4 ms·
Ah, so this is why Facebook tries to load Flash on almost every page... Allows them to gather data like this. Always wondered why Flash was "needed". (another
by reedloden 12y ago
Ah, so this is why Facebook tries to load Flash on almost every page... Allows them to gather data like this. Always wondered why Flash was "needed".
(another reason to put Flash behind click-to-play and/or push for HTML5 video)
- mkjones 12y agoI suspect flash is generally used to play sounds from chat messages - the https man-in-the-middle detection is heavily sampled, as referenced in https://www.linshunghuang.com/papers/mitm.pdf https://www.linshunghuang.com/papers/mitm.pdf. [I work at FB, but not on sounds or directly on https man-in-the-middle detection.]
- hobarrera 12y agoNope, without flash you still get the chat sound messages. I've no flash on my system and the only thing that's different on facebook is that I can't watch user-uploaded videos. Only their mobile site supports HTML5 last I checked.
- mbel 12y agoIt is still possible that they use flash as default audio source and fallback to HTML audio if flash is unavailable. Although of course it would be better if they could get rid of the flash altogether.
- eli 12y agoI don't follow why this upsets you. Seems like an argument for why allowing flash to run can be used for good?
- timothya 12y agoSide note: click-to-play is a usability feature, not a security feature. It's still possible for Flash code to run before the user "clicks to play".
- timothya 12y agoSince people are disagreeing with my comment, I'll add some extra information (apparently I missed the editing time window, but I stand by my original comment). I should note though that I was talking about Chrome (I don't know what the deal is with Firefox). If you go through the Chrome bug tracker, you can find several instances where Chrome engineers point out that Click-to-Play is not meant to be a security feature, and that the "Block all" setting is what is actually secure. There are several bugs which demonstrate ways around Click-to-Play which are closed as "WontFix". A quick search yields the following quotes from Chrome engineers: "Yes, this is why click-to-play is designed as a convenience and not a security feature. If you want plugins blocked in a way that cannot be click-jacked, use "Block all," which requires a protected browser interaction (context menu, page action, etc)." [0] "The "Click to play" setting is not a security measure. If you want to securely block plugins you must use the "Block all" option, which is a bit less convenient than "Click to play," but provides a click-jack resistant, browser mediated interface." [1] "I'm kicking this out of the security queue because it isn't a security mechanism ... The secure method of blocking plugins is to select "Block all" and right-click to run. Whereas the "Click to play" feature is for convenience and performance." [2] "It's not a security feature..." [3] [0]: https://code.google.com/p/chromium/issues/detail?id=176724 https://code.google.com/p/chromium/issues/detail?id=176724 [1]: https://code.google.com/p/chromium/issues/detail?id=225636 https://code.google.com/p/chromium/issues/detail?id=225636 [2]: https://code.google.com/p/chromium/issues/detail?id=160707 https://code.google.com/p/chromium/issues/detail?id=160707 [3]: https://code.google.com/p/chromium/issues/detail?id=414232 https://code.google.com/p/chromium/issues/detail?id=414232 I'm sure there are other instances where they talk about it more, these are just the first results I found.
- rnnr 12y agoIn recent chrome builds, they changed the behavior to right-click->Run Plugin which to my knowledge makes it immune to these attacks.
- mintplant 12y agoEr, are you sure about that? That doesn't appear to be the case with Firefox.