Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They can very easily stop including the Flash player with every version of Chrome. It seems like that would solve some obvious security problems.

This is hardly an impossible feat.



The problem is that an outdated, unsandboxed version of Flash is installed on almost every desktop system. So, if we stopped including Flash, the vast majority of our users would be more vulnerable than they already are. That's why we're shipping a current version with a sandbox that's at least as good as IE low integrity mode, and we're also wrapping up work on a version of Flash that uses the full Chrome sandbox.


> The problem is that an outdated, unsandboxed version of Flash is installed on almost every desktop system.

Don't use it.

> So, if we stopped including Flash, the vast majority of our users would be more vulnerable than they already are.

Prompt to use a specific Flash when the user requests it.


If Chrome didn't bundle a better version of flash, and didn't use the system version of flash, users would find out that Chrome is "broken" the first time they got to a page with flash. Then they would switch to Firefox, Opera, or even IE if they're on windows. Those browsers do use the system flash plugins. Who wins? Not security.

If Chrome didn't bundle a modified version, and prompted the user to select a Flash version, the only one they could offer would be the system one.

Unless you're saying that the Chrome team should go to all the effort to build a custom version of flash, but only deliver it to Chrome browsers when the user specifically requests it? That strategy seems DOA from a cost/benefit analysis perspective.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: