Australia's Leading Computer Emergency Response Team

Adobe Flash Player 11 and AIR 3
Date: 05 October 2011
Original URL: http://www.auscert.org.au/render.html?cid=7066&it=14918

Given the recent history of Adobe products, I have the Adobe security page on speed dial. So I was slightly curious as to why I found out about a security update from SANS and not Adobe.

Adobe states that "this release includes new features as well as enhancements and bug fixes related to security, stability, performance and device compatibility". So I read on to find out what these security fixes were that didn't rate a mention on the official site.

After much reading, and some creative thinking I have decided that the security must have been related to the words "new features as well as enhancements" rather than "bug fixes". The following are some of the features that could be labelled as security features. The first one is more related to securing content, whereas the second two are actual security features.

  • Protected HTTP Dynamic Streaming (HDS) — Protected HTTP Dynamic Streaming (HDS) provides protection for streaming video across screens while eliminating the deployment complexity of a license server.
  • Secure Random Number Generator — Developers can now take advantage of cryptographically secure random number generation to build more secure algorithms and protocols.
  • TLS Secure Sockets Support (new for Flash Player) — Enables secure communications for client/server applications.

Richard