Recommended Posts

Adobe adds Flash sandboxing to Firefox

Hackers bypass it in 3, 2?

Adobe has released beta code for sandboxing its heavily hacked Flash code within Firefox, in a similar fashion to the Chrome security protections added to its Reader software and Google?s Chrome browser.

?Sandboxing technology has proven very effective in protecting users by increasing the cost and complexity of authoring effective exploits,? said Peleus Uhley, senior security researcher for Adobe in a blog post.

?For example, since its launch in November 2010, we have not seen a single successful exploit in the wild against Adobe Reader X. We hope to see similar results with the Flash Player sandbox for Firefox once the final version is released later this year.?

Adobe used elements of the sandboxing technology Google had built into Chrome for its Reader code, after a string of attacks against the popular Flash platform. The technology was released on November 2010 ? and promptly broken less than two months later by a Google engineer, although Adobe said this didn't count as it couldn't be done remotely. The code has also been added to Chrome, and Adobe promised other browsers would get similar protections.

The code will work with Firefox 4.0 or later versions running on Windows 7 or Vista. More details will be given in Uhley?s talk at the CanSecWest security conference in Vancouver, British Columbia, early next month.

Source: The Register

It's sad that Adobe has to do it since they know Mozilla never will.

What makes you think Mozilla wouldn't implement such a thing? I'd say Adobe need to do it themselves because Flash is a mess when it comes to security at this point.

What makes you think Mozilla wouldn't implement such a thing? I'd say Adobe need to do it themselves because Flash is a mess when it comes to security at this point.

It depends on how you implement the sandboxing, the mode Windows offers would break Flash and Java (Which is why Mozilla haven't implemented it). Google seems to have written their own sandboxing code which is why it works with Flash (because it's designed to simply, it allows it to break out of the sandbox when needed, while an OS provided sandbox would be stricter, etc.)

Sad that people still feel they have to use Flash. Thankfully pretty much every place I care in the slightest about has already switched away.

It's sad that people feel that they don't have to use Flash to avoid the clusterf*** of web standards and growing disparity between browsers and the fact that it gives us things you would have never had on the web. The ignorance among people is astounding. But I guess people will hate when they are being told to hate. No way around it.

It's sad that people feel that they don't have to use Flash to avoid the clusterf*** of web standards and growing disparity between browsers and the fact that it gives us things you would have never had on the web. The ignorance among people is astounding. But I guess people will hate when they are being told to hate. No way around it.

But, installing Flash always was the disparity. IMO, had Flash begun like Adobe Air (that is, a download and run anywhere piece of external software), it wouldn't have taken such a hit when Apple decided not to support it. It was the fact that Jobs said it couldn't run on iOS that made everyone else say, "oh, maybe we don't really need Flash." On the other hand, had it been a stand alone application that didn't require browser buy in, it could have taken a huge lead in early mobile development by porting Air over to iOS and Android (and anything else).

growing disparity between browsers

Huh? I know this is going a bit off topic, but the disparity has almost entirely been between IE and [the others] for about ten years. Since IE is catching up with the others, I really fail to see a 'growing' disparity. Sure there's differences between Webkit and Gecko for example (and there's some concern in CSS circles about that), but they're not so extreme as pretty much [everything] to IE6/7.

Adobe Flash is rock solid now. It outperforms IE9 HTML5 h264 performance on netbooks by my testing.

Huh? I know this is going a bit off topic, but the disparity has almost entirely been between IE and [the others] for about ten years. Since IE is catching up with the others, I really fail to see a 'growing' disparity. Sure there's differences between Webkit and Gecko for example (and there's some concern in CSS circles about that), but they're not so extreme as pretty much [everything] to IE6/7.

Everyone is adapting to Webkit now.

Adobe Flash is rock solid now. It outperforms IE9 HTML5 h264 performance on netbooks by my testing.

Everyone is adapting to Webkit now.

Who is everyone? Google and Apple.. you still have disparity between Google's Chrome and Apple's Safari in how they support CSS3 features (for example Google will support CSS3 regions and some Adobe proposed CSS3 additions while Apple added some Safari specific webkit transforms that allow you to get hardware accelerated effects that only work on Safari). Naturally, Firefox, Opera and IE do not use Webkit and have completely different ways of dealing with CSS and even DOM in some cases.

We have never been further away from unified browser because every browser maker has their own interests and politics and want to rule the web.

But I do agree with you, Flash is by far, today, years ahead of anything HTML5 offers and has quickly trumped the HTML5 video/h.264 performance it briefly lost to HTML5 but with Flash you have huge interactivity support via coding on top of the video layer, plus good DRM for commercial videos and so many other things. This is only for videos mind you.

I just hope that Adobe disables, sooner than later, right click on the Flash player as I guarantee all the hate mongering people will not even know what's flash and what's HTML if that was the case today.

This topic is now closed to further replies.
  • Posts

    • Zero tolerance for antisemitic social media posts. Thousands of arrests and fines.
    • It's not about the kids, it's about de-anonymizing the entire internet to punish people for wrongthink. The only way to ban kids, is to demand ID from everyone, a digital ID if you will.
    • QuickView 6.8.1 by Razvan Serea QuickView is the fastest image viewer for Windows, designed to open all your photos instantly. It supports popular formats like WebP, AVIF, JPEG XL, PNG, JPEG, TIFF, RAW, and PSD, making it perfect for photographers, designers, and everyday users. With lightning-fast load times and zero-lag previews, QuickView handles everything from small icons to massive 8K images effortlessly. Drag and drop files to view them instantly, zoom and pan smoothly, and enjoy a clutter-free interface built for speed and simplicity. QuickView also makes managing and analyzing images easy. You can preview thousands of photos instantly, view real-time color and brightness, and check image details without slowing down your computer. It automatically fixes common file issues and works perfectly offline, so your images stay private. QuickView supports multiple languages, is portable, and requires no installation. QuickView key features: Blazing Fast Loading – Open images instantly with zero lag. Modern Format Support – View WebP, AVIF, JPEG XL, and more. RAW File Ready – Handle photos from all major cameras effortlessly. Classic Format Friendly – Supports PSD, PNG, JPEG, TIFF, and BMP. Drag-and-Drop Convenience – Open files instantly without menus. Multilingual Interface – Works in English, Chinese, Japanese, German, Spanish, and Russian. Portable & Lightweight – Single executable, no installation required. Mass Image Preview – Instantly view thousands of images with HUD Photo Wall. Real-Time Color Tools – RGB histograms and color analysis overlays. Accurate Metadata – View EXIF and file information instantly. Smart File Fixes – Automatically repair incorrectly saved files. Fast or Full-Quality Toggle – One-click RAW preview adjustment. Smooth Navigation – Zoom, pan, and scroll without slowdowns. Privacy Focused – Fully offline operation keeps your images secure. QuickView 6.8.1 release notes: Dynamic Island, Filmstrip Gallery, Custom Hotkeys & Size Optimization QuickView v6.8.1 introduces redesigned window controls, an interactive filmstrip gallery, dual-mode slideshows, fully customizable hotkeys, and substantial binary size optimizations. Changelog: Floating 'Dynamic Island' Window Controls The window controls have been redesigned for a cleaner interface. Floating Capsule Pill (#199): Replaces traditional window controls with a floating pill-shaped widget in the top-right corner. Includes hover glow transitions. Compact Size: Reduced the size of caption buttons to maximize screen space for images. Interactive Filmstrip Gallery The filmstrip gallery has been redesigned with improved controls and animations. Top-Hover Trigger: Hover near the top edge to expand the filmstrip gallery. The trigger mode can be set to Hover, Pinned, or Disabled via the Settings menu. Auto-Centering Scroll: Selecting a thumbnail triggers a smooth scrolling animation that aligns the item to the center of the bar. Visual Refinements: Corrected visual gaps when pinned, fixed zoom anchor offsets, and restored smooth horizontal auto-scrolling. Dual-Mode Slideshow Spotlight Mode: Added a slideshow mode inspired by Picasa Spotlight, which dims the background and focuses on the active image. Normal Mode: Standard fullscreen slideshow functionality. Fully Customizable Hotkeys Custom Keyboard Mapping: Added support for completely customizing and rebinding all core keyboard shortcuts and navigation hotkeys directly within the Settings menu. UI/UX Adjustments & Window Snapping Magnetic Snapping (#90): Window borders now snap to screen edges (100% magnetic snap) when resized. Responsive Toolbar (#194): Toolbar buttons automatically hide based on the window width and active mode. Timeline Scrubbing: Implemented debounced asynchronous seeking for animated formats, providing smooth scrubbing without timeline lag. Fixed frame count and distortion issues on large GIF seeking (#197). Extended Mouse Mapping (#191): Added support for mapping multi-function mouse side buttons in settings. Archive Sorting (#193): Added an option to always sort archives by name ascending. Footprint Compression & Size Optimizations Reduced the binary size of the standalone executable by removing redundant templates and dependencies. C++ Stream Elimination: Removed dependencies, saving approximately 18.5 KB. Localization Deduplication: Consolidated localization string tables, saving 10.5 KB by preventing template duplication. Vector Icon Compression: Compressed static vector icon coordinates to 16-bit integers, saving 54 KB. Code Devirtualization: Replaced std::function callbacks with C-style function pointers and devirtualized core controllers to reduce overhead. LTO Debug Fix: Removed obsolete compiler flags (/MERGE:.rdata=.text) from Link-Time Optimization (LTO) builds to fix minidump crash debugging. Decoding & Memory Fixes Hybrid Allocation: Implemented a hybrid memory allocator to balance preloading and tile rendering. Access Violations: Fixed crashes when rapidly switching images. HDR in Archives: Resolved an issue where HDR images decoded from ZIP/RAR archives lost their peak luminance metadata or failed to render in float format. WebP, AVIF & JXL (#195): Fixed shadow transparency glitches in WebP/AVIF and image distortion in JPEG XL. Download: QuickView 64-bit | Portable 64-bit | ~5.0 MB (Open Source) Download: QuickView ARM64 | Portable ARM64 View: QuickView Website | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • There was a Spider-Man game back in the day that had these as well. When other people played, they got gamer ads. When I played, I got ads for Visual Studio on the billboards in the city.
  • Recent Achievements

    • Conversation Starter
      NovaEdgeX earned a badge
      Conversation Starter
    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      521
    2. 2
      +Edouard
      186
    3. 3
      PsYcHoKiLLa
      107
    4. 4
      Steven P.
      88
    5. 5
      ATLien_0
      67
  • Tell a friend

    Love Neowin? Tell a friend!