Live data from Hacker News

Firefox makes click-to-activate Flash the default

support.mozilla.org

91–100 of 398 posts

Re: Firefox makes click-to-activate Flash the default

#91
post #59

Earlier quoted context omitted.

> We need a real open-source alternative to flash player. We quietly built the alternative to Flash over the last 10 years. It's called the web. A standard document in the web browser can play audio, video, display vector graphics, utilise OpenGL, supports direct drawing via Canvas, and it is deeply scriptable with a mature, open programming language. What else do you need?

Copy to clipboard, apparently. (Github project pages have a flash application to handle this)

Good news, we're getting there. In Chrome 43 and (probably) Firefox it's supported: http://caniuse.com/#search=clipb (see note 3)

However the API is god awful.

Re: Firefox makes click-to-activate Flash the default

#92

God will Flash just die already. Firefox is my primary browser and I run it without Flash. On the very odd occasion I need it I have IE in protected mode which has Flash built in. If a site does use Flash I will seek an alternative though as I hate it that much. On a side note Firefox without Flash is so much smoother. IMHO it is the fastest and most stable browser when it doesn't have Flash bogging it down.

The problem is the long tail of sites or site features that don't work without flash and users who rely on those sites or site features. I've heard Facebook video and last.fm streaming don't work without Flash for eg.

> I've heard Facebook video and last.fm streaming don't work without Flash

Regarding Facebook video, I fail to see how that is a bad thing ;)

Re: Firefox makes click-to-activate Flash the default

#95
post #84
post #60

Earlier quoted context omitted.

Remote code execution exploits were found in Firefox at least once per month during the first half of 2015. The only reason we didn't hear about these cataclysmic exploits is because it wasn't Flash. January 20, 2015: https://community.rapid7.com/community/metasploit/blog/2015/... February 25, 2015: https://msisac.cisecurity.org/advisories/2015/2015-018.cfm March 1, 2015: https://www.mozilla.org/en-US/security/adviso…

Mozilla seems to take anywhere from 1 to 3 months to fix these severe bugs. Adobe takes days. Source for this complete and utter FUD? Certainly not the links you gave: Jan 11, 2015: Originally reported to Mozilla as a low-severity DoS, which turned out to be already patched in trunk Jan 13, 2015: Firefox 35.0 shipped with patch It's hard to get dates out of the others because the bugs are still hidden, but the "fixed…

You're right, I misinterpreted the timeline there.

Re: Firefox makes click-to-activate Flash the default

#96
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

Turing-complete machine running untrusted code is a nightmare for security. There always be bugs and exploits, it's just a matter of time and effort to find them.

JavaScript enabled by default is already bad enough. We don't need Flash, Java, ActiveX or anything similar turned on by default. So it's a good move from security viewpoint. Less attack surface.

Re: Firefox makes click-to-activate Flash the default

#97

What about Java?

Java plugin you mean right the one that runs on browsers?. Java itself is a huge topic including JDK, compilers, runtimes, server side etc.

Of course he means that, do you know the thread you are posting to?

Re: Firefox makes click-to-activate Flash the default

#98
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

I have a lot of experience of end users and they are forever telling me that they get so many different "Update this", "Update that" windows that they can no longer distinguish real from fake. Some of them have been tricked by fake web site pop-ups as a result, others ignore legitimate update messages. I do not blame them.

Internet Explorer and Google Chrome get updated in a way that most end users find to be simple to understand, particularly with Chrome. Firefox is also quite good in this regard. All of them are reliable - it is rare, IME, to come across a Windows Update, Firefox or Chrome instance which is silently failing to update. Or not even bothering to prompt to update.

Flash, however often I install it, just doesn't seem to auto-update reliably. Quite often it only does so after a user log on/reboot, which doesn't happen much in the days of standby. Even on brand new, fresh Windows installs (so we know the OS/Flash isn't broken), I test Flash from time to time and it just doesn't prompt to update at all on some occasions. This is what makes Adobe's poor track record exponentially worse - that their software update mechanism is crap at best.

I was gobsmacked when Microsoft declared they were going to start updating Flash via Windows Update. Gobsmacked and so very relieved. It felt like they'd walked into Adobe's office, grabbed their fire extinguishers and told them "You are so useless that when there's a fire, WE will come and put it out, since you don't seem able to. We are sick of our offices getting burned down because of your idle incompetence."

I won't even address Oracle's Java. Bundling malware with their updater is tantamount to crime.

Re: Firefox makes click-to-activate Flash the default

#99
post #58
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

So Flash is second in terms of number of high severity bugs and first in terms of the percentage of bugs that are high severity, only being beaten by Internet Explorer . By your evidence the hate for Flash is quite justifiable.

Flash bugs are more important because the are crossbrowser. I will still use Flash though on older computers, because it needs less resources for video.

Re: Firefox makes click-to-activate Flash the default

#100
post #89

Earlier quoted context omitted.

EME is not present on Linux yet I think. I don't really mind this however it does mean no Netflix without Google Chrome..

EME is there, but you don't have the CDM. Outside HTML5 scope, though.

How to disable?
Post reply on HN