5 ms·
It matters because including flash with chrome is an act of realism. If the user runs firefox, safari or another browser they're still going to be susceptible t
by trotsky 15y ago
It matters because including flash with chrome is an act of realism. If the user runs firefox, safari or another browser they're still going to be susceptible to the same bug - it simply won't be attributed to the browser because the user was the one that installed the plugin. By including the plugin by default they're solving a significantly larger problem than zero days, namely users that fail to update their plugins on a timely basis (or plugins that fail to provide a reasonable upgrade path). If the security world insisted on a technical interpretation (you shipped it so it's your bug) it would be effectively discouraging a process that is net security positive - and that's the reason a distinction is made. Note that even VUPEN - whose business of selling fully weaponized exploits makes them a natural enemy of better security - tacitly admits the difference by refusing to admit the use of a flash bug. If they really considered it a non-issue they'd be freely admitting what they're exploiting. The difference? High security chrome installations often in use by the kind of targets their government customers have will frequently have flash disabled or set to click to play.
- gcp 15y agoIt's been made clear that not bundling Flash is a sustainable act, if you have the guts to do it. Apple had. Google doesn't. If Google took a firmer stance there, Flash would be dead faster.
- cheald 15y agoI think it's utterly ridiculous to take the stance that Flash is moving towards dead on desktop devices. Flash is effectively dead on mobile, and that primarily for battery reasons. Flash is still very much a big part of the desktop web, and will be for the foreseeable future.
- cheatercheater 15y agoi have flashblock on. the only time i notice it's on is when... oh wait, I don't notice it being on at all anymore. For me, flash does not exist.
- ja27 15y agoFlashblock still loads the plugin and content, doesn't it? I don't run Flashblock, but does this still work: http://hackademix.net/2008/06/08/block-rick/ http://hackademix.net/2008/06/08/block-rick/ I disable plugins in Chrome and either whitelist sites or run them as-needed.
- eftpotrm 15y agoWhat for, though? I'm another Flashblock user and it seems to lose me ads and videos. The ads don't benefit me anyway, the videos are now capable of being deployed by other means; it's just the vendors haven't yet caught up. Flash is on life support, and I don't see a way back for it.
- gduffy 15y agoLive streaming. Especially low (well, lower than HLS for example) latency streaming.
- cheald 15y agoAudio is a big one. The HTML5 audio APIs just haven't caught up yet. Live video, as mentioned elsewhere, is big as well. The vast majority of web games are still Flash, as well. Even video delivery is more robust with flash than with HTML5 - ever tried doing a preroll on an HTML5 <video> tag? Notice that it basically...doesn't work? Flash is certainly has less of a monopoly on "interactive web content" than it once did, but it still fills an extremely important and currently unreplacable role on the web. To be ringing its death toll just yet is premature.
- wahnfrieden 15y agoIndeed, the audio tag is basically entirely broken and unusable in a general sense... Most comical is android supporting the tag but not any audio decoding codecs.
- antihero 15y agoAnd it definitely should not be until they sort their security and stop pissing around with Linux. Flash is proprietary, crashy, bullshit that can't die sooner. The only advantage it has for video is pretty neat streaming support that could most likely be solved in other ways, and being able to place adverts over the damn video.
- cheald 15y agoNobody will deny that it's full of security holes, a resource hog, and woefully undersupported on Linux. But I also think it's pissing into the wind to claim that we have equivalent solutions and it's just a matter of waiting for Flash to die now. We're making progress in that direction, but it's going to be years before there's a significant dent made.
- Skrekkpus 15y agoAlthough it is true there are security problems, it is silly to think that is something unique for flash. WebGl is probably the most insecure plugin right now, largely because there is no one company responsible for upgrading it. Although there are problems with flash, Adobe seem to have high priority on patching it. canvas/webGl/SVG can't deliver yet.
- ootachi 15y agoGoogle could run Flash in a VM. Or they could re-implement it (as Mozilla is doing). Or they could buy it from Adobe (they're Google). Or they could pay Adobe to write a version that uses the sandbox. Or they could just stop shipping it. They aren't fooling anyone. It's Google's problem.
- trotsky 15y agoGoogle could run Flash in a VM. Or they could re-implement it (as Mozilla is doing). [...] Or they could pay Adobe to write a version that uses the sandbox. Isn't the nacl+pepper flash rewrite effectively the result of doing a bit of all three?
- jaredsohn 15y ago> Or they could re-implement it (as Mozilla is doing) Link? I haven't heard anything about this.
- ghshephard 15y agoShipping flash is a net security positive? I'd suggest that removing flash would be a net security positive. Flash will be gone from mobile within a year, and gone from the desktop within two-three years, so anything the vendors can do to expedite this process will be appreciated by the community at large and make us all more secure.
- deleted 15y ago[deleted]
- csulok 15y agoremoving flash would be better, but right now it's not an option. mobile web is very very new and it was built without flash, the desktop version is not so much. not even google can fully and immediately drop flash