4 ms·
Love this - All Java plug-ins are defaulted to 'click to play' I tried convincing my coworkers to disable java and failed (we are not developers).
by prteja11 13y ago
Love this - All Java plug-ins are defaulted to 'click to play'
I tried convincing my coworkers to disable java and failed (we are not developers).
- csmuk 13y agoThis is great news! It means I can actually have a full java plugin installation and just activate the applets I know are safe! I can have my java and eat it, but people can't make it eat me :)
- a1a 13y agoI do not think this is a good solution. This is once again just smashing another security trade-off in the face of the end-user. Once the user is responsible they can be blamed and the browser is considered secure with stupid users. If the developers at mozilla can't verify the security of the applet, how on earth would my grandmother be able to? Note: This is not an attack against mozilla in particular, almost all vendors does this (e.g. "antivirus: wanna allow suspicious file?" or "browser: invalid certificate". These questions are asked as if everyone is a computer scientist. We developers need to start formulating these questions so they can be answered by a normal person. Note 2: I guess it's better than doing nothing at all, since it might stop some drive-by attacks.
- prteja11 13y agoI think this feature will protect users on websites where java applets load inconspicuously. With this feature user wouldn't click on the blocked plugin/applet because they don't have a use for it. This is not the solution that will end all our problems but hey this is one step closer and I'll take that!
- revasm 13y agoThe main security benefit of click-to-play plugin schemes is not to question the user about the security of an object, which is unknown in most cases anyway, but to prevent accidental drive-by loading and other annoying (and risky) usage. Clicking an overlay to run a plugin should be as natural as clicking on a video to begin playback.
- pwnna 13y agoYes. Drive-by is big deal imo.
- zobzu 13y agoits actually pretty good since drive by are the most common attacks. grandma won't click the button if she doesn't care about the content
- hcarvalhoalves 13y ago... and this breaks a bunch of banking sites that use hidden applets.
- kps 13y agoAny such site was already broken. This change at most makes that apparent to a few more people.
- tom9729 13y agoLooks like a notification[1] is shown. I assume "Allow" will whitelist the site. Of course this doesn't help if a trusted site is compromised, but I think C2P is better than nothing. [1] http://www.extremetech.com/wp-content/uploads/2013/12/firefox-26-click-to-play.jpg http://www.extremetech.com/wp-content/uploads/2013/12/firefo...