←back to thread

288 points fernandotakai | 5 comments | | HN request time: 0.833s | source
1. hobarrera ◴[] No.10041187[source]
> [...] plugins don't need to be signed.

So the worst kind of threat is still there. Great job, Mozilla!

replies(2): >>10041250 #>>10041442 #
2. fernandotakai ◴[] No.10041250[source]
yup, and that's what i don't get. statistically, plugins like java and flash are a bigger security threat than addons. i don't even remember an addon going rogue.
replies(1): >>10041276 #
3. hobarrera ◴[] No.10041276[source]
I also quite clearly recall mozilla stating that plug-ins are responsible for over 95% of all browser crashes.
4. MacsHeadroom ◴[] No.10041442[source]
That's because plugins are going to need to be white-listed (modifiable via about:config). The win64 (beta) edition of Firefox only allows the Flash Player Plugin, for example.
replies(1): >>10042147 #
5. nightpool ◴[] No.10042147[source]
isn't this still vulnerable to the attack reported up-thread where whatever malware just goes and changed about:config before installing their plugin? (and the reason that the addon opt-out is being removed from ff42)