Firefox makes click-to-activate Flash the default
support.mozilla.org
support.mozilla.org
To be clear, by "blocked" Flash we really mean enforced click-to-activate. User choice is always a #1 priority at Mozilla.
We regularly block vulnerable plugins. What made this block different was that we did it before Adobe made an update available. Now that Adobe has released an update, it is no longer true that every version of Flash Player is blocked in Firefox.
However, we're glad to see the conversation this has sparked. Personally I align with Alex Stamos regarding Flash, in the thinking that a formal EOL would be great.
I'd also like to use this space to make a shameless plug for Shumway, a project set on building a faithful an efficient renderer for the SWF file format without native code assistance. Ending Flash doesn't need to mean an end for Flash media. http://www.areweflashyet.com/shumway/
Edit: typo
Unless you want to remove WebRTC and that's just stupid.
Fortunately it can be toggled off in about:config easily.
Set loop.enabled = false to disable hello, set media.peerconnection.enabled = false to disable WebRTC. If you don't want pocket, set browser.pocket.enabled = false.
You can even make yourself one big user.js file to fix the bad ideas that have been added to Firefox lately. Mozilla still has a good thing going for them, and that is user choice. However stupid the defaults get.
Off should be default. Let those that want to use these features turn them on if they want. Or better yet, ship a damn extension.
I'm a Pocket user, but I have no idea why that needed to be integrated into the browser, seems like an insane decision to me. I hope they got a good pay day out of that.
Same as the history based advertising tiles. Sure, it's checked locally, it still seems creepy and annoying... but again, browser.newtabpage.enhanced = false.
Unless we lose this level of user choice, I don't see a better alternative. It would be nice if someone would ship some tool to automatically update a user.js file, however, I think many of us have different opinions about what feature we do and do not want enabled in our browsers.
Off by default is neither removing user choice, nor is it preventing Mozilla from saying they ship with feature X. It is the right way to present it.
It lets more sophisticated users choose. Less sophisticated users however will more likely switch to a different browser the moment a site doesn't work before poking through settings.
I think a better way than a separate setting would be to go in the direction of many software firewalls and present it to the user as a choice when an application requests it as many browsers currently do with the location APIs. This would provide individual domain-level control over what permissions sites are granted by you. I don't know why this sort of policy seems to be restricted only to the location APIs...
Before, mozilla was implementing their own pocket competitor. Switching to pocket, and existing solution, allowed them to save money.
Firefox doesn't even predefine some of the things in "about:config" that need to be set to turn off some of these undesirable features.
There's IceCat, a GNU fork of Firefox without all the proprietary extensions.[1] It may start getting more traction as Mozilla puts more junk in the browser.
These things are lazy loaded and wont run until you turn them on. No footprint when they're off the UI (minimal footprint when they are on)
I still think WebRTC enabling peer to peer connections is better than running all of your data through a third party server.
Extremely few people have active IPv6, it seems unlikely to catch on now. In addition to that, IPv6 privacy extensions may allow a solution to this problem for many users, but if their link local IPs are also published that may lead to further trouble, depending on configuration. Remember though, this leaks all interface IPs, I have many virtual machines installed with their own network adapters added to my system, VPN adapters, etc which also leaks data as all of those adapters will have v6LL IPs on them even if they're not in use.
Additionally, this issue is already actively being used for fingerprinting. Not some exploit of tomorrow. There was a New York Times advertiser caught doing it a few days ago.
> I still think WebRTC enabling peer to peer connections is better than running all of your data through a third party server.
Yeah, which is why I encourage disabling it completely. Until either they fix the privacy issues or the value of using some WebRTC application appears to trump them to you.
Except that over 20% of the United States has IPv6 connectivity. In fact, you might be using it without knowing (most mobile providers have it now, in fact some use IPv6->IPv4 translation methods) [1].
>Remember though, this leaks all interface IPs
Does it? Maybe you should file a bug so that only routable interfaces and non-LL IPs are used. This does seem like a problem.
[1] https://www.google.com/intl/en/ipv6/statistics.html#tab=per-...
The entire rest of the world has near-zero, just look at your own link. I'm in Canada and we have 0.55% here. No local ISP will offer it to me, and the one that did withdrew it completely last year. So perhaps I'm just slighted. There are a few other countries with 5%+ but it still makes up only a very small percentage of internet users. To top it off, while there has been some IPv6 adoption in the US, CGN has also caught on pretty heavily all over the world and seems to be, sadly, the solution most ISPs will actually go with for the near term at least.
> Does it? Maybe you should file a bug so that only routable interfaces and non-LL IPs are used. This does seem like a problem.
https://diafygi.github.io/webrtc-ips/ is able to immediately reveal all the VM interfaces on my system even with no VMs using them. I suspect this is done so that faster routes may be established, but it is indeed a major problem for anyone who doesn't like fingerprinting.
IPV6 isn't going anywhere: IPV4 exhaustion is a real concern and with the internet / internet of things growing, the only place to grow is really the IPV6 space. NAT only delayed the inevitable.
See here - https://ipv6.he.net/statistics/ - for current statistics on how many IPV4 addresses are left.
(And of course I go against the public opinion here on HN, but I wonder how many people did actually use Pocket before trashing it?)
I'd reinstall the old one but "This add-on has been removed by its author".
I've been using Pocket since it was Read It Later and I was pleased to see it integrated into the browser. Mozilla is working on a Reader mode[0] but it does not seem to be ready for public consumption yet (despite landing in 2012). Most people don't even know it exists, and it obviously does not save it for later (unless you bookmark it). The implementation is open-source (MPL license), although Pocket itself is proprietary. Hotword detection is not absolutely necessary for browser functionality, yet I hear no chorus of complaints from Chrome users. Should Mozilla be prohibited from partnering with proprietary third-parties whether or not it benefits their users?
Hello is even less of an argument. Firefox Hello is a simple Javascript UI for the existing WebRTC spec supported by Firefox, Chrome, and Opera[1]. It allows people to communicate without having to set up accounts, sign-in somewhere, and works against the platform lock-in of proprietary services such as Facetime, Hangouts, and Skype. If it's disabled by default, the service becomes useless. My parents shouldn't have to enable it about:config for me to talk to them, nor should they have to download another plugin to use a technology built-in to the browser. I understand the security implications[2] in IP leakage[3], but I don't see a simple fix that doesn't neuter the functionality (although this comes close[4]). W3C has stated their position on fingerprinting[5], but at least Mozilla is actively working on the issue.
0: http://www.ghacks.net/2015/02/07/mozilla-starts-to-push-read...
1: https://support.mozilla.org/en-US/kb/which-browsers-will-wor...
2: https://twitter.com/incloud/status/619624021123010560
3: https://bugzilla.mozilla.org/show_bug.cgi?id=959893
4: https://addons.mozilla.org/en-US/firefox/addon/statutory/
5: https://github.com/w3ctag/spec-reviews/blob/master/2015/05/f...
2) Click "Customize"
3) Drag pocket and / or hello from the tool bar into "Additional tools and features"
4) Take a breather, phew that wasn't too hard was it?
https://support.mozilla.org/en-US/kb/customize-firefox-contr...
If a masochistic user wants to navigate the labyrinth of dark patterns meant to confuse them into not understanding that the "Additional tools and features" category is also the "completely disabled features that run nothing in the background" category (why would anyone think that, ever?), then they can go ahead and do it. If these things are so great, then I'm sure users would be happy to put that extra work into enabling them. After all, it's 3 simple intuitive steps!
Some websites' video don't work as well, they have JS or CSS that interfere, or assume that you don't have flash installed, or retaliate as if you are an ad blocker, so I'm glad to see this is becoming more widespread, those problems may be fixed.
Flash is never blocked for me in Firefox and never will be. Because a few months back I did this:
1. about:config 2. extensions.blocklist.enabled - 'false'
Job done. No more Mozilla annoyances between me and the content I wish to access. And yes, it was an annoyance because the link to "check for updates" in your message would not get me anywhere. That was a flaw in your strategy that I now suspect was deliberate. I really can't respect engineered annoyances that align with agendas rather than good UX.
I like Flash when it's done well. Raw performance and efficiency is one of the things I like about it. The powerful multimedia handling of everything from audio to video cannot be matched by HTML5. I'm an HTML/CSS/JS dev for my living for 20 years, that's how I know this to be true.
HTML5 video is cute. But it doesn't cut the mustard in all circumstances.
360 video, VR, and many other things will come along that are too much for web technologies to handle. Flash serves a useful purpose in allowing websites to cater to the most demanding cutting edge tech and content without needing the Firefoxes and Chromes of the world to keep up.
"closed source"; "battery drain"; "plugins are just bad".... oh cry me a river.
My comment has reached EOL.
Grow up.
Holy shit, it's like you're throwing nappies at me and telling me I should wear them immediately. I don't want or need a nappy.
Holy shit, look at this: http://www.cvedetails.com/cve/CVE-2011-3660/
"There is total information disclosure, resulting in all system files being revealed."
OMG it's from 2011, and those poor people from 2011 with Firefox installed.
Listen. I am not worried about your CVE's. Got it? Don't push your paranoid, unsubstantiated crap into my reading.
If I'm vulnerable, where's the stories of "person with Firefox and Flash gets owned" stories? Link me one, just one.
If you want security, if you want privacy. Close you damn Facebook account (if you can). Good luck.
nightpool..... some advice: uninstall your virus protection program for one year. Let us know how you go in a year. (hint, you'll be fine).
Hack me.
Congratulations, you just left yourself open to malware masquerading as addons.
And shock horror, I don't even have a virus protection program installed. I install one ever 12 months or so. Actually I install a few at one time to be thorough. Do a complete scan, and of course it comes up 100% clean, then I uninstall all of them and get on with work.
Continue being paranoid and using up CPU cycles to serve your paranoia while I enjoy a lighting fast workstation. The choice is yours. Choice is good.
When I was student, I didn't buy games. I downloaded them. Got malware and worse even with virus protection. I buy games, since about 2002 I just buy the software I want. No virus/malware issues here.
This is some comedy gold.
A: Built something in Flash
B: Built the exact same thing in JS and measured their performance side by side in the page, and on separate pages.
Even sliding an image - such a simple thing. Make it whoosh to the left. Guess what? Flash will whoosh it quicker and smoother on browsers with Flash installed.
I love JS, it's cool for web stuff and data fetching and sorting for a huge percentage of the internet. I had a great time with it doing multiple AJAX calls and sorting for a single page thing on a heavy traffic media site. Love the whole promises thing for sorting out those pesky asynchronous dinguses. Yep. HTML5 does indeed rock. Really love modern CSS too. Hate grids though but each to their own. I don't say "grids should die".
JS/HTML is not superman. If you want superman on your webpage, you need something more, such as a plugin.
Unity plugin. I might use that next. I really don't want to be fighting people about the value of plugins, even if that value and scope is reduced from what it is a few years ago, it's still there. I want to make games, and what is clear to me after trying an HTML game is that..... it's pretty much a joke. HTML5 games in 2015 are, a joke.
How dare anyone at Firefox or Facebook put forward an EOL for someone else's technology. EOL your own stuff, not someone elses. Bloody rude if you ask me.
"Flash should die because it has equal performance to native iOS apps". That's what I read between the lines in Jobs' letter. I like Steve Jobs, but he was a player. A chess player. We respect chess players, but they won't hesitate to knife you in-game.
If Flash dies, it's the hate that killed it more than any sensible reflection on the technologies we have available and how they can best be used.
If nothing else, hope I've added more comedy for you.
For the record, I'm more than fine with that. In fact, I've used extensions to get that effect for years.
I think most of the speed as a plugin vs native html/svg/js is that you don't have the whole DOM to deal with (including reflows, etc), and that their ActionScript is a much smaller subset of a language than JS in the browser, AS3 changed things a bit though. Today with canvas and an audio api that mostly works, you can get the same.
What I really wish is that Adobe would create Flash-level tooling with outputs for HTML/canvas/js/web-audio and video.
Do you have any interest an organizing an effort, along with Facebook's Alex Stamos and other folks, to plan a formal EOL for Flash? Of course, the steps Mozilla and others have taken help, but perhaps a more organized movement could get other thought and market leaders on board, trigger higher rates of HTML5 adoption and foster the bits of remaining innovation that are needed to fully replace Flash on the web.
Also, does Firefox plan to address the concerns brought up about Hello, and, more importantly, Pocket?
If you can access a Github repository then you can do so with software fully under your control (and hence make copies of the data as you wish). Did I miss something?
Well, then there are many real world use case that are not doable in our version of reality, where data can be copied ad infinitum, and where you NEED to show the end user unencrypted data.
NPAPI has its own privacy and security and stability reasons to meet a swift doom, even independent of the DRM question.
"To prevent these add-ons from running, click Restart Firefox."
Why doesn't the dialog box have that same explanation? Did you (mozilla) think the two button options "Restart Later" and "Restart Firefox" won't confuse people?
Unimplementable Features on iOS: Image effects for whirl, fisheye,
mosaic, and pixelate. Sound and video input for loudness, video
motion, and touching colors from the video.
https://github.com/LLK/scratch-html5I really like Scratch, but it's a pity that it's implemented on a platform so many people think should no longer exist.
(Assuming you can get the pixel data; but getting the pixel data from HTML content is actually a security nightmare…)
I'd love it if you kept it like this and implemented a flash whitelist function. Flash needs to be treated like Java: its legacy tech that should be used only via whitelisting. Google is too embedded into the marketing and advertising world to ever consider doing this in Chrome. Its really up to you guys, per usual, to save the web.
Do that carry any value these days?
Heck, it seems weird that Mozilla can push plugin warnings directly to the addons ui but can't indicate if a plugin can be upgraded.
Technology should be replaced by better technology. To give you some background: I've written games for all kinds of platforms: PocketPC, Windows Mobile, (Desktop) Windows, Linux, OS X, Flash (AS3), HipTop, J2ME devices and some smaller proprietary devices.
Some of those platforms offer write once, run everywhere. On other platforms every device has it's own quirks and you have to test on every device and implement workarounds.
You might not like Flash, but it is great at running on every platform/browser with the same code base. If you test it on one platform, it runs on all others. (Adobe is also very good at keeping it backwards compatible)
Now, I ask you, what's the alternative for Flash? Does HTML5 offer write once, runs the same on every platform/browser(version!)? No it doesn't, and it never will. Even simple HTML pages are full of browser checking hacks.
Now, if you can offer a programming platform where the games I develop on, run exactly the same on every browser, on every platform, I have no problem killing Flash. But let's be honest here, only plugins can guarantee such a thing.
As to Alex Stamos, the top games on Facebook are all Flash. You know why? Because developers don't have to worry whether or not those games will run inside the users browser. Because once Flash is installed, they will run without issues. HTML5? No such guarantee.
So before you declare EOL, please have a proper alternative, where I don't have to pull my hair and cry all night because browser X on platform Y version Z seems to break the end boss of level 5 in my game because its implementation slightly differs from all the rest.
Even plugins can't really get you what you want here. Yes, HTML5 has limitations, as you described, but plugins aren't the solution. HTML5 is closer, and moving in the right direction at least.
One codebase, runs everywhere, Flash in the browser, apps on mobile devices. Personally never had an issue with it.
Although I must agree with you that it's sad Adobe dropped Linux support.
Though personally I can understand why Adobe dropped support for linux, the market is just too small. Even though this community probably has a higher percentage of linux user then just about anywhere.
If Adobe decides to deprioritise a platform that mean the users of that platform with experience less support in terms of bug fixes, performance and security. If Adobe decides not to support a platform period that means users of that platform are left without a means to access Flash content.
If you are a user this is unacceptable. More importantly these things have already happened.
For websites, HTML5 offers enough to be considered a proper alternative. Yes, I probably dislike Flash websites as much as you do.
But for games, HTML5 just doesn't cut it compared to Flash (or yes, even Java applets as someone else mentioned ;)). And the sad truth is that by design, each browser vendor will have it's own implementation with it's own quirks.
(I seem to be getting a lot of down-votes on my original post, although I don't think I said anything incorrect)
Case in point, OSX. Wasn't until Flash v11 that OSX had hardware-assisted playback.
Unfortunately, that alternative is Java applets.
Now when WebGL is widely adopted why you can create your games using that technology? Or even compile your C/C++ games with asm.js. I saw very nice demos in the past.
For simple 2D games (like most of the Flash games), I saw very nice Flash-friendly libraries like Phaser[0] (based on Pixi.js).
This is in Firefix 39.0, Windows.
Let's try IE, I'm curious. I need to click 'Show all content' at the bottom, and after that I see the animations. I tried the 'virtual joystick dpad' example and it works. But the cutouts of the joypads seem off. You can see their rectangular cutout, got the impression transparency isn't working properly, but also possible it was designed that way. But I don't think so because the screenshot of that example doesn't have it, so I guess it is a platform issue.
One more go, my iPhone: It doesn't scale properly, way too big for my screen. Can't zoom out or scroll. But the animations seem to run in the corner of the screen that I can see. Same transparency issue as on IE.
And let's be honest here, those examples are pretty basic and simple.
I said when you write ActionScript3, for desktops you export to Flash and for mobile you export to iOS and Android. Runs the same everywhere.
So how do you get your WebGL game onto mobile platforms?
Blocked loading mixed active content "http://examples.phaser.io/embed.php?f=arcade+physics/angle+b... [1]
HTML5 is less to blame here; the administrator of phaser.io should configure their service to serve these javascript files over HTTPS
[1] https://developer.mozilla.org/en-US/docs/Security/MixedConte...
The things on my site (video, some ads) that use flash will fall back nicely to HTML5 is Flash is disabled, as will most of the web. Click to activate is the worst of both worlds.
If you run the popular browsers/plugins against the National Vulnerability Database, you'd get the following results (as of January 2014):
- Internet Explorer 366 total vulnerability issues (314 high severity)
- Google Chrome 235 total vulnerability issues (154 high severity)
- Adobe Flash 207 total vulnerability issues (169 high severity)
- Mozilla Firefox 190 total vulnerability issues (86 high severity)
- Oracle Java 161 total vulnerability issues (69 high severity)
[source] https://nvd.nist.gov/January 20, 2015: https://community.rapid7.com/community/metasploit/blog/2015/...
February 25, 2015: https://msisac.cisecurity.org/advisories/2015/2015-018.cfm
March 1, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-3...
April 22, 2015: https://msisac.cisecurity.org/advisories/2015/2015-046.cfm
May 12, 2015: https://www.mozilla.org/en-US/security/advisories/mfsa2015-5...
Hackers search for remote code execution exploits in Flash first and foremost because they know a successful Flash exploit will reach the highest number of targets (90% or more on the desktop) whereas only 44% of desktop machines are running Chrome and 15% are running Firefox.
Hackers seeking out and exploiting RCE bugs in Firefox is unheard of for the same reason malware targeting Macs has been virtually unheard of over the past decade: It's not that OS X is more secure; it's simply that Windows is a more lucrative target.
Source for this complete and utter FUD? Certainly not the links you gave:
Jan 11, 2015: Originally reported to Mozilla as a low-severity DoS, which turned out to be already patched in trunk Jan 13, 2015: Firefox 35.0 shipped with patch
It's hard to get dates out of the others because the bugs are still hidden, but the "fixed in" is often a security fix update after a release, which means it can't possibly have been > 6 weeks.
This leak was the best thing that happened to the web.
- Performance has not been good on Macs (my 2007 Macbook Pro literally burned my legs when running anything flashy)
- Flash updates mechanism seems a little spammy.
- Long-term perception of Adobe as a maker of a somewhat buggy, somewhat bloated software
- Steve Jobs' public denigration
- Backlash against proprietary standards being used on the web
The best thing about click to play Flash is it puts a stop to autoplay videos on the less reputable sites I occasionally and shamefully glance at for sports news.Granted most of it might be bad programming, but I still think he comes from here rather than exploits.
JavaScript enabled by default is already bad enough. We don't need Flash, Java, ActiveX or anything similar turned on by default. So it's a good move from security viewpoint. Less attack surface.
Internet Explorer and Google Chrome get updated in a way that most end users find to be simple to understand, particularly with Chrome. Firefox is also quite good in this regard. All of them are reliable - it is rare, IME, to come across a Windows Update, Firefox or Chrome instance which is silently failing to update. Or not even bothering to prompt to update.
Flash, however often I install it, just doesn't seem to auto-update reliably. Quite often it only does so after a user log on/reboot, which doesn't happen much in the days of standby. Even on brand new, fresh Windows installs (so we know the OS/Flash isn't broken), I test Flash from time to time and it just doesn't prompt to update at all on some occasions. This is what makes Adobe's poor track record exponentially worse - that their software update mechanism is crap at best.
I was gobsmacked when Microsoft declared they were going to start updating Flash via Windows Update. Gobsmacked and so very relieved. It felt like they'd walked into Adobe's office, grabbed their fire extinguishers and told them "You are so useless that when there's a fire, WE will come and put it out, since you don't seem able to. We are sick of our offices getting burned down because of your idle incompetence."
I won't even address Oracle's Java. Bundling malware with their updater is tantamount to crime.
If you keep ignoring the update prompt, Flash will quietly update itself after 45 days. That's long enough for every interested party to pwn your machine.
I have a lot of experience of end users and they are
forever telling me that they get so many different "Update
this", "Update that" windows that they can no longer
distinguish real from fake. Some of them have been tricked
by fake web site pop-ups as a result, others ignore
legitimate update messages. I do not blame them.
One solution to this is to use AdBlock Plus. When a site permits adverts that threaten a computer's security, it is time to add it to the blocklist.Ugh (damn capitalism!), I think I shall move to ublock origin today then.
Thank you for letting me know about it :)
The best solution for this, from Adobe's own forum? Find the corporate-deployment version, download that (ignoring the messages that say it isn't what you want) and run it. This works flawlessly, but even less automatically.
Both the Flash and Java updates almost feel like "Pay Attention To Me!" Just like all those discount cards that exist in part so you carry around a fetish with the corporate logo.
Silent auto-updates are really the right way to go for non-techies. Even the post-upgrade 'announcement' popups are confusing. For instance, I've installed Ghostery on their computers and the 'ghostery has been updated' popup is just confusing for them, leading to confusion and phone calls to me.
Flash also doesn't seem to auto-update for them, despite me setting it up. I don't understand it either, as they turn off & on the machine regularly. Why can't Adobe get this right?
"It is difficult to get a man to understand something, when his salary depends upon his not understanding it!"
That's the real reason they don't want a auto-update. Google pays them a lot for bundling Chrome(I think it's around $1 per install). They keep breaking the auto-update on purpose so that they can make a ton of money by bundling other software. Same with Java updates.
Even Windows has Flash via the updater.
Just about the only browser that use the old API is Firefox.
Really, at this point I think Mozilla is more interested in just getting rid of plugins than trying to implement an alternative to NPAPI - why put all the effort in to support something like PPAPI when plugins should be dead within the decade anyway?
Also, getting rid of the constant update dialogs and crapware installed with Flash will improve the overall user experience.
Flash game enthusiasts would probably disagree, but most of us can probably do without it given the risk.
I've since found a few work-related apps that need it. Hiss.
So just counting high severity vulnerabilities, the chart is
IE: 314. IE with Flash: 483.
Chrome: 154: Chrome with Flash: 323.
Firefox: 86. Firefox with Flash: 255.
And of course, you can add a third column for Java and a fourth column for browser with Flash and Java.
I have no idea what their bugs-per-line-of-code are, perhaps they have the finest code on the planet. But from a surface area perspective, installing Flash makes you more vulnerable, period. And it really is not necessary, whereas it’s not like you can browse the web in pure Flash and not install a browser.
So does turning on Javascript. Yet the popular opinion these days is that disabling Javascript makes you a luddite. Mozilla even hid the option for it in Firefox.
That's misusing statistics, you can't determine how secure something is by just summing up the number of vulnerabilities - equally weighing/comparing browsers with a plugin etc.
By the way, Apple's opinion on Flash in 2010:
Third, there’s reliability, security and performance. Symantec recently highlighted Flash for having one of the worst security records in 2009. We also know first hand that Flash is the number one reason Macs crash. We have been working with Adobe to fix these problems, but they have persisted for several years now. We don’t want to reduce the reliability and security of our iPhones, iPods and iPads by adding Flash.
Also, considering the track record of Flash on Android, your opinion is not supported by historical fact. It is very clear that Adobe is not on the ball to anyone who pays attention.
The sooner Adobe abandons the dead horse, the better for all of us. Kevin has gone away for years now, and Adobe's force is not based on Flash anymore (disclaimer: I own Adobe stock)
Unless you count iOS, Android, BSD, Solaris, QNX, Debian etc.
https://support.mozilla.org/en-US/kb/set-adobe-flash-click-p...
I feel your pain. The university site I'm working on has flash protein visualizations. We're finally moving visualizations to js. We'll get there, but with flash being kinda turned off, users will have to turn it back on manually or our pages won't work till rid of flash.
To quote a Chrome developer: "Click to play is not actually a security boundary. In particular, it has always been subject to click-jacking."
And calling it unsafe, well, that's the truth.
Anger towards browser developers or HTML5 is misplaced; you should be angry with Adobe for the fact that Flash is buggy, insecure, and closed-source.
I agree, which is why I wish browser vendors would block WebGL by default.
I'm not holding my breath though, because the reality is that market demand from people like game developers (or at least, perceived demand) is what is driving the addition of so many complex new APIs to the web.
You can go into add-ons and make it click-to-activate like flash, however.
If you think unwanted annoyances only come from Flash, you're mistaken.
(A quick Google search shows they used to use it for the network graph but it is now Canvas.)
What developer doesn't know how to copy to clipboard?
https://github.com/blog/1365-a-more-transparent-clipboard-bu...
On a side note Firefox without Flash is so much smoother. IMHO it is the fastest and most stable browser when it doesn't have Flash bogging it down.
5 to 7 years ago I would have said the same thing, I hated Flash with a passion. But now, when it's almost gone for good, I see that it had its reasons. For example the new Google Street View is many times slower and lags so much as to give me motion sickness (when it's not blocking my browser) compared to the previous version, which was Flash-based, and which used to work like a charm.
I think the terribleness of recent Google web front-ends (not only Maps and Street View but also Search, Mail, Groups, Gplus, etc.) is mostly a product of incompetent management process internal to Google, rather than an indictment of web technology generally.
I've gone back to a desktop mail client (Thunderbird) and moved away from the web for this sort of thing myself.
As far as the web goes, I am very impressed at openstreetmap. That is fast, accurate and has more useful mapping data than anything else rather than fancy overlays and imaging.
Just having it find my location became a chore. I'd be walking down the street looking at my phone the whole block, waiting for it to get my location. Many times it would show my location (with several miles of uncertainty) as being somewhere that I had not been for more than several hours. Other times it would just never find the location at all, not even having any idea what country, let alone city, I was in.
I downloaded OSMAnd and the province map data, and it was able to find my location within mere seconds every time. It was able to do it fast enough that if I clicked the power button as I was pulling my phone out of my pocket, it would have my position before my phone was in front of my face.
Unfortunately OSMAnd does not do transit routing, so I was attempting to use both at the same time. This gave me a direct comparison between how fast both were able to find my position, and how accurately. OSMAnd blows Google Maps away. I often resorted to typing in my "from" location in Google Maps, just so that I could use it to find routes for me while it was stalling on finding my location itself.
My location permissions were all correct. I tried wiping the application settings, with no luck. On the last day of my vacation I uninstalled all the google maps updates on my phone, and tried the version that shipped with it. It worked just fine.
If anybody else ever gets annoyed at Google Maps being unable to find their location in a timely manner, I highly recommend they try OSMAnd. It saved my vacation. As a bonus, it even behaves sensibly when on a boat.
Despite Google's claim to the contrary, they obviously no longer care about performance for some of their web-products.
I did go through the crash reporter.
I don't have much problems with Firefox, it seems to work smooth. May be it's Google's fault?
The company I work for makes interactive/animated training media. While I work as a coder doing mostly server-side stuff, I can vouch for the power that the Flash authoring environment provided. It was rather similar to something like Unity, with a tightly integrated scenegraph and coding environment. For our team of animators who (by necessity, not by choice) picked up some coding chops on the job, it was a huge blessing.
Moving everything over to web technology has been extremely painful for exactly one reason: lack of a decent authoring workflow for interactive animations. There's nothing that can even touch Flash in this regard.
I've heard Facebook video and last.fm streaming don't work without Flash for eg.
Regarding Facebook video, I fail to see how that is a bad thing ;)
http://www.html5rocks.com/en/tutorials/eme/basics/#clear-key
That is primarily because of the flash ads being dumped. An ad/flash/js blocker achieves much the same and then some by further reducing the latency to collect everything needed to render.
I posted a similar comment about it the other day: [0]
Personally I would like to see HTTP Live Streaming (HLS) [1] implemented in the all the browsers, it's a nice lightweight protocol and would be the path of least resistance since it's already used heavily in the mobile space.
[0] - https://news.ycombinator.com/item?id=9874338
[1] - https://tools.ietf.org/html/draft-pantos-http-live-streaming...
For everything else however (like pre-recorded video, games via WebGL), Flash should be phased out.
Interestingly, Google Chrome recently moved in the opposite direction, and removed support for having Flash off by default and activating with a single click. Instead, they consider Flash to be "important plug-in content". While they allow you to have it off by default, rather than "click to play", they now require that you right click then pull down to "run this plugin" each time you want to activate: https://productforums.google.com/forum/#!topic/chrome/xPcpRB...
I presume this is because they want to discourage people from having Flash off by default, since this would mean they would miss too many Flash ads. I took this as an opportunity to try out some different browsers, and found that Opera met my needs slightly better than Firefox. If you are looking for an alternative to Firefox or Chrome, or just want to see what's out there, you might want to check it out too: http://www.opera.com/
ps. As an example of the new Google interface strategy, to show all the responses on the Google Chrome Help Forum link above rather than being forced to click on each one, you can press the 'o' key some random number of times until they appear: https://productforums.google.com/forum/#!topic/gec-answers-f...
See https://groups.google.com/forum/#!topic/mozilla.dev.platform...
Flash isn't super relevant anymore anyway, the main thing it's used for on my computer is Flash tracking cookies, and I can do without those. I do wonder how some of the tracking and retargeting companies will deal with the decline of Flash though. We asked a partner to stop using Flash for tracking, their response was that it's the best way to doing user tracking. Hopefully they'll change their mind soon.
After all that you have to download a DMG, close all your applications and reinstall from scratch. Why not just build in an auto-update in the background and be done with it...
Many old sites will stop working (my first site was done in flash) as well as many games that are still heavily played today by millions of people. Also flash IDE provides a good introduction to programming for self-taught kids these days: many of them still do their first code in flash after clicking on "that strange icon next to photoshop".
Overall this is a good example of prolonged trusting a binary blob. IMO we will always tend to do what is more comfortable and we should strive for openness and transparency in the tools that most people rely for everyday.
The problem persists as long as there are people installing the plugin or "enabling" it.
We need a real open-source alternative to flash player.
We quietly built the alternative to Flash over the last 10 years. It's called the web.
A standard document in the web browser can play audio, video, display vector graphics, utilise OpenGL, supports direct drawing via Canvas, and it is deeply scriptable with a mature, open programming language.
What else do you need?
(Github project pages have a flash application to handle this)
However the API is god awful.
To be fair, it's basically a proprietary IE5 API that's now been standardised (like quite a few others).
Amazing, thanks.
I need all of those things to look exactly the same in each and every browser, instead of corrupted icons or broken navigation because the developer tested it in Chrome for Windows but neglected, say, Iceweasel for Debian.
I have yet to find a non-flash game capable of doing that. And if the alternative is "we should discard this closed binary that works in every platform in favor of this free-but-browser-dependant stack", I find that odd.
Bad example, because Flash for Linux has been discontinued in all flavours except PPAPI so it wouldn't work in Iceweasel.
The 'Web' can't play video or audio, the 'Web' needs plug-ins to do so. Plug-ins like H264 decoders and Flash.
Right now, you can put a <video> or <audio> tag on a page and it will work in something like 95% of the browsers in use. That's already better than Flash and going up as IE8 users upgrade to newer versions of IE or install Chrome/Flash.
Sure, you can't rely on users not recompiling their browser to disable it but you also can't rely on 100% support for anything on the web – users disable image loading, plugins, stylesheets or JavaScript, install incredibly overzealous ad-blockers, use ISPs which tamper with page contents, etc.
* Adaptive bit rate video streaming (recorded or live)
Nice to have but not required:
* Full H.264/AAC support across all browser.
Unfortunately Flash is the only viable solution for the above right now.
Flash components were really interesting, and made it easier for non-programmers, or designers to manipulate a user-friendly "API" of sorts within Flash. This was very powerful. Hugely underrated and conventionality forgotten by the Flash-haters.
Granted, it's just an anecdote, but I wonder what I missed that made others find Flash so accessible.
Sounds like you favour Perl over Actionscript. From what I know of both, they are not commonly compared! But as with many things in this business, it all depends on your needs, likes, and the project requirements.
If it's because you enjoy the Adobe Flash tooling, then Adobe is doing exporting to both Canvas and WebGL now.
http://www.adobe.com/inspire/2014/02/flash-html5-canvas.html
https://helpx.adobe.com/flash/how-to/flashpro-export-webgl.h...
There are plenty of PC Emulators aviable that run Windows XP and flash just fine. You shouldn't connect them to the internet though.
Look at what happened to Java applets.
It would be very sad to see this become the state of all the old flash games/animations.
The one thing I have learned during that time is:
How to write a good VuXML entry.
I agree with the general sentiment of removing Flash, and will do my part in convincing others that FreeBSD (and, derived, PC-BSD and FreeNAS) should probably consider setting an expiration date for Flash, then at that date delete it.
I do turn it on (enable) every now and then for some sites, but very few/infrequently and turn it off right after.
* Plugins can be enabled using one click;
* The "Copy shortcut" widgets are disabled by default. Too bad, 2 clicks instead of one.
* Some videos are disabled on some news website. Too bad they won't be able to auto-play.
* I very rarely encounter websites (less than once in a month) where invisible plugins are required, so I need to restart the page with all plugins activated. I think Google's Not-a-robot Captcha has difficulties with that, if I remember well.
I chuckled when I saw this: http://i.imgur.com/CHqRSEZ.png
:)
"All versions of Adobe’s Flash Player plugin are currently deactivated by default, until Adobe releases an updated version to address known critical security issues."
This implies that it will be reactivated soon and this isn't a permanent block. It looks like the same mechanism that blocks old and vulnerable versions of plugins like Silverlight.
That said, I've not installed flash in years. I use Firefox as my main browser with no plugins and IE/Chrome have it embedded (both auto-update with no system restart required).
Which prevents a lot of autoplaying videos, and also pages sometimes taking a long time to load on slow connections.
Which is a reasonable question in this context:
On the consumer side of things, flash is not so bad. Sure search engines couldn't read it but there is amazing content generated through it. The content is,what matters and unfortunately the Web is littered with abusive flash objects auto playing videos, audio, full screen ads and those won't simply go away with flash.
At least with flash I can easily disable it. But those auto playing html5 videos and audios ads are just as annoying. Now I need plug ins to disable native capability.
It's only a matter of time until all ads move to the medium and we find ourselves complaining.
Flash ads (including video) can be horrid on CPUs, but they also often have higher CPMs than static, "cheaper" ads. Firefox seems to be blocking flash entirely. They’re also doing it in a way that the ad networks can’t tell, unlike Chrome. In other words, if I disable Flash in Chrome, the ads normally fall back to (cheaper) non-flash ads. On Firefox, I’m getting blank gray boxes.
For sites that depend on advertising to survive, hopefully the ad networks will update their inventory with alternative non-intrusive ads a.s.a.p. so this type of (admittedly much needed) evolution doesn't suck too many content providers down.
There is support: http://pipelight.net/cms/installation.html
For me on debian it was install and it worked without even restarting the browser.
http://blog.chromium.org/2014/11/the-final-countdown-for-npa...
Edit: Ah, looks like I needed to update Chrome with the fix.
Here is how to deactivate it
You need to go to chrome plugins and disable it chrome://plugins/
edit: I use Windows 8.1.
There's no updated version yet.
Enter chrome://plugins/ in your address bar, find "Adobe Flash Player", uncheck "Always allowed to run".
You'll then have to right-click flash content to play it.
Any suggestions for a simple milt-file upload JS library? Something that works on new browsers, and falls back to flash on old browsers.
The week of July 12 is this week.
For anything else html5 video has been generally working. I've noticed a lot fewer annoying adverts too which is a bonus.
If you don't need the specific features in the Google Finance chart, that might be a good alternative.
(Disclaimer: I work at Google but not on Google Finance. My own opinion, yada yada.)
Did you mean any specific codec for video playback, or something else?
Outside HTML5 scope, though.
Why on earth should Firefox ship a different HTML5 engine for Linux than for the other OSes? To me, it doesn't make a lot sense to assume Firefox provides a better HTML5 implementation for all other operating systems.
With all due respect, this comment seems to be more of an overall anti-Linux sentiment.
But I'm still wondering, as we have very good decoders from projects like FFmpeg and VLC. (Not sure which of all those decoders are used by Firefox.) These are platform independent and to my experience better than the platform specific libraries.
For example, I often hear that people install VLC under Windows because it decodes lots of video formats better than the natively available Windows Media Player. So the native Windows libraries probably aren't that good.
Also, at least the FFmpeg project explicitly states that they don't care about patent FUD, so we can safely assume they don't cripple their decoders in the fear of violating patents: https://www.ffmpeg.org/legal.html
Firefox does ship a lot of other video and audio codecs though, such as vorbis, opus, theora, vp8, and vp9. It's recommended to use these for HTML5 when possible because they can be easily supported everywhere.
Just a minor nitpick: Under Linux, people don't download from Mozilla but have it installed by default. If not, they install via package manager and not via download from Mozilla.
So it's not Mozilla making that decision, but the respective Linux distros. But of course they have the same problem.
I believe a good compromise would be to check if ffmpeg is installed on the system, and use it only when available. So the user would have to install ffmpeg directly.
That would be a very different situation from including code from ffmpeg directly into some app.
Disabling Flash however, Youtube actually seamlessly falls back to HTML video. Well done. But I can't help but think, outside the Youtube world (BBC for e.g.). LOTS is going to break. I wouldn't take this tact with my parents or clients.
My browsing workflow involves a lot of middle-clicking links to open them up in background tabs. Autoplaying video is major annoyance in this context.
In Safari, if you tab out a new page, it will load the content but pause it until you show the page. So you can tab out a bunch of video pages and they each only autoplay when you tab through them.
Wanting the same functionality on Chrome seemed to involve plugins or clicking (which has now turned into right clicking and choosing play).
No since January[1]. Maybe you have an old cookie set or something?
[1] http://youtube-eng.blogspot.com/2015/01/youtube-now-defaults...
I would suggest checking the https://www.youtube.com/html5 page sp332 suggested to see if you have checks in all those boxes and making sure you're using a recent version of whatever browser you're running[1]. Only if your browser doesn't support the needed html5 video features does it switch back to flash.
[1] https://bugzilla.mozilla.org/show_bug.cgi?id=778617 for the ongoing Firefox bug, but you should be good with MSE in recent Firefox on Youtube in particular (see last comment in that bug)