Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Stop running Flash and Java, they are the source of most browser vulnerabilities, which are the source of most malware

Go to chrome://plugins and kill everything

When you need one of the two, run them in a separate (updated) browser in a separate guest account (fast user switching ftw).



When you need one of the two, run them in a separate (updated) browser in a separate guest account (fast user switching ftw).

Yeah, nobody is going to do that. Chrome has an option to have 3rd party plugins blocked by default (click to activate) and Firefox has Flashblock. That's about as much as you can expect users to do.


> Yeah, nobody is going to do that.

I do. Once you force yourself to do it once or twice it is actually pretty quick (2 keystrokes), but you rarely need Flash today anyway. There are far too many web rootkits going around for it to be worth running flash and java (OSX and windows)

see: http://krebsonsecurity.com/2010/10/java-a-gift-to-exploit-pa...

If you spend any amount of time on the web there is a chance that you have visited a page running an exploit pack. Their penetration rates are 10-20%. There is even a chance that you have been exploited right now and don't even know it.

Any extension that claims to block in Chrome doesn't actually block, since the extension API doesn't allow that - it is only hiding using CSS or some other Javascript trick that still leaves the plugins vulnerable. Flashblock for Firefox also doesn't prevent exploits of vulnerable browser plugins.

All those plugins create a false sense of security


The plugin click to enable in chrome is built-in.

And what do you mean flashblock in Firefox doesn't help? If you don't intentionally activate the plugin it can't hurt you.


the last time I looked at the Flashblock code for Firefox there was a way to still exploit a flash vuln by slowing the page load down or intercepting DOMContentInserted

Chrome is definitely vulnerable. They are a few versions away from making the blocking API non-experimental.


Using an extension to block may be vulnerable but the builtin click to activate is different. No API involved, I can go to youtube with click-to-activate turned on and it doesn't even spin up a plugin process until I click.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: