Live data from Hacker News

Firefox makes click-to-activate Flash the default

support.mozilla.org

41–50 of 398 posts

Re: Firefox makes click-to-activate Flash the default

#41
post #27
post #16

Earlier quoted context omitted.

Actually, Firefox uses the platform decoders to decode patented codecs like H264 or AAC. So the operating system does play a role. I also think it's not unreasonable to believe that hardware accelerated H264 decoding works less well on Linux.

Good catch. So replacing "HTLM5" with "video codes", this may have a point. But I'm still wondering, as we have very good decoders from projects like FFmpeg and VLC. (Not sure which of all those decoders are used by Firefox.) These are platform independent and to my experience better than the platform specific libraries. For example, I often hear that people install VLC under Windows because it decodes lots of video…

Firefox can actually use ffmpeg as a decoder. It would be a great option for supporting a lot of these formats. However, Mozilla can't ship it enabled, because the patent problem is very real. See, for example, all of the Play Store apps that got C&D letters from Dolby for using ffmpeg's implementation of AC3.

Firefox does ship a lot of other video and audio codecs though, such as vorbis, opus, theora, vp8, and vp9. It's recommended to use these for HTML5 when possible because they can be easily supported everywhere.

Re: Firefox makes click-to-activate Flash the default

#42
Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits.

If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014):

  - Internet Explorer 366 total vulnerability issues (314 high severity)

  - Google Chrome 235 total vulnerability issues (154 high severity)

  - Adobe Flash 207 total vulnerability issues (169 high  severity)

  - Mozilla Firefox 190 total vulnerability issues (86 high severity)

  - Oracle Java 161 total vulnerability issues (69 high severity)
[source] https://nvd.nist.gov/

Re: Firefox makes click-to-activate Flash the default

#43
post #30

One option was to go down the Click-to-Play route which offers a HORRIBLE UX. Especially on Youtube which still uses Flash by default. Disabling Flash however, Youtube actually seamlessly falls back to HTML video. Well done. But I can't help but think, outside the Youtube world (BBC for e.g.). LOTS is going to break. I wouldn't take this tact with my parents or clients.

> Especially on Youtube which still uses Flash by default

No since January[1]. Maybe you have an old cookie set or something?

[1] http://youtube-eng.blogspot.com/2015/01/youtube-now-defaults...

Re: Firefox makes click-to-activate Flash the default

#44

I uninstalled Flash a few days ago, because I didn't want to deal with the updates anymore. Since Flash was unbundled from Mac OS X it has become a pain to update. I simply don't understand why I need to go to the Adobe site to get the updates. Flash isn't super relevant anymore anyway, the main thing it's used for on my computer is Flash tracking cookies, and I can do without those. I do wonder how some of the track…

On the Mac, it's easy, I use Chrome as my Flash jail. I use Safari all the time and the few times I need Flash I fire up Chrome and it's there. Don't have to worry about Flash hacks or Chrome battery drainage.

Re: Firefox makes click-to-activate Flash the default

#46
post #30

One option was to go down the Click-to-Play route which offers a HORRIBLE UX. Especially on Youtube which still uses Flash by default. Disabling Flash however, Youtube actually seamlessly falls back to HTML video. Well done. But I can't help but think, outside the Youtube world (BBC for e.g.). LOTS is going to break. I wouldn't take this tact with my parents or clients.

> Especially on Youtube which still uses Flash by default No since January[1]. Maybe you have an old cookie set or something? [1] http://youtube-eng.blogspot.com/2015/01/youtube-now-defaults...

From the link: "and in beta versions of Firefox" Maybe he's still using a Firefox stable version a few months old?

Re: Firefox makes click-to-activate Flash the default

#48
post #14

I hope this will be another push for content creators to abolish flash in the long term.

I hope this will not make more content creators choose that annoying unity3D plugin thing that doesn't support linux for games.

> that doesn't support linux for games.

There is support: http://pipelight.net/cms/installation.html

For me on debian it was install and it worked without even restarting the browser.

Re: Firefox makes click-to-activate Flash the default

#49
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

Yes, but Flash alone doubles the attack vector of a browser - that's nothing to be sneezed at. I think it's particularly poignant when you look at the high severity metric.

Re: Firefox makes click-to-activate Flash the default

#50
God will Flash just die already. Firefox is my primary browser and I run it without Flash. On the very odd occasion I need it I have IE in protected mode which has Flash built in. If a site does use Flash I will seek an alternative though as I hate it that much.

On a side note Firefox without Flash is so much smoother. IMHO it is the fastest and most stable browser when it doesn't have Flash bogging it down.

Post reply on HN