Going cold turkey on the unholy trinity

I can't find the link right now, but I just read the other day that Mozilla is going to put into the official Firefox distribution js-based Flash support. You won't need to install Flash itself, your browser will continue to run (most) Flash content, and it'll automatically be sandboxed by the browser's existing protections for js.

i'm ok with PDF format but not so with Adobe's unnecessarily bulky updating mechanism. i had used Adobe Acrobat before and didn't find it a hog. however nowadays, i am using the same apps as yourself (SumatraPDF and PDF-XChange Viewer).

most of my video browsing is done on my android devices and when i am at home, i just 'cast' them on my tv instead of watching on the PC. since Adobe themselves don't support Flash on Android, it should be a wake-up call for video content providers to get themselves updated. so because of that, i am holding back from using Flash on my PC.
-lanux128 (October 11, 2013, 12:31 AM)
--- End quote ---

Hmm. A bit of mixed motivations here.

Wanting to watch stuff is a "now" problem. It will take *years* before holistically "everyone" is on html5 or whatever else.

As an example concept, though I'm not sure it quite applies to a PC:
Apple iPhone's famous lack of Flash. However, I would like to be able to use my phone like the small computer it is, without a certain Steve's prefs getting in my way. Specifically, a certain chat site that runs on Flash. "Won't someone ever think of the Chat Apps?"

So I found something called Photon Browser. "Oh look, my iPhone plays Flash apps now. "
(Shock! Horror!) "How did you do that?"

Because Photon Browser takes the end signal, parses it, and sends some kind of data batch to the iPhone, and back.

In the few weeks since this thread started, Mozilla is now blocking in-browser Java outright, yes?

OP, have you ever been "bitten by" Java, or had malware injected onto your system via a Java vulnerability?

(Not asking you to list them, but) I'm wondering what sites you visit which require use of Java?
I've had Java disabled in-browser since way back in 2005(?) and can't say I've ever missed it, er, don't know what I've missed out by not having it available.

I do have JRE installed to a sandboxie container. Several graphics applications that I've used depend on its availability.
I've never personally been bitten by malware employing a Java vector, but prior to disabling it in-browser, I came "yay close to being bitten" -- proxomitron rules thwarted redirection and /or loading of the injector embed object.

Along with Java, I block Silverlight, RealPlayer, and similar proprietary devices. I don't regard them as being inherently evil, though. I just don't want to expose myself to the potential grief their ongoing vulnerabilities invite. IMO, the most dangerous (and maybe I'd even label it as "evil") current aspect of web-centric computing is "dot net" (.Net) ... with NaCL (native client) on the horizon, as a close second.

Flash extension remains installed in my Firefox browser. FlashBlock browser addon suits me fine.
Probably the only thing I've blocked, and occasionally "miss" is Shockwave... or the ol' Macromedia Director.
We had some wonderful freeware and shareware games which utilized Director.

IMO, the most dangerous (and maybe I'd even label it as "evil") current aspect of web-centric computing is "dot net" (.Net)
-saralynn (October 24, 2013, 06:29 PM)
--- End quote ---

Just curious... why would you label .NET as evil?

Firefox also blocks several other plugins out of the box, there is a full list here.

@saralynn: other than crashes and general updating annoyances, i have not been affected by any malware using the plugins as a conduit (touch wood). however my primary concern is whether casual users need flash/java in their computers. i feel that the plugins system is so clunky and awkward and casual users shouldn't be expected to keep up with the latest news of security issues and update/patch diligently.

especially java, i seem to need it for only minecraft (lucky me) and as for flash videos, i don't mind since i don't/can't access to any streaming video sites (e.g. Hulu, Netflix, ESPN, etc) so whenever i see this:


i take it as their loss, not mine. :)


