FYI: Firefox now blocks Flash automatically

[Presumably this is “coming soon” as I am unable to see any change in the behaviour of my FireFox: v39.0 (no pending updates) on OS X. YMMV]
Posted today onto Twitter by Mark Schmidt (Head of @Firefox Support at @Mozilla, the makers of FireFox browser):
Mark Schmidt @MarkSchmidty https://twitter.com/MarkSchmidty 14h ago14 hours agohttps://twitter.com/MarkSchmidty/status/620743669197504513 It's day four of multiple critical Flash vulnerabilities and @googlechromehttps://twitter.com/googlechrome still hasn't disabled Flash Player.
…and then, 2 hours later:
BIG NEWS!! All versions of Flash are blocked by default in Firefox as of now. https://t.co/4SjVoqKPrR #techhttps://twitter.com/hashtag/tech?src=hash #infosechttps://twitter.com/hashtag/infosec?src=hashpic.twitter.com/VRws3L0CBWhttp://t.co/VRws3L0CBW
— Mark Schmidt (@MarkSchmidty) July 14, 2015https://twitter.com/MarkSchmidty/status/620783674561327104
To be clear, Flash is only blocked until Adobe releases a version which isn't being actively exploited by publicly known vulnerabilities.
— Mark Schmidt (@MarkSchmidty) July 14, 2015https://twitter.com/MarkSchmidty/status/620806013768323072
…from: https://support.mozilla.org/en-US/kb/keep-flash-up-to-date-and-troubleshoot-... http://www.engadget.com/2015/07/14/firefox-blocks-flash/?ncid=rss_truncated
Firefox now blocks Flash automatically
[blogger-avatar]by Daniel Cooperhttp://www.engadget.com/about/editors/daniel-cooper/ | @danielwcooperhttp://twitter.com/danielwcooper | 3 Hours Ago
Flash is the Justin Bieber of browser plugins: it's everywhere, it does nothing useful and every time you see it you want to smash a window. Yesterday, Facebook's head of securityhttp://www.engadget.com/2015/07/13/facebook-security-lead-wants-flash-dead/ publicly opined that it was time for the platform to die, and just a day later, Mozilla's Mark Schmidt has joined in. In a tweet, Schmidt has announced that, as of the latest update, the Firefox browser will block Flash automatically. It looks as if the technology world has decided that if Adobe won't do the decent thing and kill it, then everyone else will just tool up and beat it to death themselves.
BIG NEWS!! All versions of Flash are blocked by default in Firefox as of now. https://t.co/4SjVoqKPrR #techhttps://twitter.com/hashtag/tech?src=hash #infosechttps://twitter.com/hashtag/infosec?src=hashpic.twitter.com/VRws3L0CBWhttp://t.co/VRws3L0CBW
— Mark Schmidt (@MarkSchmidty) July 14, 2015https://twitter.com/MarkSchmidty/status/620783674561327104
It may have been the best way to deliver video in the early days of the internet, but the rise of standards compliant technologies make Flash look obsolete. More importantly, however, Flash is riddled with holes, and it's often used as a beachheadhttp://www.engadget.com/2015/04/18/russian-hackers-use-zero-day-attacks/ for hackershttp://www.engadget.com/2014/10/24/cryptowall-ransomware-attack-proofpoint-report/ to get comfortablehttp://www.engadget.com/2014/07/09/flash-rosetta-exploit-discovered/ inside your computerhttp://www.engadget.com/2015/07/08/hacking-team-zero-day-flash-exploit/. Oftentimes, this is met with silence from Adobehttp://www.engadget.com/2011/11/09/adobe-confirms-flash-player-is-dead-for-mobile-devices/, a point that The Registerhttp://www.theregister.co.uk/2015/07/14/adobe_response_to_security_holes/ put to the company's Wiebke Lips. Her response was that there are "extensive efforts" in progress at the company to make the code harder to crack, although they're not yet ready to be pushed out to users.
To be clear, Flash is only blocked until Adobe releases a version which isn't being actively exploited by publicly known vulnerabilities.
— Mark Schmidt (@MarkSchmidty) July 14, 2015https://twitter.com/MarkSchmidty/status/620806013768323072
2015 is becoming the year that Flash gets killed-off once and for all, with Google tweaking Chrome to "intelligently" block auto-playing adverts. In addition, YouTube, the site that was probably the plugin's biggest proponent, switched to HTML 5http://www.engadget.com/2015/01/27/youtube-html5/ to deliver video at the start of the year. It's likely that other notable holdouts will be pressured, either by these latest moves, the most recent security controversies or the Occupy Flashhttp://www.occupyflash.org/ movement. Yup, there's a whole movement dedicated to eradicating this stuff from the web.
Oh, and should you want or, more likely, need to use Flash, you can reactivate the feature at your liberty by dipping into Firefox's settings menu.
Hide Comments
participants (1)
-
Wayne Billing