Chrome will begin pausing many Flash ads by default on September 1
plus.google.com
plus.google.com
https://chromium.googlesource.com/chromium/src.git/+/master/... (See constants)
and
https://chromium.googlesource.com/chromium/src.git/+/master/... (See ShouldThrottleContent)
TLDR, essential content is either:
1) On the same domain as the page
2) Considered "Large" (at least 298 x 398, certain aspect ratio, minimum total area), with an exception for tiny content (likely transport plugins).
ZeroClipboard is used by Github and lots of other sites for the little buttons next to repo URLs, etc.
1 - https://github.com/zeroclipboard/zeroclipboard 2 - http://caniuse.com/#search=clipboard
So why do we need Flash for clipboard actions today?
- http://venturebeat.com/2015/02/25/google-now-automatically-c...
- https://code.google.com/p/chromium/issues/detail?id=467709
- https://plus.google.com/+ArtemRussakovskii/posts/MtcZGJprWje
"Browser developers should also consider what they can do to reduce fngerprintability, particularly at the JavaScript API level."
"We identified only three groups of browser with comparatively good resistance to fngerprinting: those that block JavaScript, those that use TorButton, and certain types of smartphone."
Not having Flash doesn't mean you're immune to fingerprinting. That said, it would be nice if Adobe prevented system font lists via Flash.
I wonder if browsers' plugin sandboxes could block Flash from calling the OS API to enumerate system fonts.
On the security issues it's some what true because the nature of Flash, applications like these are almost impossible to sandbox properly unless you have an operating system that sandboxes everything by default.
Flash it self these days is pretty much code execution as a service it can do pretty much everything you want some browsers sandbox it better than others but it's still intended to pull code from the ether and run it and when you have a setup like that you will never be able to limit it effectively. Flash can be phased out only because it's mostly used to play various forms of media, but any other use of it cannot be converted to HTML5.
If Javascript (as it's parsed and executed in browsers) will ever get to the point of being as flexible and powerfull as Flash is today you'll see browser based RCE vulnerabilities skyrocket also, JS is safe to use only because the browsers restrict it, Flash and AIR are intended to support everything from an animated ad to a full desktop application.
Just look at Node.JS (and many NoSQL DB's that used JS) in it's early years almost every (non-DOM based) cross-site scripting vulnerability in a Node.JS application could result in remote code execution on the server, even today you can still easily cause it if you don't handle the code properly one stupid eval in your node code which was there for lazy debugging can lead to your box getting owned in minutes.
That wasn't what Apple (Steve Jobs) claimed... [1]"Whenever a Mac crashes more often than not it’s because of Flash. No one will be using Flash, the world is moving to HTML5." Also Flash doesn't crash Chrome, doesn't crash FF for ages either. No clue about Safari the quote was debunked by everyone, even Apple backtracked on it to a more "we meant Safari in certain cases" type of statement. we can all move along.
[1]http://www.digitaltrends.com/computing/steve-jobs-unleashes-...
So, the language about crashes may have had more or less basis in reality, but it's not as if Jobs was concerned with nuance and details.
That said, two of the biggest web browsers have not natively supported flash ads for years. So I'm puzzled that ads are still being produced in 2015 for a dying runtime.
So, in general, swiffy appears to be a relatively heavyweight solution that
is not (yet?) optimized for mobile devices. Morever, there are 4 (yes 4!)
giant swiffy ads on the landing page of androidpolice.com, each of which
consumes more than half the viewport, all of which are dynamic.I'm not surprised. As someone who has worked with it (and even written pieces of a simple Flash renderer), SWF was designed to be an extremely compact format and is far simpler to parse and render than the HTML + CSS + SVG + JS replacement that's being promoted.
In that respect, all the complaints about Flash and mobile battery life should be attributable to the mere presence of Flash content. The reason why disabling Flash improves battery life is because the content doesn't get rendered. If the same content were present and rendered with HTML5 it would require more computing power, because the overhead of parsing (several!) text-based formats and using a complex rendering model originally designed for static documents compared to a binary format and rendering model designed for interactive animations, simply cannot be eliminated. I suppose new standards for documents, vector images, and scripting could be designed (WebAssembly comes to mind), but at that point you'll just be reinventing Flash/SWF...
For that reason, disable JS and you will get improved battery life too:
https://www.reddit.com/r/apple/comments/2lent3/fwiw_disablin...
the Flash Player plugin can render hardware accelerated video since v10.2 (released early 2011).
http://blogs.adobe.com/flashplayer/2011/02/flash-player-10-2...
"For example, using Flash Player 10.2 with Stage Video hardware acceleration, we’ve tested a Mac Mini released two years ago and a low-powered GPU-enabled Windows netbook playing smooth full HD 1080p video using less than 8% of the CPU; more powerful computers use even less."
So another interpretation is: Apple was well aware that smooth video playback was coming to other platforms and Jobs piece (and opening up the acceleration API) was an reaction to that.
[1] http://www.adobe.com/cn/devnet/flashplayer/articles/fplayer1...
I'm aware of that but the quality of the actual implementations still varies widely. I've done the comparison periodically since that was released and their quoted figures have never reproduced on any Flash video player which is actually used on the web (YouTube, Vimeo, jwplayer and a few other open-source projects, the custom players used by various big media companies, etc.).
On OS X or Windows XP-8.1, on multiple devices, it's consistently been the same: Flash = fan on high, HTML5 = fans off. Flash's settings show hardware acceleration enabled but there's either a really restrictive hardware check quietly disabling it or absolutely nobody ever managed to ship a player using Stage Video, including the companies quoted in that press release.
0.0.0.0 www.autofixinfo.com # Autoplay video
0.0.0.0 c.brightcove.com # Autoplay video
0.0.0.0 player.theplatform.com # Autoplay video
0.0.0.0 link.theplatform.com # Autoplay video
0.0.0.0 ci-2862d2c8d6-68f418d2.http.atlas.cdn.yimg.com # Autoplay video
0.0.0.0 video-img2.thedailymeal.net # Autoplay audio
0.0.0.0 ht1.cdn.turner.com # Autoplay video
0.0.0.0 ht2.cdn.turner.com # Autoplay video
0.0.0.0 ht3.cdn.turner.com # Autoplay video
0.0.0.0 ht4.cdn.turner.com # Autoplay video
0.0.0.0 ht5.cdn.turner.com # Autoplay video
0.0.0.0 ht6.cdn.turner.com # Autoplay video
0.0.0.0 ht7.cdn.turner.com # Autoplay video
0.0.0.0 ht8.cdn.turner.com # Autoplay video
0.0.0.0 ht9.cdn.turner.com # Autoplay video
Protip: install dnsmasq which allows you to block entire domains rather than listing hosts independently.(Note: corrected s/VPN/OVP, see followup.)
Uh... oh! You meant CDNs? I'd suspect there'd be a lot of collateral damage if you block entire CDNs, no?
"Tips for Choosing an Online Video Platform (OVP)" http://www.streamingmedia.com/Articles/Editorial/Featured-Ar...
Yes, there's collateral damage. I'll take it. If needs be, I'll hop into /etc/hosts and unblock for a moment.
I personally find it very convenient.
You'll need to right click and run the script as Administrator since it is accessing your System32 folder.
I've got a set of scripts for updating and toggling hosts files.
Tablets, mobile phones and computer systems as normal user, no such luck.
Plugins such as uBlock Origin should allow for adding hosts to blocklists.
In fact I've (unintentionally) bypassed site-blocking on some public networks, just because I configure my devices to use public DNS servers instead of whatever the DHCP provides.
0.0.0.0 c.brightcove.com # Autoplay video
0.0.0.0 player.theplatform.com # Autoplay video
0.0.0.0 link.theplatform.com # Autoplay video
Wow you really must not like video.Killing the source is the only option.
Edit: Have some bug links
Original reporter suggesting the setting should apply to HTML5 media. Includes a very long discussion of the problem and why it's difficult: https://bugzilla.mozilla.org/show_bug.cgi?id=659285
Bug about websites that assume autoplay works, marked invalid because those websites shouldn't(?) make that assumption: https://bugzilla.mozilla.org/show_bug.cgi?id=1173848
> act slightly wonky when it doesn't.
I would hope so. Autoplay videos are fraught with discrimination: "live in a country where bandwidth is expensive? Fuck you, have an autoplay video."
I hope browsers move toward having autoplay as default "off" in the future.
Horrible. That's why people use ad blockers.
https://plus.google.com/104092656004159577193/posts/CQAJEyHG...
"Disable video/audio autoplay" https://code.google.com/p/chromium/issues/detail?id=514102
Where is Flash still essential?
bbc iplayer on Mac and GNU/Linux
- Facebook (videos)
- Twitter (bizarrely uses it for gifs in Firefox)
- YouTube
- BBC news
- The Independent and most of UK press
- Basically any site with embedded video
- even github prompts because of that copy+paste feature
I have no interest in Flash games or adverts, so it's annoying that these big sites all still use Flash.Many embedded videos often don't, though.
Though for Flash that's already possible. It's HTML5 that's bugging the shit out of me now.
For Firefox, I think you can just set media.autoplay.enabled = false in about:config.
Now if only they can start optimizing Chrome urgently, that'd be just great!
Why am I feeling that Crysis may be more reasonable than Chrome?
Yeah, because WebGL never crashes the browser (not even the kind of small demos that seems to be all it's used for).
The problem with WebGL is that it pretty much inherited the mess of OpenGL every driver version on every GPU can implement different feature set of it (similar to the extension mess of OpenGL in Nvidia and ATI minidrivers at the time) which results in Browsers having to maintain blacklist/whitelists[1] for a very large array of hardware and software combinations (Chrome currently isn't maintaining a driver version based list other than a cut off date for certain drivers which also causes problems if you are running old hardware and the best drivers for it are considered out of date by Google).
WebGL it self is also not implemented in the same manner across different browsers Chrome and FF for example have quite a different blacklist/whitelist for WebGL, I don't know if this because of different in browser implementation or because of they are simply encountering different issues and adjusting accordingly.
The worse thing I've encountered so far is WebGL on switchable graphics (e.g. Nvidia Optimus) enabled laptops, some features might switch the GPU arbitrarily even mid execution which causes the whole thing to implode..
[1]https://chromium.googlesource.com/chromium/src/gpu/+/master/...
Whats worse is that WebGL can actually crash your graphics driver and if it's bad enough than Windows can't recover the kernel mode driver it's a complete kernel panic. This doesn't happen often but if you want to do it you can do it sadly too easily, Chrome/FF chase known DOS cases with WebCL quite well but they really don't catch all of them and if that feature isn't blacklisted for your setup well you can crash a machine with a single pixel draw ;)
And the introduction of WebCL would probably lead to some of the nastiest RCE vulnerabilities you can imagine soon enough you are allowing people to execute general purpose code directly on the metal and interact with Kernel mode components. There are already GPU rootkits out there soon enough they'll find an infection vector trough WebGL or WebCL and it will be a very unpleasant period.
Also are you sure they still use ANGLE by default? Both Chrome and FF had the ability to enable native support years ago using –use-gl=desktop for Chrome or webgl.prefer-native-gl for FF, 2-3 years ago that was the only way of getting any reasonable performance out of them..
But even with ANGLE, WebGL feature implementation is still not consistent across hardware and drivers (Graphic drivers treat DX like one would treat a 5 year old, they'll hear it and do what they want ;)) from even a single vendor yet alone across the 3 desktop and 3-4 mobile GPU vendors.
Unfortunately the abstraction layers aren't yet good enough that something stable on nvidia will be stable on ati :)
Only the 3rd properly applies to Chrome and Flash. Chrome didn't embrace an API they could extend; they shipped a plugin providing an ~ABI of a foreign/closed API then still had to make atomic decisions like this one.
Before that on FF i had an add on that disabled autorun for flash also (very similar to how chrome does it with plugins gotta right click to load it).
But if Google does it only for none Google adnetworks that's going to be a huge lawsuit. The article doesn't really clarify why would it work on Google own networks because they convert to HTML5 or because they will white list their own stuff.
TBH we could've gotten rid of Flash years ago, Google was actually a big supporter for Flash, it was very important for them at some point in time, Google Chat, Gmail Extensions, Google Wave, and most importantly getting high bit rate video on YouTube off the ground (DXVA, OpenGL support was critical for YouTube and every other streaming site out-there), and heck Google promoted Flash on Android until JB as their big gotcha over Apple..
But if Google does it only for none Google adnetworks that's going to be a huge lawsuit. The article doesn't really clarify why would it work on Google own networks because they convert to HTML5 or because they will white list their own stuff.
It's because their ad network converts stuff, at least that's the only way I can read these sentences: Google said advertisers who are worried about having their ads switched off should consider converting their Flash artwork to HTML5. According to the cyber-goliath, "most Flash ads uploaded to [Google] AdWords are automatically converted to HTML5."
So, in other words, if you're not on Google's ad network, you're locked out of Chrome – unless you also switch to HTML5 artwork.The opening subtitle can be also interpreted both ways, in fact most people would say that "If your ads aren't on web giant's network, they better be HTML5 – or they're dead to Chrome." means that Google will block Flash from every source but Google.
that should be the default. And that's also going to be impossible now those annoying bits will be HTML5.
People don't like ads they use adblockers, site revenues go down advertisers find new and even more invasive ways to display ads. Wont be surprise if in a year or 2 how content will work is that all (actual) content on the site will be encrypted and encoded into and then decoded using JS and the only way to get the decryption key is to load and play trough the ad to the end. Heck with how cheap symmetric encryption is becoming on modern CPU's not to mention GPU's it won't cost that much to implement. The CDN runs the content, the CDN runs the ad's one doesn't fully load without the other...
If i was bored enough or evil enough i would write this myself but any evil exec's listening you are free to take this idea :)
On the other hand, I think Chrome is the only major browser that ships with the ability to play Flash, so one could argue that it is just altering the benefit that Google has been providing to all Flash providers for years.
Sometimes I forget to turn ad-block back on after testing stuff. Thanks Google.
Though better sandboxing would be my choice.
Those sites aren't going to break, even without adding any exceptions. There's no definition of "essential" that would exclude Flash content on Google Finance. As mentioned above, the exact heuristics they're using are:
"TLDR, essential content is either: 1) On the same domain as the page 2) Considered "Large" (at least 298 x 398, certain aspect ratio, minimum total area), with an exception for tiny content (likely transport plugins)."
Edit: This is strange. I went to change the setting and it is greyed out and cannot be changed. This is in both chrome AND firefox. Both are up to date with most recent version, and my macbook was bought this year. Neither have adblockers enabled.
I thought this change was universal, but you seem to be suggesting it's not. Did I wind up trapped in the less friendly part of an A/B test?
I don't know if there is a similar addon for Chrome.
Not it isn't. The flash player is actually superior in almost every way. And like you, I won't provide any data to back that opinion up. I'll just use the word "almost" to give me some room in case someone jumps in with actual data.
THE ABOVE TEXT IS ALSO OPINION.
https://github.com/hfiguiere/no-flash/
Mozilla may include this functionality in Firefox directly:
So, there is a very specific example of how the YouTube Flash player was superior to the HTML5 one. At least for my use case.
[I doubt this an HTML vs Flash issue, though]
You can still choose Add To > Watch Later.
Why would google take a good but not sufficient approach?
IMO because of marketing issues: get some hackers and tech savvy people to evangelize that they are improving their privacy issues. I suppose google doesn't need flash/super cookies, "so lets take them out, we look good, and we still have the same entropy to get to know the user"
Can’t we just throw out all flash?
And I was more asking if the EU might add it to the current trial, but considering it was just badly phrased, guaranteed not.
I can disable JS, too. Or I can disable ad trackers on my system.
Doesn’t remove them for anyone else, though, and doesn’t mean I still get the same quality of browsing.
Way too much stuff needs it. For example fun little browser games. For example http://www.kongregate.com/ http://www.miniclip.com/ http://www.friv.com/
At least in my browser (Firefox on Linux) flash plays better than html5 for video.
We already have a way to transmit two-way video live in browsers (WebRTC).
It should be not to hard to use the codecs existing for that to make a one-way live streaming in browsers.
If someone would add a small standard extension (like Microsoft originally suggested) to allow for one-way streams, we could do livestreaming over it, too.
Preferably even make it seamless – allow pointing a video element to a livestream source.