Look back in anger: 5 years of Adobe Flash failure
It might soon be curtains for Adobe Flash Player. Yesterday, Firefox announced that all versions of Adobe Flash would be blocked from its browsers for security reasons. This announcement came hot on the heels of Facebook’s chief security officer calling for a kill date. Apple, notably, has frozen Adobe out of its app development since 2010.
It is time for Adobe to announce the end-of-life date for Flash and to ask the browsers to set killbits on the same day.
— Alex Stamos (@alexstamos) July 12, 2015
The problem stems from the software’s myriad insecurities due to old code that hackers can exploit across Adobe products. So how did this erstwhile basis of apps and video-streaming fall so far out of favor? Let’s take a walk (of shame) down memory lane.
Adobe Flash accounts for 7 percent of known Web plug-in vulnerabilities in Symantec’s 2009 Security Threat Report. (Adobe Reader accounts for 15 percent.)
April 8-9, 2010
Reports trickle in that Apple has locked out Adobe’s Flash-to-iPhone compiler (basically a way to create iPhone apps using Adobe’s Flash CS5 software) from the iPhone 4 S. In Apple’s agreement with app developers, it states: “Applications may only use Documented APIs in the manner prescribed by Apple and must not use or call any private APIs.” Adobe Flash’s Flash-to-iPhone compiler API is built using Flash CS5, a private API that Apple can’t fiddle with. Uh oh.
April 20, 2010
Adobe officially abandons plans to bring Adobe Flash to Apple’s iPhone and iPad. Years of bickering between the two companies ensue.
April 29, 2010
Apple CEO Steve Jobs writes a now-infamous 1,600-word explanation of 6 reasons why Apple products such as iPhones, iPads, and iPods will no longer support Flash, entitled “Thoughts on Flash.” The most important for Jobs was the undesirability of having third-party layers of software between the developer and the platform, which chains developers to libraries and tools that they have to wait for third parties to update, slowing down the development process.
Adobe shelves its Flash software for mobile devices altogether and shifts to HTML5, the more widely-accepted standard for displaying content on the Web. This doesn’t solve much though. As CNN Money notes two years later, Adobe’s source code is so old in comparison to everything else that this is a Band-Aid on a bullet wound.
June 28, 2012
Adobe announces that the Android 4.1 update will not support Adobe Flash by default. It was removed from the Google Play Store on August 15, 2012, though devices that already had it downloaded can continue to use it.
Hackers gain access to the names, encrypted passwords, and credit card information of 3 billion Adobe Flash users. This was achieved through the theft of source code for Adobe Acrobat, ColdFusion, ColdFusion Builder, and other Adobe products. Turns out, Adobe’s core code was so old that knowing just a few lines of it was enough to access the ecosystem.
October 28, 2014
HTML5 is officially endorsed as a stable recommendation by the W3C Committee, 17 years after the last update in 1997. It’s superior to Flash because it has mobile capabilities, a key area where Steve Jobs felt that Flash fell short.
July 13, 2015
Firefox’s support lead Mark Schmidt announces on Twitter that Flash is blocked by default on Firefox browsers due to two unpatched vulnerabilities — vulnerabilities that are unknown to the vendor (in this case, Firefox) and are hence easier to exploit by hackers.
— Mark Schmidt (@MarkSchmidty) July 14, 2015
“It’s our policy to block vulnerable plugins. What made this block different was that we did it before Adobe made an update available,” Schmid told Digiday. Yesterday, Adobe updated Flash to fix the vulnerabilities, but Schmidt says that the decision was made before the updates were posted. “The public nature of the vulnerabilities, thanks to the Hacking Team dump, were a factor in the decision to block before an update.”
In the end, abandoning Flash might be Adobe’s opportunity to finally embrace the possibilities of mobile and reestablish trust with users. As CNN Money noted back in 2011, Adobe makes no money from the technology when a video is streamed or someone plays a game using Flash technology. Furthermore, as Mary Meeker noted in her 2015 Internet Trends report at Recode’s Code Conference in June 2015, mobile penetration is at 73 percent globally, so a more mobile-friendly technology such as HTML5 would be preferable for web developers and users.
Whatever happens, Schmidt is pleased that this long-standing issue is being discussed. “I’m glad to see the tech community talking about the possibility of an EOL [end of life] date for Flash. I think that’s a good thing,” Mark Schmidt told Digiday.
‘There was nowhere to air it’: Why a CBD brand is leveraging digital video as part of its ad strategy
Two years after the Farm Bill legalized hemp, CBD brand Sagely Naturals is adding video advertising to its marketing strategy.
Consultancy businesses tried to promise they’d upstage agencies — it hasn’t really worked like that
So far this year there has been about $15 billion dollars worth of media billings by advertisers to marketing services businesses — none of which has gone to consulting firms.
Member ExclusiveDigiday+ Research: The future of agency work is remote(ish)
The share of agency professionals who said they do not want to return to full-time office work has risen by more than 40% this year.
SponsoredMarketer’s playbook: Delivering performance alongside privacy
Jonathan Meltzer, director of marketing, ads privacy, platforms and measurement, Google One way to prepare any business for what’s next in 2021 and 2022 is to invest in data and insights. However, shifts in consumer expectations challenge even the most experienced marketing team to find safer ways to show people ads and measure campaigns. To […]
How esports org 100 Thieves will boost its M&A strategy with $60M in Series C funding
As esports organizations expand their offerings in search of a cohesive and profitable business model, the acquisition of new companies can help bring in fresh ideas and unique revenue streams.
‘Brands have really taken note of this interest’: How Sanctuary is partnering with brands as Gen Z, millennials seek out astrology content
This year, brands like McCormack, Venmo, Away, Benjamin Moore and Le Creuset have worked with Sanctuary to create custom branded content -- matching paint colors, spending habits or cookware to specific astrology signs, for example -- that’s then posted on Sanctuary’s Instagram page.