Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

A company I deal with have the following mitigation in place:

Cross fingers until next Tuesday.



While you're probably joking, this seems incredibly incompetent since a better mitigation exists:

Disable Adobe's flash plugin on IE.


Unfortunately I'm not joking. They have 2500 workstations running something written in Adobe Air so no banana with removing flash.


AIR should still run with flash. Just the IE plugin needs disabling you don't have to remove flash.


The page they hit to launch it uses flash as well. The thing is a giant turd. We're currently rewriting it.


Can you register a custom protocol handler like air://example.com/airApp.air and use that link?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: