher sticking with LA.
-
QUOTE (Chi Town Sox @ Jul 12, 2010 -> 10:09 AM) They have gotten a little better but are NOT very good, everyone thinks LBJ is good because he has highlight real blocks when it all reality, he is below average on the ball. Wade is a gambler and can look like a defensive stopper at some points and just look like a fool at others. http://www.basketballprospectus.com/articl...p?articleid=918 Both have become very good defenders. Especially LeBron.
-
QUOTE (Jenksismyb**** @ Jul 12, 2010 -> 09:53 AM) I have two concerns for that team which makes me hesitant to believe that they're outright favorites to win the title or even favored to win 70+ games: (1) how long will it take for them to figure out the best way to play together, and how exactly are they going to play? As much as the NBA is about superstars, it's not streetball. There's still a team aspect to the game, which is one reason Lebron's teams haven’t won. A spread em out and let one guy try and dominate doesn't work. The main 3 are going to have to figure out who's going to take the shots and how many they get. People seem to think that'll be easy, but at least with Wade and Lebron, that's not how they've played the last 6 years. And really this is the main reason why I don't think you can say Lebron + s***ty team = 60 wins, therefore Lebron plus 2 other guys = 82 wins. Lebron's game is to drive and get hacked or drive and get fouled. It's that 1 on 5 mentality. Same with Wade. None of these guys are deadly shooters. So I guess I just don't see the automatic greatness here. Their games don't really complement each other (a point Rick Barry has been advocating for a week now). The Bulls 72 win team had greatness in different areas - MJ was all around offense, Pippen was lock down defender and a guy that could finish around the rim, Rodman gave you the rebounding and garbage buckets, and Kukoc/Kerr/Harper were the shooters. You could beat them in one aspect of the game, and they’d adjust and beat you in another. That’s why they were nearly unbeatable. So far on Miami you've got two all around great offensive players, and one really good perimeter big guy. You don’t have the rebounding, you don’t have the interior presence (at all, we’ll see who they end up with) and they don’t have any shooters. This could all change in a few weeks as he fills out the roster, but I’m just not seeing anyone out there that’s going to be on those same levels. I see two guys that have the same game and a perimeter-oriented big man. I still think they’re missing some pieces. (2) Who plays defense? So they score 100 a night, but what happens when they go up against teams that have solid offenses that can also score? Bosh is weak, and neither Lebron or Wade are lock-down defenders. I dunno, is it possible? Sure. But I think they still have a lot of questions to answer. I think it’ll be a great experiment for the future – can you amass lots of talent, even if it’s the same type of talent, and still win? Or is there a formula of championship teams that require you to have greatness in all aspects of the game? Wade and LeBron have turned themselves into very good defenders. They will have the defensive advantage at SG and SF on most teams they play outside of LA. Mike Miller is a fantastic shooter and good rebounder as well off the bench. With Bosh, LeBron, Wade, Mike Miller, and Joel Anthony, rebounding won't be an issue unless someone like Oden, Howard, Noah, Gasol etc are roaming the paint. As for shooting, you have Miller, LeBron, Chalmers, and potential FA's like Bell, Stackhouse, Richardson, Jason Williams, Keyon Dooling etc. This team will win 60+ games, but will have struggles with Orlando's style, Boston's defense, and the Lakers/Blazers frontline. However, the Heat must sign a defensive PG like Dooling. Having LeBron or Wade guard PG's like Rose and Rondo is just stupid and a waste.
-
QUOTE (zenryan @ Jul 11, 2010 -> 06:28 PM) And now Jesse Jackson is getting involved in the Lebron James story. tmz I'm going to have a party the day that dude takes his last breath.
-
Bellamy should be in Birmingham any day now. Nothing left to prove in winston-salem.
-
I don't like defending him, but Redick has turned himself into a Ray Allen type hustle defender. He's constantly chasing his man around the screens and sticking with him. He's not a liability on defense, he's average now. He will get beat by quicker 2G's, but so will many.
-
QUOTE (Jordan4life @ Jul 10, 2010 -> 10:39 AM) C'mon, Palehose. Riley's pulled this crap before. He won't coach a team unless he feels they're a legitimate championship contender. What he did to Stan Van Gundy still wreaks. I'm not saying this is a sure thing. But it won't surprise anybody. I wouldn't be surprised by it, but the fact that Stan Van Gundy is telling RealGM or whatever site about it is hilarious. He already took bitter beer face shots at LeBron, so now it was Riley's turn again I guess. Stan has been taking this stance ever since Spoelstra was named coach, but now RealGM is posting it like a fact. We all realize Pat Riley wants as much attention and rings as possible, but it's not something new, or it shouldn't be at least. It's a giant douchebag thing to do from Riley, but if you are one of the best coaches of all time and happen to be part owner and GM, it's almost logical.
-
QUOTE (Jordan4life @ Jul 10, 2010 -> 10:32 AM) The most hated team in recent sports history becomes just a little more hated. Read more: http://www.realgm.com/src_wiretap_archives.../#ixzz0tIHryCug What a f***ing shock. An opposing head coach said Riley is going to come back to coaching and we should believe it? Even the Heat were selling LeBron, Wade, and Bosh on the fact that Spoelstra would be their head coach and they were fine with it. Riley will step in if he feels Spoelstra is in over his head(which he might be). Gee I wonder who that head coach was?
-
Looks like Riley might be doing a sign and trade for LeBron and will be retaining Udonis Haslem as well. Pat Riley must have mafia ties or something.
-
QUOTE (zenryan @ Jul 9, 2010 -> 06:21 PM) Kobe didnt leave LA a few years back to piggyback another star. There is a difference. He wanted to join Deng, Noah, Wallace etc in Chicago, but LA acquired Pau Gasol instead.
-
QUOTE (SoxAce @ Jul 9, 2010 -> 04:10 PM) LeBron more often than not would rather pass it. I've seen more than enough games seeing him kick it out to Mo Williams/Jamario Moon/etc.. (even if they are open for a few seconds) for a three. Kobe never does that unless he is getting triple teamed (not doubled), and you'll see a guy like Fisher, maybe Gasol shooting the rock. Now he'll get to do it again with Eric Gordon!!! (or most likely Baron Davis) Looks like Kobe should have passed it to Derek Fischer much more often at the end. Don't get me wrong, I poop my pants every time Kobe shoots it at the end, it's just amazing how many he has missed overall. I just have his game winners seared into my mind.
-
http://www.82games.com/gamewinningshots.htm Carmelo seems to be clutch.
-
QUOTE (whitesoxfan101 @ Jul 9, 2010 -> 02:34 PM) Well, it's good if he doesn't want to be the greatest ever, because that concept died last night. He can certainly reach his goal of multiple championships now that he has Wade to take the last shots, and Bosh and Wade to help him in general. But the dream of being a billion dollar athlete also died last night, because LeBron James the player isn't dead, but LeBron James the brand is. Miami is going to be on national TV for just about every single game. Miami will be in the playoffs every single year, and LeBron will be the best player on the floor for likely at least 1 or 2 championship teams. LeBron's marketing hit here might take a dive, but worldwide places like China will immediately take him to the top as they have done with Kobe after his titles. LeBron can make a killing off of foreign marketing, and that's assuming the bandwagon fans in America turn their noses up at LeBron for joining Dwyane Wade, which is a big assumption when the dust settles.