PDA

View Full Version : Firefox Set to Block Almost All Browser Plug-Ins



beanlicker
01-31-2013, 11:41 PM
by Paul Wagenseil

January 30 2013 04:48 PM ET

The Firefox Web browser will soon block all browser plug-ins except Adobe Flash Player by default, Firefox maker Mozilla announced yesterday (Jan. 29).

"One of the most common exploitation vectors against users is drive-by exploitation of vulnerable plug-ins," Michael Coates, Mozilla director of security assurance, said in a blog posting (https://blog.mozilla.org/security/2013/01/29/putting-users-in-control-of-plugins/).
Coates added that "poorly designed third-party plug-ins are the No. 1 cause of crashes in Firefox and can severely degrade a user's experience on the Web."

The move ought to severely cut down on the number of browser exploits affecting Firefox users. Dozens of exploits have been crafted against Flash, Adobe Reader and Java browser plug-ins. Users can become infected simply by landing on a corrupted website (http://www.securitynewsdaily.com/1876-driveby-download-definition.html).

This month, Java browser exploits (http://www.technewsdaily.com/16337-java-0day-new-year.html) got so serious and widespread that Firefox disabled Java plug-ins entirely.

"This change will help increase Firefox performance and stability, and provide significant security benefits, while at the same time providing more control over plug-ins to our users," Coates wrote.
Instead of running plug-ins automatically, future versions of Firefox will ask users to approve each instance in which a plug-in is needed, a feature that Mozilla calls "Click to Play."

Users will be able to adjust their settings to let specific plug-ins always run when accessing specific websites.

For example, the Microsoft Silverlight plug-in is needed to play Netflix streaming content, so users may want to make sure that plug-in is always enabled for the Netflix site.
The only plug-in that Firefox will automatically load for all sites is the latest current version of Adobe Flash Player, which is used by hundreds of thousands, if not millions, of sites — most notably, YouTube.

Older versions of the Flash plug-in will be blocked along with the rest and placed on Mozilla's list of blocked add-ons and plug-ins (https://addons.mozilla.org/en-US/firefox/blocked/). Coates did not give a timeline for that process.

PAiN
02-01-2013, 03:40 AM
Thanks for the info bro. I use a few plug-ins.

You have to be careful with plug-ins alot of them have viruses. If you don't know what you are doing I would suggest not using them. I can't tell you how many times I have had people tell me they are having browser problems and the first thing I tell them is to disable all plug-ins and 99% of the time that fixes the issue.

bigpimpdaddy
02-01-2013, 07:17 PM
Sounds like they are getting their crap together...