Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Mozilla Firefox Security Software Technology

Sandboxed Flash Player Coming To Firefox 86

Trailrunner7 writes "Adobe, which has spent the last few years trying to dig out of a deep hole of vulnerabilities and buggy code, is making a major change to Flash, adding a sandbox to the version of the player that runs in Firefox. The sandbox is designed to prevent many common exploit techniques against Flash. The move by Adobe comes roughly a year after the company added a sandbox to Flash for Google Chrome. Flash, which is perhaps the most widely deployed piece of software on the Internet, has been a common attack vector for several years now, and the attacks in some cases have been used to get around exploit mitigations added by the browser vendors. The sandbox is designed to prevent many of these attacks by not allowing exploits against Flash to break out into the browser itself."
This discussion has been archived. No new comments can be posted.

Sandboxed Flash Player Coming To Firefox

Comments Filter:
  • 'bout time! (Score:2, Insightful)

    by Anonymous Coward on Monday February 06, 2012 @05:59PM (#38946825)

    Its about damn time they did this for Firefox. I don't know how many times Flash has caused my browser to crash and I couldn't do anything about it. I love how in Chrome only the Flash player dies and not the browser.

  • Here's my hope. (Score:5, Insightful)

    by Moryath ( 553296 ) on Monday February 06, 2012 @06:00PM (#38946829)

    Maybe sandboxing the damn flash player will stop it from periodically causing Firefox to hang for 30 seconds or so thanks to some damn ugly "full motion video" ad that's trying to load up?

    I'd love to see a ban on FMV ads. Double for FMV ads that start themselves automatically, and quadruple for those fucking ads that blast audio after doing so.

  • Whitelist (Score:5, Insightful)

    by sakdoctor ( 1087155 ) on Monday February 06, 2012 @06:00PM (#38946835) Homepage

    The whitelist for flash is in the single digits. Most sites don't need that privilege.
    Youtube, a couple of porn sites ... that's about it really.

  • Half Way There (Score:4, Insightful)

    by rsmith-mac ( 639075 ) on Monday February 06, 2012 @06:08PM (#38946905)

    Considering Flash's extensive use as an attack vector this is great news. I would sleep better at night though if Firefox itself was also sandboxed; in fact I'm a bit surprised you can even sandbox Flash when the browser doesn't support it.

  • Re:Here's my hope. (Score:4, Insightful)

    by cmarkn ( 31706 ) on Monday February 06, 2012 @06:53PM (#38947339)
    Yes, because clicking once for each domain that provides scripts to the site, the first time you visit it, is such a nightmare.</sarcasm>

"Here's something to think about: How come you never see a headline like `Psychic Wins Lottery.'" -- Comedian Jay Leno

Working...