The Call to Kill Adobe’s Flash in Favor of HTML5 Is Rising
arc.applause.com
arc.applause.com
What do we do about the historic content that will never, ever be ported to anything other than Flash? Every thing on Kongregate? Newgrounds? Homestarrunner.com? Desktop Tower Defense? We're talking about taking a decade's worth of interactive web content and declaring it no longer relevant. Without a plan for preserving that material and continuing to make it accessible, I think that killing off Flash rather than deprecating it is a terrible idea.
What about the game industry? What about the animation industry? HTML5 doesn't replace Flash for those arenas. It's blatant ignorance for individuals to even come out and claim Adobe should set and end of life date for the product. Sure Flash has had some issues, and they came at the expense of FutureWave Software, Macromedia, and Adobe moving faster than anyone in the web industry at the time, with different goals, that just happen to now be of interest to web developers at large.
The reality is that web tech has just eaten into and provided standardized variants of features that Flash/Shockwave has had for over TWO decades. Yeah, real progressive of the web community. _Slow clap._
In the gaming arena, you can look at http://html5games.com/ or http://www.kongregate.com/html5-games or http://www.html5games.net/ or even just Google "HTML5 Games". Based on all of those HTML5 games it's clear that HTML5 can replace Flash in the gaming arena. There's only 1 place where HTML5 games and Flash games are really that different - on mobile devices (Flash doesn't work well if at all, HTML5 works like a charm).
As for animations, doing some simple Googling will bring up results that also show HTML5 can replace Flash: https://www.freshdesignweb.com/examples-html5-animation/
HTML5 doesn't replace Flash. It's certainly an alternative, like my engine is an alternative to LÖVE, but it doesn't replace it. This is akin to saying SDL replaces lwjgl, or Unity replaces UE4.
HTML5 without WebGL doesn't match the functionality offered by flash, even for just 2D content.
HTML5 with WebGL runs fairly poorly on a lot of machines, and not at all on many as well.
I'm not really sad to see flash go (though I truly hope there is a way to preserve it's content, and would be very sad to see that go), but HTML5 is a ways off from providing the feature set and reliability of Flash.
That's Flash's domain predominantly, and that's what it does best out of its feature set.
But I see your point and expect HTML5 to improve, but it is along way from being what a lot people think it is.
That would be because Chrome on iOS is not Chrome, it's a wrapper around a UIWebView with all the performance pitfalls that entails. Go try it in Safari on iOS or Chrome on Android if you want a proper performance comparison.
The world has just changed around Flash. The performance and security problems, which were an annoyance 7 years ago, are today seemingly fatal--not least because Adobe has spent 7 years trying to fix them and failing.
At some point it seems like we should just throw up our hands and invoke the sunk cost fallacy.
Flash needs to go for the sake of our security, not to climb up to a bleeding edge. The security risks are way beyond unacceptable.
Perhaps you could argue that some similar functions in HTML5 have just as serious of threats but additionally lack an off switch??
As for accessing legacy content, treat Flash like Ebola and keep an old machine around for that? It would help if the old machine has no writable flash or drives (or at least includes a non-writable restore image if there's a drive).
If our machines have writable flash for the network adapter, video card, hard drive, bios, and a few other things, how secure can they be? Even our flash isn't safe from Flash.
But your main point is a very good one. There are way too many people in the industry right now complaining about those older technologies who think that the world somehow magically owes them updates to 10-20 years of past work, just because their bleeding edge browser-native tools have finally reached the point in the very recent past when they can do some of the same work to a useful degree.
There are also way too many people moaning about how these plug-ins are such horrendous security problems while ignoring the facts that (a) every major browser also has a less than stellar track record on security issues, with Firefox and Chrome patching numerous vulnerabilities in updates every few weeks, and (b) moving the more advanced, and often hardware-accelerated, functionality from plug-ins to native browser capabilities isn't really reducing the area of the attack surface, it's just reshaping it. Given these facts, there is little reason to assume that browsers will inherently be more secure just because plug-ins were forced out in favour of native technologies. As others have been pointing out today, the reverse might actually be true, because at least the plug-ins have a degree of isolation and click-to-play safeguards are now widespread, while the trend with browsers (again, particularly Firefox and Chrome) is to remove obvious settings that would allow users to turn off certain functions.
By adding HTML5 video and now its DRM-related infrastructure, WebGL, and other features that developers used to use Flash/Java for, you are also increasing the attack surface of the browser "package" as a whole. The comparison is a perfectly reasonable one.
Unless more than one browser uses, say, the same video codecs, or the same third-party DRM-related module, or the same system services for doing hardware-accelerated 3D rendering.
There may be some marginal advantage to having different implementations in different browsers, but marginal is probably all it is. Realistically, as things we used to do in the likes of Flash or Java move into browser-native implementations, there is still no reason to assume that the people writing those implementations will magically produce completely secure implementations where no-one ever has before.
Stick it in our history books as an example of what happens when you tie yourself to a proprietary platform?
I'll miss some of the content to be sure, but ultimately the security of hundreds of millions of users trumps nostalgia and old Flash games from the 90s.
If there's a good way to preserve the content in some way, I'm all for it, but justifying the continued use of Flash purely on the grounds of historical content is IMO pretty weak.
Side note: a lot of the old Flash animations have been "ported" to YouTube, the non-interactive stuff at least. Heck, the YouTube versions show up before the real Flash versions sometimes...
Ultimately it comes down to this: keeping a notoriously insecure runtime around in active use, by hundreds of millions of people, is a non-starter. Unlike, say, Java applets, the frequency and severity of security holes found in Flash is just ridiculous. After years of allegedly focusing on cleaning up Flash, serious exploits are still being discovered regularly.
The strongest argument in favor of keeping Flash around is IMO the fact that there is important functionality provided by Flash that has not been effectively (or at all) replicated by HTML. The weakest argument is IMO any centered around historical preservation.
Personally, even considering the strongest argument, keeping an insecure runtime running on hundreds of millions of machines vs. better in-browser games... The choice seems pretty clear.
But right now we're not moving towards deprecation, Flash is not officially stated by Adobe (nor anyone else of any authority) to be a deprecated technology, and new work is being created for it still (with the encouragement of Adobe, even).
Deprecation at the community level will also require us to define replacements and expand the current limitations of HTML5 so that functionality lost with Flash can at least in some way be recovered.
That being said, my ideal solution here is a bit harsher than yours. Like you, I hope all browsers immediately stop executing Flash code without explicit user permission on a per-SWF basis, and I want them to unbundle Flash. The only people who should be running Flash are the ones who have chosen explicitly to put it on their machine.
In any case, my original post was in response to the notion that Flash should be kept alive because of all the old games/animations that have already been created for it - that is IMO a pretty bogus argument for keeping around something so infamously insecure. Flash needs to be deprecated.
Not to mention from a preservation of history perspective deprecation of Flash is not harmful. You can run an old copy of Windows in a VM with an old copy of a browser with an old copy of Flash (and not have any back compat issues, sweet). I do not believe it should be a priority to preserve everyone's ability to view old Flash content without any prior setup at the drop of a hat. If you want to rewind to the mid-00s it's easy enough to get something like this set up - certainly easier than buying your own 35mm projector or microfilm machine like other archival formats.
Actually, the really annoying stuff isn't Flash, it's Shockwave. The format's not been reverse-engineered, and it's hard-to-impossible to find a working plugin for it that seems to play some of those old Shockwave games.
If Apple kills iOS in a decade what happens to all those apps? They're not sentimental.
This isn't about emotional blackmail. And heck, I'm not the person who made any of those things. I'm just the person who remembers them fondly and still wants to have them around. The difficulty of preserving digital works is bad enough without callous disregard for the task.
Also, consider that the next couple billion people to come online will be mobile only. Why create content that they can't use?
In multiple posts, I've said deprecate it. No new Flash content. No reason to create more content that is encumbered by Flash's legacy status. (Although others here have pointed out that HTML5 is not quite as capable of replacing Flash as some think.) But why the huge rush to completely abolish the Flash content that already exists?
Removing flash entirely has the added benefit of forcing the best content onto modern mediums. Depreciating it doesn't fix the security problems associated with it, it just extends them indefinitely.
Just like Commodore 64, Apple IIe, the original PlayStation, NES, XBox, and a slew of other platforms made obsolete by something called "progress".
I'm pretty comfortable calling these things irrelevant.
It's time for flash to die.
http://www.colorado.edu/geography/foote/geog4043/notes/flash...
http://www.colorado.edu/geography/foote/geog4043/notes/flash...
Flash for desktop browsers, apps for mobile devices, even Adobe agrees on that. And if you just have a simple website, make it in HTML5 (Adobe also agrees on that)
People confuse website content (which should be built on HTML5, I agree) with rich 'clients' such as games. If you want to build games for the web, good luck with HTML5.
But more importantly, we should decouple the idea of Flash the authoring tool and Flash the runtime. I believe Flash the authoring tool already allows you to output to HTML 5 rather than an SWF file. So you can have all the benefits of flash authoring, without the drawbacks (killing your customer's batteries).
Then there's Shumway (Mozilla's JS based flash runtime).
There are already lots of alternatives to the nasty Flash runtime.
How true is the battery thing today, really?
Objectively, on my relatively powerful workstation PC, watching Flash videos using Flash widgets on web sites doesn't tend to bump either CPU or GPU frequencies up noticeably.
In contrast, watching HTML5 video can cause either or both to go way up, with consequent extra power consumption, temperature rises, fan noise, etc. And all these trendy modern animations and canvas/SVG effects in browsers that are replacing some of what Flash used to be used for apparently require more effort from that workstation-class hardware than literally doing full-screen real-time 3D rendering in a graphics application.
Of course it's possible that this is just dodgy graphics drivers -- I do have an extremely low opinion of AMD's supposedly premium products since I've actually used some of them -- but those same dodgy drivers are there when using Flash too, and it can still play videos without raising the ambient room temperate by multiple degrees.
It isn't a Flash Professional clone though; we've made a lot of decisions based on the newer medium and newer ideas.
The irony of it is - I'm not sure 5 animated WebGL banners would keep his laptop any cooler...
That's not a good sign.
BTW I'm on a Mac viewing your (66k polygons) example in Chrome - and my fans started spinning almost a few seconds after opening your link. Five of those running in parallel and my laptop would probably explode.
GPU seems to be going crazy - http://i.imgur.com/t4qC0LJ.png
for example, it's much more efficient to let the browser (Safari) play html5 video and hardware decode it than the same video through flash.
it's also much easier to control things when it's not in a black box such as flash, browsers let you disable or whitelist things like JS, WebGL, etc.
To a developer Flash is not a black box - to a user, again - it seems that that technology gets a lot of blame for what developers are doing with it. If you have 5 animated banners hogging your CPU/GPU, whether in WebGL or Flash - who is to blame?
The blackbox comment is referring to it not being part of the DOM.
Of course the content of a plugin is not a part of the DOM - however you're not calling MP4 videos or webfonts "blackboxes" for not being able to read their source code from the web inspector either...
Playing SD quality video in HTML5 in Safari; minimal CPU usage, 7 hours battery life (on a 2012 MBA). Playing SD quality video in Flash in Safari; heavy CPU usage, audible fan noise, 2 hour battery life.
In a past life I did some Flash development; the Windows player was generally a little better (with the Mac one being in between and the Linux one being _horrendously_ inefficient), but it was still far from _good_.
Whitelisted/Click-to-play flash works relatively well.
I think the file format itself is quite nice (it's much more compact than SVG, for example) - the real problem is with the interpreter's implementation...
please point to me a remote code execution exploit from any browsers that have been fixed in 48h or less, I dare you.
> Publish Date : 2015-07-05
> Last Update Date : 2015-07-07
Admittedly, most CVEs tend to take longer, but there's your counterexample.
Isn't there also a possibility for the browsers to sandbox the plugins enough to keep them safe?
Seriously, there was no better/easier way to visit a site, download an app, and have it push out updates. It was beautiful.
No other cross platform solution comes close to AIR in that regard.
The real problem will be the Flash games and applications that try and call home to domains that no longer exist.
https://helpx.adobe.com/flash-player/kb/archived-flash-playe...
In the later versions it was renamed to "projector" but you can still tell them apart from the "_sa" in the filename.
Also Flash nowadays also compiles to native code and is used by many mobile games, even on iOS.
And DRM video of course.
That's a worst-case scenario, but I get the "enable Flash bar" all too often - even when the website automatically upgrades to HTML5 instead. Even YouTube tries Flash first.
Flash should be a fallback plan, not the first preference. Stop it. Please. I'm growing weary of ignoring that bar, it's like it's actually part of the browser chrome.
Apparently it's not dead enough, HTML5 didn't grow enough in those last 5 years to kill it, so what ppl are asking now ? "oh please Adobe kill it yourself"
and why ?
oh because this remote code execution flaw is unacceptable, humm OK, so following this logic we should kill any technology that get the same flaw right ?
How about killing Firefox ? Chrome ? Windows ? etc.
I mean that's what we are talking about here right, preserve ppl from security flaw by killing bad technology that constantly have flaw, well ... why stop at Flash only ?
ouh it took Adobe 48h to fix a security flaw, if your platform take more than 48h to fix the same kind of security risk it should be killed too, and there we look into the details and oh surprise, how long does it take Mozilla to fix a remote code execution ?
at least few weeks, well that's it we should all ask Mozilla to kill Firefox too.
Let's review the others now, Google with Chrome, Microsoft with Windows, etc. I mean really we have the great opportunity here to ask every single big software vendors who ever had some security flaw in their software to just kill them because duh it's just keep happening and it is unacceptable.
No, no worries, don't even bother to fix them, just kill them.
Because everyone knows that only good secure software never have bugs or security flaws right, so let's do this logic thing let's kill all software that have flaws and only keep using those with no flaws.
Hahaha it is ridiculous, every single software out there have bugs, flaws, etc. and among all that yeah sure you have big security exploits waiting to be discovered, but the important thing to understand is that it does concern everyone.
If you say or think it is only Adobe with Flash you are lying to yourself big time.
But fair is fair, if you want to lash out on Flash, yeah be my guest but then do the same for every other tech out there because they are all guilty of the same problems.
Software can not be bug free, it's like that, accept it and live with it.
You will always have a bunch of people trying to find those bugs and exploit them, and as well you always have another bunch of people trying to fix those bugs.
But if your logic is just about "oh this piece of crap of software is ridden with bugs we should just kill it", then be ready to kill the next one, and the next one, and the next one, till there is no software anymore out there.
go here http://www.cvedetails.com/top-50-vendors.php and starts to ask all those companies to kill their products