Patch Your Flash (Again) and Just Turn On Click-to-Play

Patch Your Flash (Again) and Just Turn On Click-to-Play

Tech News adobe browsers flash patching security

So Adobe pushed out an emergency Flash patch on Thursday and I almost missed it because I don't check Adobe's security bulletins for fun (does anyone?). But a friend on Twitter flagged it Friday morning and I figured I'd better write this one down before I forget, because this is like the third "update Flash RIGHT NOW" moment since Christmas and I'm losing track.

The short version: Adobe fixed two vulnerabilities, CVE-2013-0633 and CVE-2013-0634, and both were already being exploited in the wild before the patch existed. One of them was getting delivered through a malicious Word document with an embedded SWF, targeting Windows machines. The other was a drive-by download aimed at Safari and Firefox on OS X. So basically nobody was safe just by picking a "safer" browser or OS, which is the part that annoys me most. People love to tell you switching to a Mac makes you immune to this stuff. It doesn't. It just changes which zero-day gets you.

If you haven't updated, go do it now, seriously, close this tab after. You want 11.5.502.149 on Windows and Mac (10.x on Linux, though who's counting at this point). Chrome and IE10 on Windows 8 bundle their own Flash and update themselves, so those are probably already fine, but standalone installs on everything else need a manual push.

Here's the thing I actually want to talk about though.

I've basically stopped letting Flash run automatically at all, and I think more people should. Both Chrome and Firefox let you flip plugins into "click to play" mode, so instead of every embedded SWF firing off the second a page loads, you get a little gray box and nothing happens until you actually click it. It sounds like a hassle and for about two days it is, and then you stop noticing because it turns out the vast majority of Flash on the modern web is either an ad or some auto-playing video you didn't want anyway.

In Chrome it's under chrome://settings then Content Settings, down in Plug-ins, set to "Click to play." Firefox has it built into about:config if you dig, or you can just install the Flashblock extension and not think about it. Takes maybe ninety seconds either way. I did mine back in December after the last Flash scare and honestly the web feels less cluttered now, not just safer. Half the sites I visit for work still insist on Flash video players in 2013 which is its own kind of embarrassing, but that's a rant for another post.

I'll admit I have a bias here. I've hated Flash since roughly 2008, back when it used to eat 40% of my CPU just sitting in a background tab doing nothing, and I don't think it's aged well. HTML5 video isn't perfect either, but at least when it breaks it doesn't usually come with a side of remote code execution. Every few weeks there's a new "critical, update immediately" bulletin, and every few weeks I do it, and every few weeks I wonder why this is still how a big chunk of the internet works. It's not like there wasn't a warning. People have been saying Flash was a security liability for years and the answer from a lot of sites has just been "well, everyone already has it installed."

Anyway. Patch it, or better yet, cage it so it only runs when you actually ask for it. I'm not going to pretend click-to-play is some genius insight, plenty of people smarter than me have been saying it for a while, but I still run into folks who've never bothered flipping the setting because it never occurred to them Flash could be the thing that gets them.

In unrelated small stuff from this week: I finally caved and installed Vine, mostly out of curiosity, and I don't get it yet. Six seconds feels like both nothing and somehow too long depending on what's happening on screen. Maybe it clicks eventually. Or maybe I'm just getting old and cranky about apps, which, given the above 900 words about a browser plugin setting, is probably not a huge surprise to anyone reading this.