3 ms·
> we can confidently avoid all the security pitfalls that Flash had a reputation for There wasn't only memory issues. Flash was also vulnerable to clickjacking
by hackideiomat 3y ago
> we can confidently avoid all the security pitfalls that Flash had a reputation for
There wasn't only memory issues. Flash was also vulnerable to clickjacking for instance.
Also, if you do not break the browsers resitrictions, flash is not feature complete (e.g., make cross origin requests and read responses).
But if you do support it, you also have the security implications.
- nine_k 3y agoAt least this can be done responsibly. Ruffle might ask the user, and let the user deny such requests, allow them once, or allow for a particular combination of domains, and blindly everywhere like Flash would do.