The flash player seems to only be available over HTTP, not HTTPS.
How do I download and install the player securely - in a way that isn't vulnerable to a MITM (man-in-the-middle) attack?
Hi, This is why you always want to Uninstall/Install from the Adobe Site. You can download and SAVE the Uninstaller to your Desktop and also the Installers. As long as you follow the Uninstall instructions and the Install instructions, you can disconnect from the Internet and Install from your Desktop.
The Adobe Flash Player Uninstaller is here:
http://kb2.adobe.com/cps/141/tn_14157.html
You can find information for the Manual Installers here and also various instructions and settings needed.
http://kb2.adobe.com/cps/191/tn_19166.html
Hope that helps.
eidnolb
No that doesn't help at all. Those instructions direct users to the Flash Player Download Center. It is impossible for users to securely download Flash from the Flash Player Download Center.
ʇɐb ɹəuəllıʍ,
Yes, well, only Adobe can fix the problem; I was hoping some Adobe employee would happen to notice and take action, given this is a Critical security vulnerability; You agree this is a valid problem, right?
I was not aware of a way to get in touch with Adobe to report unresolved security vulnerabilities. I just poked around and http://blogs.adobe.com/psirt/ eventually led me to the Adobe Security Report Form which I've filled out.
(Amusingly, Adobe's "Notifying Adobe of Security Issues" web page says, "Adobe takes security very seriously and aims to quickly address any security-related problems involving our products. We've set up an email address that customers can use to report security issues to us directly." In fact, it seems they do not, as they've not provided this "email address that customers can use to report security issues" on said web page.)
We'll see if Adobe finally gets its act together.
I'd recommend posting on our security form (see link below.) I can't promise that you'll get a response, but this issue will be reviewed. I'd recommend asking for a response though, given your concerns.
http://www.adobe.com/support/security/alertus.html
Thanks,
Chris
Chris, thanks for trying, but I've long since done that.
You weren't looking closely enough at what I wrote, which indicated I'd already done so: I wrote, "I just poked around and http://blogs.adobe.com/psirt/ eventually led me to the Adobe Security Report Form which I've filled out."
The text "Adobe Security Report Form" in my earlier post is linked to the URL you posted.
It's the same Security Report (Form) I refered to two more times when I wrote:
North America
Europe, Middle East and Africa
Asia Pacific
Copyright © 2012 Adobe Systems Incorporated. All rights reserved.
Use of this website signifies your agreement to the Terms of Use and Online Privacy Policy (updated 07-14-2009).