Adobe issues emergency Flash fix
bbc.com
bbc.com
Which is highlighting this security release from Tuesday: https://helpx.adobe.com/security/products/flash-player/apsb1...
Edit: in response to TazeTSchnitzel to whom I cannot reply. If BBC included a link to the original post or the actual security advisory I would be less likely to call it blog spam, but I stand by my classification. It is a repost without the sources and with less information (notably a warning to users about the McAfee opt out among other things).
If you ever cannot reply to a post try clicking the "X minutes ago" link and usually the reply link will then show.
The only site I commonly visit that doesn't work is BBC News, funnily enough. It's a little annoying because it will work if I change the user agent to iPad, but instead I just don't watch BBC News videos.
http://www.pcworld.com/article/250455/for_flash_on_linux_chr...
> Adobe and Google have now created a “Pepper” implementation of Flash Player for all x86/64 platforms supported by the Google Chrome browser, Adobe said.
Yeah, sure, Flash does a lot of crazy stuff that's hard to sandbox, and everyone who understands the code base probably left Adobe years ago, but what the hell is Adobe's own flagship Acrobat doing, that they just can't get it right no matter how many times they try?
Does pushing out so many updates increase the number of third party spyware toolbars that get installed, or something? Is McCaffe (or NSA) giving them a kickback for every virus vector they install that makes McCaffe Security Scan Plus seem useful, on top of the toolbar kickbacks? http://www.tiagoespinha.net/2010/10/adobe-starts-including-s...
Why don't they just run it through emscripten and be done with it?
Open Firefox and navigate to about:config.
You will be sarcastically warned that you about to void your warranty, just click on the “I’ll be careful, I promise!” button to move on.
Now search for:
plugins.click_to_play
Next you need to right-click and toggle the setting so that the value is true.Once you are done restart Firefox.
To test it out, head over to a site with Flash (BBC, ironically, has Flash), you will notice you will have to click on the plugin to activate it.
That’s all there is to it.
I'm sure there's a similar method for Chrome, but I don't have it installed to test.
- Open Settings
- Show Advanced Settings (bottom)
- Content Settings (under Privacy)
- Plugins -> "Let me choose when to run content."
- It will now be click-to-play and enable a icon like the pop-up blocker in the address back to enable all on a page or to whitelist the page.
- You can also whitelist from the settings page by clicking Manage Exceptions, and adding them like this: [*.]youtube.com (all sub-domains, and protocols on youtube.com)
I did not know chrome had this setting option, or I view it but did not really realize what it was for. I'm glad you took some time to list the needed steps.
Seriously, I've been Flash-free for many months, and I haven't missed a thing. I highly recommend it. Other than some really old websites, everything works as expected (YouTube, news websites with video, etc.).
Real Player was the market leader in DRM-ed video, until Flash improved and took over.
The issue is obviously the Flash player and the browser plugin architecture. With WebAssembly you get the "binary blob" executed without a plugin.
https://helpx.adobe.com/security/products/flash-player.html
Flash is and always has been an absolute joke, I refuse to install it on anything I own.
I'm sorry for the snark, but bbc reporting without details about Flash - including the helpful 'Flash is a commonly used browser plug-in' subtext below the logo - seems a bit off around here?
This should be a wake-up call to make flash non-default and, if installed, click-to-play only. Its time we started treating it like Java. Like Java, its clear its owner can't secure it. I imagine its borderline unmaintainable spaghetti code at this point.
Its also very hypocritical of Google, who has taken issue with SSL encryption levels and NPAPI, to be bundling what's essentially the second largest malware vector in browser history, only behind Java. This SHOULD be our wake-up call.
Additionally, it was Flash that was compromised, not Pepper. There's a distinction.