10 ms·
Mark from Mozilla here. To be clear, by "blocked" Flash we really mean enforced click-to-activate. User choice is always a #1 priority at Mozilla. We regularl
by marksc 11y ago
Mark from Mozilla here.
To be clear, by "blocked" Flash we really mean enforced click-to-activate. User choice is always a #1 priority at Mozilla.
We regularly block vulnerable plugins. What made this block different was that we did it before Adobe made an update available. Now that Adobe has released an update, it is no longer true that every version of Flash Player is blocked in Firefox.
However, we're glad to see the conversation this has sparked. Personally I align with Alex Stamos regarding Flash, in the thinking that a formal EOL would be great.
I'd also like to use this space to make a shameless plug for Shumway, a project set on building a faithful an efficient renderer for the SWF file format without native code assistance. Ending Flash doesn't need to mean an end for Flash media. http://www.areweflashyet.com/shumway/ http://www.areweflashyet.com/shumway/
Edit: typo
- farawayea 11y agoThis is great. Let's continue: remove pocket, remove hello
- hartator 11y agoI wouldn't mind these two as assumed business decisions. But please stop the hypocrisy. It's just hurting Mozilla image without fooling anyone.
- glogla 11y agoHello is just few (hundred?) lines of Javascript giving UI to WebRTC. Unless you want to remove WebRTC and that's just stupid.
- ultramancool 11y agoRemoving registration on Hello servers and WebRTC altogether is not stupid if you give a shit about your privacy, look at the leaks WebRTC provides, local IPs which are great for fingerprinting, real IPs from behind VPN, etc. It's one big gaping privacy nightmare so far, so it's pretty reasonable to have it disabled, until this gets sorted out at least. Fortunately it can be toggled off in about:config easily. Set loop.enabled = false to disable hello, set media.peerconnection.enabled = false to disable WebRTC. If you don't want pocket, set browser.pocket.enabled = false. You can even make yourself one big user.js file to fix the bad ideas that have been added to Firefox lately. Mozilla still has a good thing going for them, and that is user choice. However stupid the defaults get.
- mhurron 11y agoIt is getting annoying to have to go into about:config with every release to turn things I don't want off. Off should be default. Let those that want to use these features turn them on if they want. Or better yet, ship a damn extension.
- ultramancool 11y agoIt's a real pain, but they want the less sophisticated users to be able to take advantage of all the latest stuff and if Chrome or IE is shipping with it enabled, they have to compete. Well, that explains WebRTC at least. As for the other stuff... I'm a Pocket user, but I have no idea why that needed to be integrated into the browser, seems like an insane decision to me. I hope they got a good pay day out of that. Same as the history based advertising tiles. Sure, it's checked locally, it still seems creepy and annoying... but again, browser.newtabpage.enhanced = false. Unless we lose this level of user choice, I don't see a better alternative. It would be nice if someone would ship some tool to automatically update a user.js file, however, I think many of us have different opinions about what feature we do and do not want enabled in our browsers.
- mhurron 11y agoOff by default lets everyone choose to turn it on if they're interested. It also might clue in Mozillas devs that if they want people to turn it on, a setting in about:config isn't the only place you should be putting the button. Off by default is neither removing user choice, nor is it preventing Mozilla from saying they ship with feature X. It is the right way to present it.
- ultramancool 11y ago> Off by default lets everyone choose to turn it on if they're interested. It lets more sophisticated users choose. Less sophisticated users however will more likely switch to a different browser the moment a site doesn't work before poking through settings. I think a better way than a separate setting would be to go in the direction of many software firewalls and present it to the user as a choice when an application requests it as many browsers currently do with the location APIs. This would provide individual domain-level control over what permissions sites are granted by you. I don't know why this sort of policy seems to be restricted only to the location APIs...
- Raphmedia 11y agoIt's third party features that I will never use.
- deleted 11y ago[deleted]
- baby 11y agoOh please don't remove pocket, this is one of the awesome feature of Firefox along with Tree Style Tab (and if it was just me I would add Tree Style Tab by default as well) (And of course I go against the public opinion here on HN, but I wonder how many people did actually use Pocket before trashing it?)
- chris-at 11y agoPocket had an add-on that was working just fine. The old one even needed less space than the new button and didn't require a cookie. I'd reinstall the old one but "This add-on has been removed by its author".
- baby 11y agoIt's debatable but I think something like pocket is fundamental to a 2015 browser experience. The bookmarking system has been bad since its beginnings.
- techwizrd 11y agoJust out of curiosity, how will removing Pocket integration and Hello (a thin UI over WebRTC) personally? Both are lazy-loaded, so the only bloat they add is "visual bloat". This behavior is seriously disappointing from the Firefox community. I've been using Pocket since it was Read It Later and I was pleased to see it integrated into the browser. Mozilla is working on a Reader mode[0] but it does not seem to be ready for public consumption yet (despite landing in 2012). Most people don't even know it exists, and it obviously does not save it for later (unless you bookmark it). The implementation is open-source (MPL license), although Pocket itself is proprietary. Hotword detection is not absolutely necessary for browser functionality, yet I hear no chorus of complaints from Chrome users. Should Mozilla be prohibited from partnering with proprietary third-parties whether or not it benefits their users? Hello is even less of an argument. Firefox Hello is a simple Javascript UI for the existing WebRTC spec supported by Firefox, Chrome, and Opera[1]. It allows people to communicate without having to set up accounts, sign-in somewhere, and works against the platform lock-in of proprietary services such as Facetime, Hangouts, and Skype. If it's disabled by default, the service becomes useless. My parents shouldn't have to enable it about:config for me to talk to them, nor should they have to download another plugin to use a technology built-in to the browser. I understand the security implications[2] in IP leakage[3], but I don't see a simple fix that doesn't neuter the functionality (although this comes close[4]). W3C has stated their position on fingerprinting[5], but at least Mozilla is actively working on the issue. 0: http://www.ghacks.net/2015/02/07/mozilla-starts-to-push-reader-mode-to-desktop-firefox/ http://www.ghacks.net/2015/02/07/mozilla-starts-to-push-read... 1: https://support.mozilla.org/en-US/kb/which-browsers-will-work-firefox-hello-video-chat https://support.mozilla.org/en-US/kb/which-browsers-will-wor... 2: https://twitter.com/incloud/status/619624021123010560 https://twitter.com/incloud/status/619624021123010560 3: https://bugzilla.mozilla.org/show_bug.cgi?id=959893 https://bugzilla.mozilla.org/show_bug.cgi?id=959893 4: https://addons.mozilla.org/en-US/firefox/addon/statutory/ https://addons.mozilla.org/en-US/firefox/addon/statutory/ 5: https://github.com/w3ctag/spec-reviews/blob/master/2015/05/fingerprint.md https://github.com/w3ctag/spec-reviews/blob/master/2015/05/f...
- urda 11y ago1) Open the menu 2) Click "Customize" 3) Drag pocket and / or hello from the tool bar into "Additional tools and features" 4) Take a breather, phew that wasn't too hard was it? https://support.mozilla.org/en-US/kb/customize-firefox-controls-buttons-and-toolbars https://support.mozilla.org/en-US/kb/customize-firefox-contr...
- makomk 11y agoFor some reason, I keep having to do that - it doesn't stick. And every version brings more unwanted toolbar buttons I need to remove. I'm seriously considering looking into building a version of Firefox with them patched out altogether.
- lamby 11y agoRebutting a claim that the default options are poor by providing instructions to change those settings seems, at best, a non-sequitur.
- stevenh 11y agoThese need to be disabled by default, and the steps you list should be taken by people who want to enable them. If a masochistic user wants to navigate the labyrinth of dark patterns meant to confuse them into not understanding that the "Additional tools and features" category is also the "completely disabled features that run nothing in the background" category (why would anyone think that, ever?), then they can go ahead and do it. If these things are so great, then I'm sure users would be happy to put that extra work into enabling them. After all, it's 3 simple intuitive steps!
- Excavator 11y agoDon't even need all that. Just, right-click the icon and click "Remove from Toolbar/Menu".
- justizin 11y agoI noticed this behavior when I fired up an older Mac I hadn't used in a year or so, it was refreshing that Flash always required click-to-activate, and I made this the setting on all my machines a while back and started suggesting to my friends to. Some websites' video don't work as well, they have JS or CSS that interfere, or assume that you don't have flash installed, or retaliate as if you are an ad blocker, so I'm glad to see this is becoming more widespread, those problems may be fixed.
- exodust 11y agoWhen is the formal EOL for Firefox? It's my primary browser, but some people hate it, so just thought I'd ask when the EOL for Firefox is? Flash is never blocked for me in Firefox and never will be. Because a few months back I did this: 1. about:config 2. extensions.blocklist.enabled - 'false' Job done. No more Mozilla annoyances between me and the content I wish to access. And yes, it was an annoyance because the link to "check for updates" in your message would not get me anywhere. That was a flaw in your strategy that I now suspect was deliberate. I really can't respect engineered annoyances that align with agendas rather than good UX. I like Flash when it's done well. Raw performance and efficiency is one of the things I like about it. The powerful multimedia handling of everything from audio to video cannot be matched by HTML5. I'm an HTML/CSS/JS dev for my living for 20 years, that's how I know this to be true. HTML5 video is cute. But it doesn't cut the mustard in all circumstances. 360 video, VR, and many other things will come along that are too much for web technologies to handle. Flash serves a useful purpose in allowing websites to cater to the most demanding cutting edge tech and content without needing the Firefoxes and Chromes of the world to keep up. "closed source"; "battery drain"; "plugins are just bad".... oh cry me a river. My comment has reached EOL.
- nightpool 11y agoHoly shit. Flash has over 34 CVEs in one week—and only because a prominent organization that was sitting on a bunch of them got hacked—and you call mozilla taking steps to protect the security and integrity of their customers an "engineered annoyance"? Grow up.
- exodust 11y agoI am older than you probably, I am over 40. Holy shit, it's like you're throwing nappies at me and telling me I should wear them immediately. I don't want or need a nappy. Holy shit, look at this: http://www.cvedetails.com/cve/CVE-2011-3660/ http://www.cvedetails.com/cve/CVE-2011-3660/ "There is total information disclosure, resulting in all system files being revealed." OMG it's from 2011, and those poor people from 2011 with Firefox installed. Listen. I am not worried about your CVE's. Got it? Don't push your paranoid, unsubstantiated crap into my reading. If I'm vulnerable, where's the stories of "person with Firefox and Flash gets owned" stories? Link me one, just one. If you want security, if you want privacy. Close you damn Facebook account (if you can). Good luck. nightpool..... some advice: uninstall your virus protection program for one year. Let us know how you go in a year. (hint, you'll be fine). Hack me.
- tgb 11y agoFor what it's worth, the shumway racing AS3 demo appeared to work but froze all input like closing or switching tabs for me and I had to kill it with task manager. Windows 8.1, Firefox 39.0.
- amyjess 11y ago> To be clear, by "blocked" Flash we really mean enforced click-to-activate For the record, I'm more than fine with that. In fact, I've used extensions to get that effect for years.
- agumonkey 11y agoWhat made Flash so fast ? was it direct unsafe access to the metal or was there some black magic in their code ?
- throwaway2048 11y agoactionscript (the flash programming language) is pretty much the same as javascript, the main reason why flash is often a lot faster than html+js things in a browser is it is not constrained to a slow, broken DOM for building uis.
- agumonkey 11y agoI know but I would be very surprised if the DOM model was <postedit>entirely</postedit> responsible for the performance hit.
- throwaway2048 11y agoit is by far the largest preformance drain in pretty much any dynamic website.
- agumonkey 11y agoSo retrofitting arbitrary layouts onto a ~text document specific one is that much an error. In hindsight I find it fantastic how web pages became the basis infrastructure of all this UX reinvention.
- samch 11y agoI think the answer is probably Tamarin[1] which started life as Flash's ActionScript engine and has since been donated to Mozilla. The Flash Player has also had direct GPU support for graphics and video for many years. [1] https://en.wikipedia.org/wiki/Tamarin_%28software%29 https://en.wikipedia.org/wiki/Tamarin_%28software%29
- spyder 11y agoOne notable difference is that ActionScript 3 is a strongly typed language, which can help with performance.
- mangeletti 11y agoHi Mark, Do you have any interest an organizing an effort, along with Facebook's Alex Stamos and other folks, to plan a formal EOL for Flash? Of course, the steps Mozilla and others have taken help, but perhaps a more organized movement could get other thought and market leaders on board, trigger higher rates of HTML5 adoption and foster the bits of remaining innovation that are needed to fully replace Flash on the web. Also, does Firefox plan to address the concerns brought up about Hello, and, more importantly, Pocket?
- deleted 11y ago[deleted]
- brighteyes 11y agoThey have already said that after the feedback they will make pocket into an addon (installed by default but easily removable like any addon).
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- aroch 11y ago> The choice is to install it by default and make users opt-out, giving the uninformed users' data to Pocket (and thus their "partners")? Except no data is sent to Pocket unless you actually opt-in to the service by signing up. Unless you login to Pocket the plugin and all its communication code is inactive... It is fine ti not like the integration but spreading FUD is annoying
- Manishearth 11y agoData doesn't go to pocket until you start using it, and even then, you have to click through a few pages to get there. Pages which make it abundantly obvious that its a third party service. Mozilla did user testing before integration and found that people do want it. Remember that techies complaining on HN doesn't mean that the majority doesn't like it. It's not different from the privacy implications of having Google/Yahoo as a default search provider. It's a nice feature that (very visibly) uses a third party service instead of being part of Firefox Accounts.
- yarrel 11y agoCan you call for a formal EOL on HTML5 DRM as well, please?
- JoshTriplett 11y agoAs much as I'd like to see this, Mozilla doesn't have the necessary clout to do this when other browsers are adopting it.
- grumblestumble 11y agoThe web has become an application delivery platform, like it or not. While there are arguments against forcing DRM on consumers, for video production workflows and project management, DRM is a necessity. I'm assuming you've worked with private Github repos with access control, right? Same idea.
- Karunamon 11y agoA political necessity, certainly not a technical one. The default state of content is open, restricting it should be seen for the positive (read: affirmatively taken) action that it is.
- pflanze 11y agoHow are private Github repositories using the same idea? Normal access controls are just implemented at the data source, limiting read (or write) there. DRM is implemented in the hardware of the user so that some programs that the user uses can access the data, but not those programs fully under control of the user. If you can access a Github repository then you can do so with software fully under your control (and hence make copies of the data as you wish). Did I miss something?
- grumblestumble 11y agoOkay, so maybe not the best analogy. Contact access expiration via git is far more primitive, sure - if you have access today you can clone a private project and have a snapshot of it in that state, once your access rights are revoked you just won't see any further work. Unfortunately, this 'freedom' leads to far more problems than it solves - horrible corporate bureaucracies around where you may or may not check code out to, remote wipe capability, contractor laptops, etc. There are many real-world use cases where, in order to accomplish the completion of a project, you need to provide an external resource with access to sensitive data for a limited amount of time. Think manufacturing, commercial video production, medical data, game development - pretty much anything where you outsource a specific phase of product development to a third party. Without DRM, these workflows are limited to online-only, where assets are streamed and can't be stored locally. This is a dealbreaker when, for example, you need to send part specs to a manufacturer in the middle of China.
- natch 11y agoThe web page explains: "To prevent these add-ons from running, click Restart Firefox." Why doesn't the dialog box have that same explanation? Did you (mozilla) think the two button options "Restart Later" and "Restart Firefox" won't confuse people?
- rorykoehler 11y agoFWIW This is how I have all my browsers setup anyways. Autoplay ruined my web experience so I turn off all plugins and white list as necessary.
- jordigh 11y agoIs Shumway a possible replacement for Scratch 2's flash implementation? They seem to think that there are some flash things that just can't be done without flash: Unimplementable Features on iOS: Image effects for whirl, fisheye, mosaic, and pixelate. Sound and video input for loudness, video motion, and touching colors from the video. https://github.com/LLK/scratch-html5 https://github.com/LLK/scratch-html5 I really like Scratch, but it's a pity that it's implemented on a platform so many people think should no longer exist.
- pcwalton 11y agoYou should be able to implement those effects with either simd.js or a WebGL shader, no? (Assuming you can get the pixel data; but getting the pixel data from HTML content is actually a security nightmare…)
- drzaiusapelord 11y agoI was advocating for this yesterday in /r/sysadmin and this morning it was a pleasant surprise to hear that this actually happened. I imagine you're getting all sorts of complaints from advertisers and others, but its the right move. The web is simply dangerous and having an unaccountable closed source binary happily running anything served to it is just crazy. I'd love it if you kept it like this and implemented a flash whitelist function. Flash needs to be treated like Java: its legacy tech that should be used only via whitelisting. Google is too embedded into the marketing and advertising world to ever consider doing this in Chrome. Its really up to you guys, per usual, to save the web.
- digi_owl 11y agoOne slightly annoying thing i found right now is that if i have a plugin set as disabled in about:addons, it will not show up on the update checker found in the top link.
- cpeterso 11y agoThe (unprivileged) Plugin Check website can't detect disabled plugins because they don't show up in navigator.plugins. Ideally, Plugin Check should be an automatic check built into Firefox. The advantage of the Plugin Check website is that it works in any browser.
- acdha 11y agoCouldn't you preserve the nice trait of working in any browser by having the browser load it with a hash-fragment containing a list of disabled plugins to add to navigator.plugins?
- digi_owl 11y ago> The advantage of the Plugin Check website is that it works in any browser. < Do that carry any value these days? Heck, it seems weird that Mozilla can push plugin warnings directly to the addons ui but can't indicate if a plugin can be upgraded.
- cpeterso 11y agoGood point, especially considering that Chrome no longer supports NPAPI plugins. :)
- deleted 11y ago[deleted]
- Retra 11y ago>Your product is superfluous and unnecessary; we already have alternatives like Chrome, Safari, and IE ...What does this mean? Why don't you consider Chrome, Safari, or IE superfluous and unnecessary instead?
- geofft 11y ago... alternatives like Google's closed-source Chrome, Apple's closed-source and behind-the-times Safari, and Internet Explorer??? Are you trolling? Are you attempting to discredit the anti-Firefox campaign by trying to say that running Internet Explorer is a reasonable alternative for your Macbook, and that a kernel panic from non-kernel software is somehow the software's fault, not the kernel's??
- arenaninja 11y agoI invoke Poe's Law. I'm not sure if you're being facetious or serious
- koonsolo 11y agoHi Mark, Technology should be replaced by better technology. To give you some background: I've written games for all kinds of platforms: PocketPC, Windows Mobile, (Desktop) Windows, Linux, OS X, Flash (AS3), HipTop, J2ME devices and some smaller proprietary devices. Some of those platforms offer write once, run everywhere. On other platforms every device has it's own quirks and you have to test on every device and implement workarounds. You might not like Flash, but it is great at running on every platform/browser with the same code base. If you test it on one platform, it runs on all others. (Adobe is also very good at keeping it backwards compatible) Now, I ask you, what's the alternative for Flash? Does HTML5 offer write once, runs the same on every platform/browser(version!)? No it doesn't, and it never will. Even simple HTML pages are full of browser checking hacks. Now, if you can offer a programming platform where the games I develop on, run exactly the same on every browser, on every platform, I have no problem killing Flash. But let's be honest here, only plugins can guarantee such a thing. As to Alex Stamos, the top games on Facebook are all Flash. You know why? Because developers don't have to worry whether or not those games will run inside the users browser. Because once Flash is installed, they will run without issues. HTML5? No such guarantee. So before you declare EOL, please have a proper alternative, where I don't have to pull my hair and cry all night because browser X on platform Y version Z seems to break the end boss of level 5 in my game because its implementation slightly differs from all the rest.
- brighteyes 11y agoWhile I do understand where you are coming from - it can be more convenient to target a single implementation - the fact is that Flash has not been what you describe, for a while now. Flash officially announced it would no longer support Linux, and Flash is not usable in most mobile browsers either, for example. Even plugins can't really get you what you want here. Yes, HTML5 has limitations, as you described, but plugins aren't the solution. HTML5 is closer, and moving in the right direction at least.
- koonsolo 11y agoMobile doesn't need browser plugins, because it has apps. AS3 compiles to Android and iOS, just as it should. So I agree with Adobe that mobile doesn't need to support Flash. BTW, the same AS3 codebase for Flash runs as mobile apps. Do the HTML5 games support all versions of all browsers on the most popular mobile devices? Not on mine at least :(. One codebase, runs everywhere, Flash in the browser, apps on mobile devices. Personally never had an issue with it. Although I must agree with you that it's sad Adobe dropped Linux support.
- baby 11y agoThis is great. Let's continue: add Tree Style Tab natively
- lucianp 11y agoI second this! Tree Style Tab is one of the few addons that I cannot live without. Heck, it is one of the reasons why Firefox is my primary browser. This feature should be made native and the original developer should be rewarded somehow for his efforts.
- Sanddancer 11y agoWhy isn't Mozilla spending more time to ensure Firefox is using all of the security resources that the OS gives it? Things like ASLR still aren't enabled by default, let alone plugin sandboxing like what exists in Chrome. While Shumway would be nice, having a reliable, secure way to hook into native code would be a lot nicer.
- jasonthevillain 11y agoThe next time this happens can you please disable it entirely? The things on my site (video, some ads) that use flash will fall back nicely to HTML5 is Flash is disabled, as will most of the web. Click to activate is the worst of both worlds.