ADDED: Mozilla blogging about security benefits of PDF.js, which apply here too to
ADDED: Mozilla blogging about security benefits of PDF.js, which apply here too to
I think it's crucial to make sure end users concerned with security understand the difference between built-in or bundled Adobe Flash Player (Google Chrome style), and what Firefox is offering.
As soon as Chrome added a built-in Flash Player, it became the preferred target for hack contests, and still falls over repeatedly: http://www.securelist.com/en/advisories/52983
> Multiple vulnerabilities have been reported in Google Chrome, which can be exploited by malicious people to compromise a user's system. The vulnerabilities are caused due to a bundled vulnerable version of Adobe Flash Player.
That's not what Firefox is doing, and I hope the tech community helps regular users understand the difference.
And please, for the love of all that is holy, also make sure they understand what it might mean for the stability of features such as video recording.
Over the past few years Chrome has repeatedly shipped PepperFlash versions with various degrees of brokenness for video recording; wreaking havoc for webcam based services across the web.
Ironically enough these issues are extra hard to address, because when you tell Chrome users to 'try another browser' they all go "Nahh. I'm already on the best one."
Nobody gives two glances about Safari, mate.
- Frequent crashes when acquiring video camera [2]
- Recorded sound being choppy and broken (still not fixed for Red5) [3]
- Audio delays and broken echo cancellation in Speex [4]
- Microphone sound levels not reported, breaking apps like ours which check if a microphone worked properly. (resolved together with [3])
- Sound stopping to record after a few minutes [5]
- Inability to give camera access on retina displays [6]
- Rushed fix for a click-jacking attack introduces horrible UX that gets into an unrecoverable state by default [7]
All in all I can personally confirm that Chrome has not been good for people doing video recording on the web.
[1] https://code.google.com/p/chromium/issues/detail?id=150596 [2] https://code.google.com/p/chromium/issues/detail?id=140831 [3] https://code.google.com/p/chromium/issues/detail?id=136624 [4] https://code.google.com/p/chromium/issues/detail?id=144554 [4] https://code.google.com/p/chromium/issues/detail?id=152314 [4] https://code.google.com/p/chromium/issues/detail?id=140724 [5] https://code.google.com/p/chromium/issues/detail?id=168859 [6] https://code.google.com/p/chromium/issues/detail?id=177621 [7] https://code.google.com/p/chromium/issues/detail?id=155437
Firefox is to Flash like a solid wooden door is to a screen door.
Even if it isn't bulletproof, it's still a huge improvement over the status quo.
And keep in mind this solution precisely fits your desires: "less code and business built-in to the browser". This Flash player runs directly on top of the existing sandbox and does not create yet-another-special-case-for-native-code. It introduces little to no additional attack surface area.
Let's suppose we believe our site to be secure because we've tested it on Windows and Mac and checked the flash doesn't cause issues, and we've tested it on mobile and the flash simply doesn't work. Now we need to test all over again.
Consider, for example, JPEG injection bugs. There are JPEGs embedded inside Flash content that are now being parsed by different code.
Let's suppose you're an ad network and you don't want to mistakenly inject malware into other websites because that would be bad. Now you need to think of a whole bunch of new cases. E.g. you might have carefully sanitized all the JPEGs on your site, but not the ones embedded in SWFs. This is merely an example.
Would it be a Good Thing if every copy of the Flash runtime magically disappeared and got replaced with this thing? Maybe. But as it is, life just got more, not less, complicated.
As a user, though, your browser is significantly more secure running Shumway than running Flash. It literally removes an entire attack vector without adding a new one. If there's an exploitable vulnerability in Firefox's JS engine, you're vulnerable to it regardless of whether you run Shumway or not — but if there's an exploitable vulnerability in Flash, you aren't vulnerable if you're running Shumway instead.
Ultimately, individual users have to take charge of their own individual attack surface. If switching from one Flash player to another increases their personal security, it's a good thing.
In general, I'd say replacing things with emulations of things is not a good way to get better reliability, performance, or security -- now you have bugs in the original thing and the emulation of the thing to consider.
In this case, the emulation lives within a restricted runtime environment and the real thing doesn't. But that's a performance / resource consumption / convenience / compatibility hit in exchange for "security", and those tend to fail simply because most people like their performance / resource consumption / convenience / compatibility.
Shumway decreases the attack surface of Firefox for general-purpose browsing: most people would install Flash otherwise, and this way that (infamously broad) attack vector is removed.
thanks :) I, Gabe Newell and many others would like to see this happen.
Ironically most of the useful flash applications/games etc wouldn't run on these runtimes as they are using features not supported in HTML5. This sort of thing works best for crappy adverts and banners, which no one really wants anyway. This is highlighted by the fact the big competitor (Gordon?) is developed by the Google ad sense team ;)
Unless you really loved the flash IDE which I guess some people do...
I'm genuinely curious, as I do a bit of html5/webgl and formerly did a lot of flash/haxe, so I'm wondering what I missed...
However there are other things, like webcam/device support, some audio stuff, filters that may be very slow on a canvas and hard to run in WebGL inside other panes (overlays etc).
Users want to watch videos, they don't care about the technology under the hood.
Do you ever try and watch youtube videos that say, "this video isn't available on your device"...
https://news.ycombinator.com/item?id=6558539
I guess you could ask him for more details.
And you remember who Gordon Shumway is right? ( https://en.wikipedia.org/wiki/ALF_(TV_series) )