Live data from Hacker News

Firefox makes click-to-activate Flash the default

support.mozilla.org

131–140 of 398 posts

Re: Firefox makes click-to-activate Flash the default

#131
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

Yes but Flash vulnerabilities are incremental vulnerabilities.

So just counting high severity vulnerabilities, the chart is

IE: 314. IE with Flash: 483.

Chrome: 154: Chrome with Flash: 323.

Firefox: 86. Firefox with Flash: 255.

And of course, you can add a third column for Java and a fourth column for browser with Flash and Java.

I have no idea what their bugs-per-line-of-code are, perhaps they have the finest code on the planet. But from a surface area perspective, installing Flash makes you more vulnerable, period. And it really is not necessary, whereas it’s not like you can browse the web in pure Flash and not install a browser.

Re: Firefox makes click-to-activate Flash the default

#132

I uninstalled Flash a few days ago, because I didn't want to deal with the updates anymore. Since Flash was unbundled from Mac OS X it has become a pain to update. I simply don't understand why I need to go to the Adobe site to get the updates. Flash isn't super relevant anymore anyway, the main thing it's used for on my computer is Flash tracking cookies, and I can do without those. I do wonder how some of the track…

The only other place where I've found that flash is relevant is in auto-play videos, so now with flash installed but disabled is basically removing the auto-play 'feature', which is really neat.

? http://www.w3.org/TR/html5/embedded-content-0.html#attr-medi...

Re: Firefox makes click-to-activate Flash the default

#133
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

I have a lot of experience of end users and they are forever telling me that they get so many different "Update this", "Update that" windows that they can no longer distinguish real from fake. Some of them have been tricked by fake web site pop-ups as a result, others ignore legitimate update messages. I do not blame them. Internet Explorer and Google Chrome get updated in a way that most end users find to be simple…

I have had multiple non-technical friends, in one case on a fresh install I'd done myself, run into the Flash update window simply showing a gray background that never does anything.

The best solution for this, from Adobe's own forum? Find the corporate-deployment version, download that (ignoring the messages that say it isn't what you want) and run it. This works flawlessly, but even less automatically.

Both the Flash and Java updates almost feel like "Pay Attention To Me!" Just like all those discount cards that exist in part so you carry around a fetish with the corporate logo.

Re: Firefox makes click-to-activate Flash the default

#134
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

Cost/benefit seems higher for Flash/Java than browsers. You really need a browser, but you don't really need a [fancy thing that can't be done in JS]. As another commenter said, it doubles your attack surface and for little benefit. Flash game enthusiasts would probably disagree, but most of us can probably do without it given the risk.

As an enthusiast for a handful of flash games, it is increasingly tempting to make a VM just for running them. Even then, with all the progress in Javascript, it's questionable whether I should bother.

Re: Firefox makes click-to-activate Flash the default

#135
post #42

Bugs are always bad (and security bugs even more so) - but I've always felt that Flash gets a disproportional amount of hate/hype in the media. To some degree it should be normal that the more widespread a technology is - the more it gets targeted for security exploits. If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014): - Internet…

I have a lot of experience of end users and they are forever telling me that they get so many different "Update this", "Update that" windows that they can no longer distinguish real from fake. Some of them have been tricked by fake web site pop-ups as a result, others ignore legitimate update messages. I do not blame them. Internet Explorer and Google Chrome get updated in a way that most end users find to be simple…

Yes! I admin my parents' computers and after trying to explain which 'update' windows are genuine, I realised that there just isn't a good way to tell them apart.

Silent auto-updates are really the right way to go for non-techies. Even the post-upgrade 'announcement' popups are confusing. For instance, I've installed Ghostery on their computers and the 'ghostery has been updated' popup is just confusing for them, leading to confusion and phone calls to me.

Flash also doesn't seem to auto-update for them, despite me setting it up. I don't understand it either, as they turn off & on the machine regularly. Why can't Adobe get this right?

Re: Firefox makes click-to-activate Flash the default

#136
post #127
post #54

Earlier quoted context omitted.

> However, Mozilla can't ship it enabled Just a minor nitpick: Under Linux, people don't download from Mozilla but have it installed by default. If not, they install via package manager and not via download from Mozilla. So it's not Mozilla making that decision, but the respective Linux distros. But of course they have the same problem. I believe a good compromise would be to check if ffmpeg is installed on the syste…

Mozilla does not allow Firefox trademark use for distro customized builds.

False. It's allowed as long as Mozilla approves the changes. This is how Ubuntu ships Firefox.

Re: Firefox makes click-to-activate Flash the default

#137
post #73

Earlier quoted context omitted.

The new Google Maps is also dramatically slower, laggier, and buggier than the old version which was a regular web app built to work on browsers from 2005. I think the terribleness of recent Google web front-ends (not only Maps and Street View but also Search, Mail, Groups, Gplus, etc.) is mostly a product of incompetent management process internal to Google, rather than an indictment of web technology generally.

FWIW, Google Maps are generally noticeably slower and laggier in Firefox when compared to Chrome.

Maps straight-up crashes ff for me when zooming.

Re: Firefox makes click-to-activate Flash the default

#138
post #59

Earlier quoted context omitted.

Copy to clipboard, apparently. (Github project pages have a flash application to handle this)

Good news, we're getting there. In Chrome 43 and (probably) Firefox it's supported: http://caniuse.com/#search=clipb (see note 3) However the API is god awful.

Isn't this like a huge security risk?

Re: Firefox makes click-to-activate Flash the default

#139
post #86
post #58

Earlier quoted context omitted.

So Flash is second in terms of number of high severity bugs and first in terms of the percentage of bugs that are high severity, only being beaten by Internet Explorer . By your evidence the hate for Flash is quite justifiable.

It's second to IE in both those metrics, but "percentage of bugs that are high severity" seems like a strange thing to be measuring in any case.

Perhaps it's intended as a proxy for overall quality.

Re: Firefox makes click-to-activate Flash the default

#140

Earlier quoted context omitted.

Good news, we're getting there. In Chrome 43 and (probably) Firefox it's supported: http://caniuse.com/#search=clipb (see note 3) However the API is god awful.

Isn't this like a huge security risk?

Why? Copy FROM clipboard would be, sure. Copy TO clipboard... OK, I can come up with scenarios where it'd be a problem, but they're pretty far-fetched.
Post reply on HN