Firefox to enforce 'click to play' for non-Flash plug-ins


— 5:09 PM on January 30, 2013

Day-to-day web browsing in Firefox is about to get a little different. According to a blog post by Michael Coates, Mozilla's Director of Security Assurance, Firefox will soon require users to click to play content from all third-party plug-ins—except for the latest version of Flash.

In other words, Silverlight videos or Java applets will no longer appear automatically. The way Firefox's Click to Play feature works right now, users are presented with a grayed-out box and a "click here to activate" link, like so:

Folks running Firefox should start seeing a lot of those boxes soon—but hopefully not too many. Coates says it'll be possible to set certain sites to "never run plugins or . . . always run plugins." Off the top of my head, I can think of one site you'd want to add to the white list right away: Netflix, which (somewhat bizarrely) uses Silverlight to stream video content.

The thinking behind Mozilla's decision is pretty easy to understand. As Coates points out, auto-running plug-ins can jeopardize performance and stability. Also, security holes in outdated or vulnerable plug-ins are a "common exploitation vector." There may be no stopping users from clicking the "activate" button and infecting themselves, but at least this way, it won't happen automatically.

   
Register
Tip: You can use the A/Z keys to walk threads.
View options

This discussion is now closed.