Reducing Adobe Flash Usage in Firefox
blog.mozilla.org
blog.mozilla.org
While Chrome's proposal to white-list the top-10 domains is a good start at curbing the loading of Flash on my laptop, I prefer the approach being considered by Safari to report that Flash (and other legacy plugins) is not available on the platform even if it is installed. [2]
Safari's approach will ensure that most users see HTML5 content and won't really miss Flash. Folks who use sites like Twitch that insist on Flash will know how to force Safari to load the content they want to view.
Unfortunately, Safari's user share outside of Mobile is very low. We need Chrome, Firefox and IE to adopt a similar approach (or agree on an approach for all vendors) if we are to really rid ourselves of Flash.
1. https://bugzilla.mozilla.org/describecomponents.cgi?product=...
2. https://webkit.org/blog/6589/next-steps-for-legacy-plug-ins/
Edit: Moved links to the end of the post.
https://docs.google.com/presentation/d/106_KLNJfwb9L-1hVVa4i...
> In 2017, Firefox will require click-to-activate approval from users before a website activates the Flash plugin for any content.
Wow, what an odd position to take (apple not you)! It seems downright harmful to the user and completely disregards the users own intentions. What next, the browser will redirect all visits to online music stores to the iTunes one?
For those who like this behavior and want it in Firefox without having to constantly murk in about:config / about:addons, use https://addons.mozilla.org/en-US/firefox/addon/flashdisable/
As for "why?", it's because this behavior ensures the HTML5 is served, and if a site absolutely requires Flash, it's only a click away to activate. I prefer this to current Firefox's Click-to-play, who shows Flash in my browser plugins list, causing some sites to prioritize and serve Flash rather than HTML5.
The resource (and battery!) usage for "native" streaming is so much lower than the browser version. You can freely leave it in the background while doing other things. Plus, you can force a 1080p feed. (All without paying.)
The issue is that the source is HLS which most desktop browsers (with the exception of Edge and Safari I believe) don't support. I've used twitch with flash disabled on Edge but there's often problems.
Presumably the new beta html5 player (which requires turbo subscription for now) works around HLS in some way.
So if websites aren't recognising Shumway even as an option, but looking explicitly for the flash plugin, what chance does it have for market penetration?
(And yes, I filed a bug on said website's issue tracker)
I usually don't make comments regarding other people's software choices but you are definitely doing it wrong.
Mac OSX's built in pdf viewer "preview" is much better than even adobe's reader even though they invented the format.
The entire rendering system of OSX is based on postscript so it flies.
I forget what publisher but the book would never load in Apple's preview, I think maybe due to it having a password or DRM? So they're are still probably rare reasons to install Adobe Reader on a Mac.
I fully understand that Flash has had an outsized share of vulnerabilities 'affecting browsing' over the years; I fully understand that Adobe has deprecated Flash for new content production; I fully appreciate that the 'web platform' has acquired new APIs and capabilities over the last four years, making it a more potent platform than the days when people opted for Flash or Silverlight because an external runtime was the only way to reliably deliver the experiences those developers wanted.
But in a world where a HTML webpage from 1991 [1] still loads and renders fine, I'm worried about the sheer amount of content that exists in Flash from the 2000s that will be made inaccessible. Sure, those developers should have known that developing on a proprietary platform is a risky bet, but this was back when Javascript was awful, browsers were racing to implement not-yet-final enhancements to CSS3 with vendor prefixes, and powerful vendors were bickering about which formats to support in a proposed <video> tag. These developers of course should've known better, but they had no other choice.
What Mozilla is doing here is actually quite reasonable, but they're under pressure from Google Chrome who can unilaterally decide to ban flash from all but the top 10 sites, and get away with it due to their control of multiple platforms and their unwillingless to compromise.
If Mozilla's tactics stray too far from Google's, they risk being seen as followers, rather than policy drivers; furthemore they answer to a divided fanbase that on one hand wants an open, independent web (in which Flash has no place), and on the other hand, wants a refuge from the incumbent browser maker's unilateral policies (currently Google, previously Microsoft).
I’d have marginally more sympathy if the modern alternatives we’re supposed to use instead now actually worked as well as the technologies they allegedly replace, but often they do not, and the biggest advocates for the newer technologies are often among the worst offenders.
I’d also have marginally more sympathy if there was evidence that closing out the plugins would significantly improve security, but given that many of these changes just move the attack surface to the browser itself and that the popular plugins have mostly been subject to some sort of click-to-play safeguard for a while, I’m not sure the security argument holds much water either.
But in any case, actively cutting users off from large amounts of existing content with no workaround seems like a huge backward step to me.
Already, many widely used devices can't access Flash content. Browser vendors are doing the responsible thing here by preventing any future situation like what has happened with Flash on mobile.
One could make similar arguments about replacing complex and/or interactive graphical content once drawn using plugins with HTML5 canvas, SVG or WebGL elements. The quality of implementation, reliability and performance of these newer technologies are not quite universally awful across all browsers, but the situation is disturbingly close to that once you start using them for more demanding applications like complex animations or drawing interactive diagrams with thousands of elements.
Well you can't rely on Flash being available anyways. It's not available at all on mobile.
Nothing anyone has ever made (or will ever make) in Flash will work on mobile today.
For example, H.264 is patent-encumbered. It’s now supported to some degree for HTML5 video elements by all the major browsers on most platforms, but it has been a long road to get that far.
Mozilla struggled for a long time with getting support into Firefox across platforms. To this day, Firefox still relies on third party software and/or hardware decoding to provide the required functionality, and this was a real world limitation on at least one major platform as recently as two years ago. A similar limitation would affect any other browser whose developer wasn’t in on the patent pool or paying royalties to it.
Google also threatened to pull H.264 support from Chrome for a while, reportedly because of concerns over the licensing costs.
Anyone distributing video encoded using H.264 also needs to be mindful of the licensing rules. Although small scale and non-commercial uses typically don’t require royalty payments under the current rules, there is a legal minefield here for anyone operating a larger business who might be affected. This is a significant concern in itself given that some major browsers only support H.264 for HTML5 video.
Beyond the patent issues, we also have the issue that H.264 comes in many flavours, and support for those isn’t standardised across browsers and platforms either. Unless you’re only talking about the least common denominator, it’s not really sufficient to refer to H.264 support; you need to know which specific variations are supported on any given browser, OS and hardware in order to serve video with the best possible quality and efficiency. Finding that information is not straightforward, even if you have the resources to then encode in many different variations once you know.
Looking at the above, it’s hard to see anywhere that the current situation is actually better than what we had for a long time with plugin-based players, except on newer systems that don’t support those plugins. Which brings us to…
Well you can't rely on Flash being available anyways. It's not available at all on mobile.
Of course you can’t rely on it now, but that is mostly an artificial limitation imposed first by the mobile browser developers and subsequently by Adobe themselves in response. A Flash player was available on Android for a long time, and Microsoft were reportedly keen to see a version running on Windows Phone as well.
What we’re really talking about here is Apple starting the ball rolling by refusing to allow plugins on iOS, for reasons we may or may not believe are what Apple publicly claimed at the time. Considering that there have been numerous significant problems with Apple’s support for HTML5 video on iOS devices — not least relying on the infamous AppleCoreMedia to handle that content instead of the browser itself for a very long time, causing all sorts of functionality to break — and that Apple’s policies prevent any other browser on iOS from doing better, I have always found their stance on this rather hypocritical.
No matter who you want blame however doesn't change the fact the Flash isn't ubiquitous. It's ubiquity always depended on a single vendor supporting it on every platform.
Don't lock yourself in to that crap in the first place.
Consider the pain an educational expense.
In fact, XMLHttpRequest didn't become a W3C Working Draft until 2006 [1], before then it was a proprietary Microsoft extension. Canvas didn't become a standard until 2007 [2], until then it was Apple's proprietary trick. The DOM was the only API of what we now call the 'web platform' for many, many years.
Between 2000-2006, Flash, Shockwave, and Java Applets were delivering rich interactivity while the open standards were nowhere to be found. While we can and should celebrate that the 'web platform' is finally good enough to replace proprietary applets, the schadenfreude is unnecessary.
I'll allow there were few alternatives at the time, for in-browser, run-many-places interactive content. You could have ginned something up in JS, Java, or distributed binaries for your target platforms.
But if you find yourself gazing into the abyss of "well, I've got to use a proprietary standard to do that", you can be virtually certain of the consequence you've noted here.
(Not that open standards last forever either, but the track record is vastly superior.)
Twitch is one of the popular sites that don't have a working HTML5 player for the masses (it does work without Flash using the methods above). There's Beam.pro which has some interesting approaches to live streaming with HTML5 [2]. The only thing I haven't found a great solution for are the big Music streaming sites, which all rely on Flash (the others shut down). Some people told me Google Play Music may or may not work with HTML5 but I haven't tried that yet.
Also, a great number of websites will ask you to turn on Flash when installed but deactivated and only use the HTML5 player when it's not actually installed. I guess it's a design flaw that Browsers report disabled or click-to-play plugins to websites.
0: http://rg3.github.io/youtube-dl/
1: http://docs.livestreamer.io/
2: https://forums.beam.pro/topic/168/where-we-re-at-with-html5-...
- Candy Crush (50,000,000+ monthly users)
- Dragon City (10,000,000+ monthly users)
- Criminal Case (10,000,000+ monthly users)
- Angry Bird Friends (1,000,000+ monthly users)
I'm currently working on a Flash game with a large player base. Firefox's suggestion of adopting HTML technologies is not simple when the game is 9 years old! I think many Facebook games are going to run into a similar issue.
It's getting scary now tho, it seems like Firefox and Chrome are aggressively trying to get rid of the usage of Flash. We've essentially decided that we're going to convert this 9 year old game to C++ (via Emscripten) in the next year. Good luck to everyone else who is going through the same thing as we are.
It's not just Firefox and Chrome that are focusing on Flash. Safari 10 (in macOS Sierra to be released this year) and Edge are also restricting Flash usage:
https://webkit.org/blog/6589/next-steps-for-legacy-plug-ins/
https://blogs.windows.com/msedgedev/2016/04/07/putting-users...
Coming soon: 6x6 fingerprinting/tracking SWFs?
Just a friendly reminder that the 2D graphics functionality of Flash is still not replaced for a massive chunk of graphics and games built with a vector-based visual style.
Canvas 2D vector graphics still do not properly antialias adjacent edges (shows garish seams and unexpected transparencies), whereas Flash would render them properly and with high quality.
"Websites that currently use Flash or Silverlight for video or games should plan on adopting HTML technologies as soon as possible."
This is utterly unrealistic, these games are 10 or more years old sometimes, and still played in large numbers, with no money available for the developer to rewrite them.
Only an automatic transpiler of some kind has any chance here.
[0]: http://mozilla.github.io/shumway/ [1]: https://bugzilla.mozilla.org/describecomponents.cgi?product=...
An OpenFL HTML5 app is already capable of rendering SWF animations, but it doesn't currently support the internal actionscript.
With access to the games' original source they could be ported to OpenFL pretty easily (it uses Haxe, a language similar to actionscript that can transpile to many other language targets), but that's a bit short of automatic runtime transpilation of SWF content.
And who can forget http://www.weebls-stuff.com/other-toons/video/magical-trevor...
Really, what I expect to see is just an emulator specifically written for the sake of these old Flash games. Probably as a core of MESS, and thus of JSMESS, with the games then showing up in the Internet Archive's "Online Arcade" like everything else.
Add "##video", "##audio", and "##canvas" to your blacklist rules to remove them from the DOM.
Then you can whitelist on a per-site basis to turn them back on if desired.
https://addons.mozilla.org/firefox/addon/happy-bonobo-disabl...
The source code is on GitHub:
I block the source video content networks or whatever they're called, in /etc/hosts or equivalent. Those should be addable as custom blocklists in uBlock Origin as well. See following post higher up this thread.
0.0.0.0 player.theplatform.com # Autoplay video
0.0.0.0 link.theplatform.com # Autoplay video
0.0.0.0 ci-2862d2c8d6-68f418d2.http.atlas.cdn.yimg.com # Autoplay video
0.0.0.0 big.assets.huffingtonpost.com # Autoplay video
0.0.0.0 ht1.cdn.turner.com # Autoplay video
0.0.0.0 ht2.cdn.turner.com # Autoplay video
0.0.0.0 ht3.cdn.turner.com # Autoplay video
0.0.0.0 ht4.cdn.turner.com # Autoplay video
0.0.0.0 ht5.cdn.turner.com # Autoplay video
0.0.0.0 ht6.cdn.turner.com # Autoplay video
0.0.0.0 ht7.cdn.turner.com # Autoplay video
0.0.0.0 ht8.cdn.turner.com # Autoplay video
0.0.0.0 ht9.cdn.turner.com # Autoplay video
Alternatively, uMatrix should allow you to globally blacklist, then optionally whitelist same.That said, it used to be easy to block annoying stuff by having Flash enabled on demand.
https://blogs.windows.com/msedgedev/2015/01/29/simplified-ad...
https://blog.twitch.tv/html5-player-turbo-beta-starts-today-...
It clearly does not fit. The graph flattened out at Jul 2015.
I personally killed flash from Chrome about a year ago. I've seen a few sites that use it, which I just leave, but I haven't seen anything I can't live without.
It's strange they weren't mentioned in the blog post. Only the third class of blocked content, viewability test, is mentioned.
>* Blocking the content will not be noticeable to the Firefox user.
>* It is possible to reimplement the basic functionality of the content in HTML without Flash.
There are three classes of content in the block list: Fingerprinting, Supercookie and Viewability. While I'm heard of various fingerprinting techniques besides Flash, I'm curious how "to reimplement without Flash the basic functionality" of supercookies, given its main feature is persistence despite of user's effort.
Edit: Turns out Firefox is planning on blocking all sites by default. So Firefox's approach looks more promising.
YouTube is no more worthy of using Adobe Flash than my personal website. They should be treated the same. If we are to disincentivize Flash, it should be disincentivized equally across the board.
Some people want flash, probably because they are oblivious to security concerns or simply don't care about standards and progress. These are the people we must convince. Letting them have what they "must" have while chipping away at the problem is something that might work here and now. Likely these people wouldn't even realized the browser was doing it in this case and would blame the sites for having broken flash. Despite seeming morally grey or deceptive, it could work and might not punish the browser doing it.
I am generally against browsers acting against user desires for compatibility. (And specifically, backwards compatibility, which the web should strive to be.) I would argue that blocking Flash is an antifeature, but providing a security gate, like not running it by default, is a security feature.
This is why mobile browsers and unpopular systems can't access Flash content. In effect Flash breaks backwards compatibility across platforms.
I uninstall flash entirely, never install it in the first place and/or do not use browsers that come with any proprietary plugins. I expect most people here on HN each have their own preference that largely defies attempts to clean categorization in statistical terms.
But most other users probably can be lumped into categories that aren't "misc" or "other". Anything that gets a larger chunk of web users safer and hopefully away from flash is good by me. I mostly care about the practical results, so bring on the "security gates", white lists, black lists and in general down with flash and the cesspool of security vulnerabilities it exposes people too.
People simply don't care.