Recommended Posts

Adobe adds Flash sandboxing to Firefox

Hackers bypass it in 3, 2?

Adobe has released beta code for sandboxing its heavily hacked Flash code within Firefox, in a similar fashion to the Chrome security protections added to its Reader software and Google?s Chrome browser.

?Sandboxing technology has proven very effective in protecting users by increasing the cost and complexity of authoring effective exploits,? said Peleus Uhley, senior security researcher for Adobe in a blog post.

?For example, since its launch in November 2010, we have not seen a single successful exploit in the wild against Adobe Reader X. We hope to see similar results with the Flash Player sandbox for Firefox once the final version is released later this year.?

Adobe used elements of the sandboxing technology Google had built into Chrome for its Reader code, after a string of attacks against the popular Flash platform. The technology was released on November 2010 ? and promptly broken less than two months later by a Google engineer, although Adobe said this didn't count as it couldn't be done remotely. The code has also been added to Chrome, and Adobe promised other browsers would get similar protections.

The code will work with Firefox 4.0 or later versions running on Windows 7 or Vista. More details will be given in Uhley?s talk at the CanSecWest security conference in Vancouver, British Columbia, early next month.

Source: The Register

It's sad that Adobe has to do it since they know Mozilla never will.

What makes you think Mozilla wouldn't implement such a thing? I'd say Adobe need to do it themselves because Flash is a mess when it comes to security at this point.

What makes you think Mozilla wouldn't implement such a thing? I'd say Adobe need to do it themselves because Flash is a mess when it comes to security at this point.

It depends on how you implement the sandboxing, the mode Windows offers would break Flash and Java (Which is why Mozilla haven't implemented it). Google seems to have written their own sandboxing code which is why it works with Flash (because it's designed to simply, it allows it to break out of the sandbox when needed, while an OS provided sandbox would be stricter, etc.)

Sad that people still feel they have to use Flash. Thankfully pretty much every place I care in the slightest about has already switched away.

It's sad that people feel that they don't have to use Flash to avoid the clusterf*** of web standards and growing disparity between browsers and the fact that it gives us things you would have never had on the web. The ignorance among people is astounding. But I guess people will hate when they are being told to hate. No way around it.

It's sad that people feel that they don't have to use Flash to avoid the clusterf*** of web standards and growing disparity between browsers and the fact that it gives us things you would have never had on the web. The ignorance among people is astounding. But I guess people will hate when they are being told to hate. No way around it.

But, installing Flash always was the disparity. IMO, had Flash begun like Adobe Air (that is, a download and run anywhere piece of external software), it wouldn't have taken such a hit when Apple decided not to support it. It was the fact that Jobs said it couldn't run on iOS that made everyone else say, "oh, maybe we don't really need Flash." On the other hand, had it been a stand alone application that didn't require browser buy in, it could have taken a huge lead in early mobile development by porting Air over to iOS and Android (and anything else).

growing disparity between browsers

Huh? I know this is going a bit off topic, but the disparity has almost entirely been between IE and [the others] for about ten years. Since IE is catching up with the others, I really fail to see a 'growing' disparity. Sure there's differences between Webkit and Gecko for example (and there's some concern in CSS circles about that), but they're not so extreme as pretty much [everything] to IE6/7.

Adobe Flash is rock solid now. It outperforms IE9 HTML5 h264 performance on netbooks by my testing.

Huh? I know this is going a bit off topic, but the disparity has almost entirely been between IE and [the others] for about ten years. Since IE is catching up with the others, I really fail to see a 'growing' disparity. Sure there's differences between Webkit and Gecko for example (and there's some concern in CSS circles about that), but they're not so extreme as pretty much [everything] to IE6/7.

Everyone is adapting to Webkit now.

Adobe Flash is rock solid now. It outperforms IE9 HTML5 h264 performance on netbooks by my testing.

Everyone is adapting to Webkit now.

Who is everyone? Google and Apple.. you still have disparity between Google's Chrome and Apple's Safari in how they support CSS3 features (for example Google will support CSS3 regions and some Adobe proposed CSS3 additions while Apple added some Safari specific webkit transforms that allow you to get hardware accelerated effects that only work on Safari). Naturally, Firefox, Opera and IE do not use Webkit and have completely different ways of dealing with CSS and even DOM in some cases.

We have never been further away from unified browser because every browser maker has their own interests and politics and want to rule the web.

But I do agree with you, Flash is by far, today, years ahead of anything HTML5 offers and has quickly trumped the HTML5 video/h.264 performance it briefly lost to HTML5 but with Flash you have huge interactivity support via coding on top of the video layer, plus good DRM for commercial videos and so many other things. This is only for videos mind you.

I just hope that Adobe disables, sooner than later, right click on the Flash player as I guarantee all the hate mongering people will not even know what's flash and what's HTML if that was the case today.

This topic is now closed to further replies.
  • Posts

    • You pay just $100 per TB with this rare 4TB PCIe Gen4 NVMe SSD deal by Sayan Sen SSDs and GPUs are incredibly hard to get nowadays due to high pricing. Discounts are quite rare which is why we report on them as soon as we spot a good deal. For example AMD's new 9070 GRE was finally up for sale at a very good price of just $500 thanks to a special coupon. Sadly that deal is gone but if you happen to be looking for a 4TB NVMe SSD and can spend around $400 there is a really good offer on sale that you should not miss out on as TeamGroup's 4TB G50 model is on sale for that that price which means you are only paying $100 per TB, a very good deal in the current market (purchase link under the specs table down below). The TeamGroup T-FORCE G50 NVMe SSD is a PCIe Gen4 drive and as such it promises to deliver sequential read speeds of up to 5,000 MB/s, helping accelerate game loading, file transfers, and everyday computing tasks. Since this is a 4TB drive you can use it for a gaming library to take advantage of things like DirectStorage. The SSD features an InnoGrit controller and SLC caching technology to support consistent performance. An ultra-thin, patented graphene heatsink is included to aid in heat dissipation. Get it at the link below: Team Group T-FORCE G50 4TB Internal SSD (TM8FFE004T0C129): $449.99 + $50 off w/ promo code SSF69668, limited offer => $39.99 (Sold and Shipped by Newegg US) Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • I agree. I also think Phil stayed too long. They should definitely fire whoever thought all a console platform needed was Call of Duty, Elder Scrolls, and Fallout to survive. Asha and crew are still saying they need more Elder Scrolls and Fallout games. They simply don't get it.
    • Macbook Air is an appealing option, as are plethora of Windows devices with various different CPU's
    • Mozilla highlights Firefox Nova 2026 redesign and more upcoming features with new roadmap by Sayan Sen Last month Mozilla confirmed that Firefox was set to get a major redesign this year. Dubbed "Project Nova", it can already be tested and will roll out to all users later this year.The idea is to keep the browser competitive in a rapidly evolving internet landscape. As such the revamp focuses on improving privacy, usability, performance, accessibility, and customization. Key privacy features including the built-in VPN, private browsing mode, and Enhanced Tracking Protection, will be more visible and easier to manage, while users will have the option to disable AI features entirely through a dedicated kill switch. Additionally, the redesign promises faster page loading, the return of Compact mode, expanded personalization options, and stronger accessibility support. You can find the full details in the dedicated piece linked above. In a new blog post today the company once again reiterated on Nova and also emphasized other new and upcoming features like the settings revamp that is intended to make it easier for users to understand browser settings. In order to make it simpler for users to keep up with such features Mozilla today is launching Firefox roadmap. Hence enthusiasts and interested users will be able to check out what's cooking and also share feedback about the upcoming additions. Alongside the roadmap announcement, Mozilla also highlighted what's new in Firefox 152. One of the biggest additions is the arrival of Tab Groups on Android. The feature, which has already been helping desktop users organize large numbers of tabs, is now beginning to roll out on mobile. Users will be able to group related tabs together, assign names and colors to them, and return to them later. Mozilla says support for iOS will arrive later this year. Firefox 152 also introduces the aforementioned redesigned Settings experience. The company says the changes are meant to make controls easier to find and help users discover features they may not have previously known about. Existing preferences are not changing, though they are now better organized. Another notable addition is the new Blocked Tracker Widget, which provides a visual overview of Firefox's privacy protections by showing how many trackers have been blocked over time and the types of tracking activity the browser has stopped. Looking ahead, Mozilla revealed several upcoming roadmap features. They include customizable keyboard shortcuts, as well as enhanced PDF editing tools that will allow documents to be split, merged, and reorganized directly within Firefox. The company is also working on bringing Multi-Account Containers into the native Firefox experience thus removing the need for a separate extension. Meanwhile Firefox's built-in VPN is set to expand to mobile devices. Mozilla is also developing AI-powered features like Quick Answers, which can provide concise responses to voice queries, and Smart Window, its optional AI browsing experience that is now available without a waitlist. Finally, a new Power Saving Mode is in the works and will help reduce the impact of resource-heavy tabs on mobile devices in order to extend battery life. The video below summarizes the upcoming changes in an easy to understand format: You can find the announcement blog post here on Mozilla's official website.
  • Recent Achievements

    • One Year In
      Console General earned a badge
      One Year In
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • Veteran
      branfont went up a rank
      Veteran
  • Popular Contributors

    1. 1
      +primortal
      513
    2. 2
      +Edouard
      196
    3. 3
      PsYcHoKiLLa
      109
    4. 4
      Steven P.
      89
    5. 5
      Nick H.
      71
  • Tell a friend

    Love Neowin? Tell a friend!