Flash and Chrome
chrome.googleblog.com
chrome.googleblog.com
The FLV format also finally made streaming video a seamless experience for the end user; leading to the creation of Youtube and other streaming video services.
Like all technologies, Flash was overused in places (pre-loaders, rotating 3d logos, banner ads) and Adobe's push towards Flex and RIA's took Flash away from of it's roots in animation for quite a few years. However, it will be interesting to see if the equivalent HTML5 stack follows a similar timeline-- minus the website pre-loaders...of course.
There's some irony with Google blaming Flash for being spammy; I recently inspected what's probably the biggest shopping website in the EU because it slowed my computer to a crawl and noticed at least 30 to 40 outgoing connections, a lot of them to Google and its diverse ad, tracker and analytics properties.
e.g. I tried to download an mp3 of a radio show from bbc.co.uk earlier today and "download blocked" with no option to override. I have all the protect me from myself settings firmly off. chrome help says it's Internet Settings. Internet settings says it's fine to download, and I've downloaded dozens of other mp3s flawlessly. mp3 actually downloads if you paste the button url in a new tab rather than click the button. I've had similar issues with other, innocent and harmless, files in the past. Well, since they brought in their cleverness and download "protections".
I forsee similar issues with flash as it goes through its deprecation.
You're being a little kind; this is not so much irony as outright hypocrisy.
Apple did something similar with iOS, refusing to support the plugins arguing that they were insecure and so on, and then promptly using one of their own for HTML5 media elements that broke all kinds of functionality, as well as ignoring the related Web standards whenever it suited them, and then locking up their ecosystem so no-one else could offer an alternative browser that handled these issues better.
The problem with modern browser developers is that they seem to have decided their job isn't just to present the content of the Web but to try to influence and curate it on behalf of their user bases. Google gets extra demerits because it is also trying to do the same through its control of the dominant search engine. I don't think this amount of concentrated power is even remotely a healthy trend for the future of the Web.
Slightly off topic: I always found the term "block" to be a bit odd in the web browser context. The browser is the ultimate authority on what gets rendered and shown to the user; there's no need to block anything, because it can just not attempt to show it in the first place.
The term goes back at least as far as popup blockers. I wonder if it's because early popup blockers were browser plugins, rather than built in features, so they did have to actively intervene in the user experience.
The term "ignoring" is more accurate.
Ah, so it's for the user, not because other ad networks cannot rely on implicit whitelisting for their analytics callback channels because, aww shucks, the browser vendor just happens to run the ad network.
[1] https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...
We've had better alternatives on the desktop for over six years now, since Apple said "No Flash for iOS" in April 2010, when content creators panicked to capture that market and started conversion to HTML5 video. That already was a long time coming.
Chrome finally saying farewell to Flash in this manner forces the market to recognize that Flash is no longer an option even on the desktop.
As for my security argument: using the link above, if we start with vulnerabilities found in Flash Player after April 2010, that's still 830 of them.
Beyond that, one of the most significant areas of flash as a player is eLearning, training and simulations. Say what you will about a lot of the garbage in player, the authoring tools were some of the best available... though I haven't seen what Adobe has on deck today, it was a very nice experience with nothing comparable for at least until 2012 (last time I worked with flash/flex).
What my real hopes were when adobe bought Macromedia, was that they'd open up the format, and convert it to a packaged zip file with a manifest, svg and javascript proper as the language. Allowing for browsers to co-opt and internalize the players. Then adobe could continue to make great tooling and the browser vendors could correct the ship on the players. My dream is pretty close to what Silverlight offered, but that was something nobody was willing to look at for good enough reasons.
I emphatically agree. Back in 2004-2006 I was doing Macromedia Flash MX 2004 development (with the new-and-shiny ActionScript 2.0! Based on the forthcoming ECMAScript 4 standard that should be finalized any day now...). It was hands-down one of the best development environments I've used w.r.t. creating games and "rich Web applications". It really was the best thing available at the time: you could draw and animate your sprites, tiles, backgrounds, whatever within the same IDE in which you wrote your code. You could attach scripts to any object on- or off-stage, and they ran in an event loop. The documentation it shipped with was also excellent, and I picked up a hardcopy of the "ActionScript 2.0 Bible", a massive tome of beginner's tutorials, intermediate tips and tricks, and complete language and library reference -- for a measly $20.
Nowadays, Unity gives a similar yet more featureful environment for writing games, and Silverlight briefly presented an alternative for "rich content". As far as rich content goes: sure, we can do that stuff with HTML5 and JavaScript nowadays, but it was just so much more pleasurable to work with the Flash IDE than anything else I've seen, excepting maybe Silverlight. Where making a Web 2.0 application feels like an enormous pain in the ass, making the same in Flash was a joy. It was fun rather than frustrating!
I think if Adobe (or even Macromedia) had opened up the Flash format (SWF), and maybe even the plugins, things would've gone a lot differently. Flash could've been a law-abiding citizen of the "Open Web", and we could've seen some healthy competition amongst development and runtime environments. The community at large could've found ways to iterate and improve on the technology. But, I suppose that ship has sailed and we're stuck trying to jackhammer the round peg that is application delivery into the trapezoidal hole that is document delivery (i.e., the Web).
For video, HTML5 video was simplistic before DASH, which became a standard in 2012. Further, with Flash your choice of codecs was easy (Sorensen Spark, and later H.264); with HTML5, you have to stream in whichever combination of audio and video codec and container the browser supports.
For rich interactivity other than video, we're just now, in 2016, at a point where we can claim the Web Platform [1] finally is on par with Flash, but sites like CanIUse still exist [2], because not every browser supports every new API. Flash gets a (rightfully) bad rep for its security vulnerabilities, but it was a single platform to target, and it's been replaced with alternatives that are no less subject to vendor pressures, despite being 'open' and 'neutral'.
Vulnerabilities aside, at least Flash runtime didn't give unfettered access, and was even nice enough to ask for permissions to the webcam and microphone. Furthermore the runtime was frequently updated and patched by the vendor, and Flash being embeddable in web pages made keeping up-to-date individual Flash applications easy, as they were hosted on the server.
I'm not sure I'd call that "better". Running, albeit a bit worse, is better than not running at all.
it did, see Adobe AIR, publishing to Windows / mac OS X / iOS / Android is imho cross-platform enough.
In the case of about 95% of the Flash that's been written, we have had a better alternative all along: Not writing Flash. Not animating the self-help menus at your ISP, not auto-playing music at every restaurant website, not cramming a megabyte of crap into the ads coming down your 56kbps modem connection, etc.
A better comparison could be for CVSS scores over 9: Flash 742, Chrome 209.
Worse, to fix a lot of these issues you'd have to fix the APIs as well, and that means a new version that doesn't work with the old codebase. People only use Java and Flash because they're on every computer and work with legacy apps. If you introduce a new breaking version, then you're asking for trouble.
I haven't had to deal with that kind of content for quite a while now, but I would think some of the authoring has gotten better. It's a bit of a shame though as flash animation projects were so much lighter than video streaming.
Some sort of WebGL/asm.js/WebAssembly player for SWFs on the internet archive would be the pipe dream, I think. That way we could watch Strong Bad long after Flash is available in the future.
For instance there is proprietary Flash implementation called Scaleform used for games UI. Even long ago before Autodesk acquired them it's had both decent compatibility with normal SWF as well as full GPU acceleration for every platform possible include Linux.
Scaleform has a complex code base but clearly it is possible to reverse engineer the Flash runtime and make a compatible player.
But you may give it a try ...
Still, faults aside, Flash was awesome. It was an advanced "Hypercard" (which I learned to build things in as a kid). I hope we don't completely lose some of the good aspects of these technologies.
Anyway, I'm a Firefox user and I don't have Flash installed. The web works just fine without it. One less plugin to worry about.
That time was the 90s and early 2000s. And in that time, I avoided pages with Flash because they were painful. They are still a little painful now.
If Flash was transformative, I think it was that it introduced the kind of bloat and intrusiveness that we now take for granted on the web.
The amount of auto-play videos (both ads and non-ads) is extremely obnoxious and I haven't found a good way to prevent that them yet.
I never have any issue with any auto-play videos at all.
The performance on the good old FF 30 is N*10 times better than latest chrome browser.
Standalone flash players exist, and flash-to-HTML translation will continue to improve.
For example, consider the case when a new domain owner attempts to block all bots from spidering their site, by adding something like this to their robots.txt file
User-agent: *
Disallow: /
This is actually a fairly common case when domain resellers purchase expired domains.Now when you try to visit the archived link, because the live robots.txt file disallows bots, you won't be able to access the archived site (which may have been owned by someone completely different).
[0] https://archive.org/post/406632/why-does-the-wayback-machine...
It makes much more sense to archive the robots.txt along with the content, and use the robots.txt linked with that version of the site. Updating the current robots.txt shouldn't affect a past archive.
Are they still planning to grant a one-year exemption to the top ten flash-only sites? The article doesn't mention it, but I haven't heard anything about it being cancelled.
The only exemption those top 10 Flash sites will get is they will have this permission by default, but you should still be able to both permanently add other websites to the whitelist and remove those default ones ones from it. Which, in my book, isn't nearly as bad as Apple's hardcoded support for FairPlay + DASH in Safari only on netflix.com.
I could be wrong though, there could be more stages where it gets harsher and what I described is only the first step.
"Adobe Flash Player is required for interactive charts."
I'm all for killing Flash, but if even Google is unable to completely do away with it, doesn't that mean that it might be a premature move?
I don't have any interest in seeing Flash kept around. In fact, I'm quite happy to see it die. But do we actually have working alternatives for the problems it currently solves? I don't ask this rhetorically, I'm very curious if there's still problems which HTML5 is unable to reasonably solve.
[0] https://www.dropbox.com/s/f52ew4wpwcmt1dr/Screenshot%202016-...
And btw, GPM seems to use a similar DRM method as the one supported in Netflix, so if your browser does not support DRM, you're out of luck [1].
[1]: http://googlesystem.blogspot.com.br/2016/04/google-play-musi...
There's some superb wrapper apps [0], but they apparently use WebKit.framework, so it still prompts you to install Flash.
Although I just discovered that the Radiant Player people are working on an Electron version [1], which is very exciting!
[0] https://github.com/radiant-player/radiant-player-mac
[1] https://github.com/radiant-player/radiant-player-electron
whatever your problem: slow machine, battery, security, etc. it's all its fault
seriously, if everyone have already moved to HTML5, how come we are still blaming Flash for those daily petty problems ?
It's not used so let's block it but it is still responsible for the majority of problems ...
nobody notice the ambiguity of the argument ?
It's quite painful to see such arguments from Google, I thought they would be smart enough to understand that any popular technology get hacked, the problem is not really Flash, its the browser itself (and the advertising networks that are perfect to distribute dodgy payloads to tons of users).
The other sad point is the amalgam of everything, for some ppl Flash equals advertising, and that's bad so Flash is bad, and they don't want to think further than that.
The choice of the users ? The tons of SWF content (that will probably not be ported to HTML5) ? nobody care apparently
And about throwing everything in the same bag, so apparently if Flash is dead then ActionScript is dead too right ?
nope
Flash is just 1 runtime running in the browser, there are other runtimes: Adobe AIR for desktop and mobile, and also Redtamarin [1] for the command-line / server-side.
A couple of the games used a ton of frame by frame animation with large sprites, so they probably wouldn't convert to spritesheets very well and should stay vector graphics.
Example: https://youtu.be/Qk9HlXbqRTQ?t=43s
Moreover, you can rewrite a game in html5 from scratch, if it is simple enough, but it will be slower, less smooth, and require some latest browser versions to run at all.
[1] https://developers.google.com/chart/interactive/docs/gallery...
[2] https://github.com/google/google-visualization-issues/issues...
[3] https://www.google.com/publicdata/explore?ds=ltjib1m1uf3pf_#...
I believe this is the library: http://vizabi.org/examples/bubble-chart.html
I doubt that very much - Google has been extracting data from and indexing Flash content for close to a decade[1]. If they wanted to reverse-engineer the behaviour of flash code, they could run it as blackbox code in a Flash sandbox
1. http://searchengineland.com/google-now-crawling-and-indexing...
The bytecode format and semantics of both AVM1 and AVM2 (the VMs used in Flash) are common knowledge.
since 2008 gaforflash [1]
since 2014 as3-universal-analytics [2] (measurement protocol)
https://blog.mozilla.org/futurereleases/2016/07/20/reducing-...
Meanwhile, it's pretty easy to force Firefox to apply this policy right now. Just go to the Plugins screen and select "Ask to activate" for Flash. I've been using Firefox like this for over two years, and have never been happier with my web experience.
Why? As I've said before, and will say again: A lot of enterprisey applications have tools developed in Flash/Flex. Mostly internal and B2B tools, but tools nonetheless. It's not likely that they will be replaced anytime soon, because no one is going to authorize the budget for replacing something that still works, so Flash will be around in one form or another for a long while.
Companies still using them are now in the same position as those using active-X, they need IT to deploy special measures for users that need to access them.
I think it's fair to sum up this situation by saying that java applets are dead or dying. Flash may well be in the same position in 3-4 years.
I'm all against Flash. But this argument sounds silly. Why not handle this like any decent OS, and "nice" the Flash portion of the page, so that it takes only cycles (or bandwidth) which are otherwise left unused?
I wonder if Flash is still slower than the current JS bloat of the "modern web". My intuition says, probably not.
Great news!
All that left was Flash video (very easy to replace server-side, just switch to an HTML5 player and all the videos on your site are good to go) and sites with Flash-only interfaces (good riddance, for the most part).
I guess it would be nice to watch Homestar videos on my phone browser instead of having to find them on YouTube, but that's literally the only other use case I had.
I don't know what you guys changed under the hood, but I'm
experiencing the exact opposite of your first paragraph claims:
most videos don't work, and it's draining my macbook's battery
at an unprecedented rate. I can live with my flash videos not
working, but the reduced battery life is making chrome
unusable.If you have actual issues with the new design, file bugreports or issues.
(Me, bitter?)
What do you mean the graphics took a huge step backward? You don't like the new UI, or stuff like WebGL/HTML5 Canvas is performing poorly?
Personally I prefer the new UI, better suits El Capitan's return to a more clean, flat look.
NPAPI was outdated, unperformant and insecure, the goal of PPAPI was to address those issues. All that would be needed for Unity web player to work out-of-the-box in Chrome again is for it to be ported to PPAPI
Instead Java used that time to build several help pages that showed you how to install other browsers then made a shitty anti-chrome campaign when it was finally removed, and unity just sat there and did nothing the whole time.
"I don't expect Chrome to keep supporting PPAPI native plugins for any longer then they have to (in order to support Flash), because it has the same security issues as NPAPI.
And, porting the plugin to PPAPI would be far from trivial, and not be compatible with existing content anyways"
Is any of that fundamentally wrong? They decided it was a better use of their time to go right to WebGL.
That being said, I think Unity is going in the right direction trying to get away from plugins altogether. They are trying (successfully IMO) to compile to "true" web technologies and let the game be exported as HTML5 and javascript which is the right choice.
Which had the effect of banning Unity.
I understand that this was a good move from a general security standpoint. I'm annoyed that Google has done their best to make it impossible for a power user to override it, just as they made it unreasonably complicated to install non-Google-approved plugins.
By all means, set your softwares' defaults for general security. Don't tell me what I'm not allowed to do with my own computer "for my own good." We don't accept that when Microsoft or Apple does it.
> All that would be needed for Unity web player to work out-of-the-box in Chrome again is for it to be ported to PPAPI
No. All existing Unity apps would have to be recompiled. Making legacy games harder to run leaves a bad taste in my mouth, even if it's for good reasons.
Unity apps compiled against the UWP runtime should run all the same regardless of whether UWP is wrapped in an NPAPI or PPAPI plugin, unless the wrapper plugins themselves and/or how they call the UWP runtime are implemented differently.
Flash can be blocked, through browser extensions, CSS, or simply by removing the !@#$%^&*() Flash plugin, disabling all autoplay video.
HTML5 has no such similar functionality.
This feature of Flash is very sorely missed.
(/etc/hosts or similar blocklists of all known video service providers is an effective and reasonably concise, if not entirely perfect, alternative. I recommend it.)
I've yet to find an extension which blocks all video effectively. Or prevents autoplay.
Chome/Android doesn't support extensions at all. So there's that.
Flash, by its very blobbiness, had an effective defeat mechanism: remove the blob.
Again, for video, especially autoplay sources, I've found blackholing the video platform provider's hosts or domain quite effective. It's still only a handful for most offenders. And if the practice spreads we may see pressure from the providers themselves to defeat autoplay.
Though those of us blocking will be beyond caring.
> HTML5 has no such similar functionality.
Just as you can block Flash by not having a client that handles Flash content ("removing the...Flash plugin"), you can do that for HTML5 too.
But there's a whole lot of baby that gets thrown out with the bathwater in that case.