Today I came across an interesting corporate attitude. We have been building a range of Flash-based sites and are gearing up to launch them over the coming months.Throughout development, the security guys in the organization have been casting a critical eye at Flash as a technology platform - especially at some of the recent security holes. This is not unlike most operating systems and Web browsers, yes there are holes and they get fixed - with Flash it is certainly something that Adobe are very pro-active when it comes to addressing. Plus most of these issues require access to the SWF file itself…. you would think that if this were true then we would have a bigger problem on our hands!After addressing these whilst in the States, I was thinking that everything was calmed down, and that the security guys (who don’t seem to fully understand or ‘get’ the Web) had been reassured. I was wrong! I was reading the minutes of a meeting between senior technical architects this morning, and this beauty jumped out at me…
The team felt as good corporate systems, a project should be initiated to display a message to the Customer regarding the use of Flash, and its potential vulnerabilities. For example, in a pop-up window, whenever Flash is going to be executed or downloaded.
Its amazing how one paragraph can make you both smile, cry and bang your head on a desk!Aside from the question as to why anyone would ever thing this is a good idea, is it really wise to tell the user that there are potential security vulnerabilities with a Website? How would you feel if you go to an e-commerce site and are presented with a message like this:
Hello, welcome to SourceBottle!This site uses XY & Z, which have been found to have several, mostly theoretical, security vulnerabilities which may cause your personal details to be compromised.have a nice day!
Madness! It certainly gives the impression that the company doesn’t know what they are doing. In an age of increasing paranoia about security, I would also imagine that most users would quickly leave the Website and choose to start looking around at the competitors!Oh well… it least it made me smile! (more…)

