Ten Minutes to Stop Flash From Running Itself

Ten Minutes to Stop Flash From Running Itself

Tutorials adobe browser-security chrome firefox flash

Its been one of those weeks where I keep three browser tabs open just to watch things fall apart in real time. Yesterday the NYSE froze up for something like three and a half hours over what they're calling a "technical issue," United grounded planes over a computer glitch, and the Wall Street Journal's own site went down, all in the same few hours. Twitter was full of people convinced it was some coordinated hack. It almost certainly wasnt (these kinds of coincidences happen more than people want to admit, systems are fragile, thats the whole story most of the time) but I get why nobody believed that on a day like that.

The thing I actually want to talk about is smaller and, honestly, more useful to you than speculating about NYSE server racks.

On July 5th somebody dumped about 400 gigabytes of internal data from Hacking Team, the Milan surveillance company that sells spyware to governments (some of them the kind of governments you really dont want owning spyware). Buried in that dump were multiple previously unknown Flash Player exploits the company had apparently been sitting on and selling access to. Adobe pushed an emergency patch yesterday for one of them, CVE-2015-5119, and I'd bet money there's at least one more coming before the month is out.

Ive been telling anyone who'll listen for over a year now that Flash needs to just be gone, and this is exactly the kind of week that proves it. So instead of another "look how bad this is" post, here's what I actually did about it, in like ten minutes, and you can too.

Chrome

Go to chrome://settings/content, scroll down to Plugins, and switch it from "run automatically" to "click to play" (older versions of Chrome may have this as a checkbox rather than radio buttons, doesnt matter, same idea). Once thats on, Flash content on a page shows up as a gray box with a puzzle piece icon instead of just running. Click it if you actually want it, ignore it if you dont. Most ads never get clicked, which is the whole point.

Firefox

Type about:config in the address bar, click through the "here be dragons" warning, and search for plugins.click_to_play. Flip it to true. Or if you dont like poking around in about:config, go to Options > Applications, find Shockwave Flash in the list, and set the action to "Ask to Activate" instead of "Always Activate." Same result, friendlier menu.

Safari

Preferences > Security > Plug-in Settings, then find Flash in the list and set it to "Ask" instead of "On." Its been in there for a while, most people just never open that pane.

None of this breaks the sites that still need Flash, it just stops it from firing without you asking it to. And pair it with an ad blocker if you can stand the moral complexity of that decision (I use uBlock Origin, its light and doesnt eat your CPU the way some of the older ones did) because a huge chunk of these exploits get delivered through ad networks, not the sites themselves. You can visit a completely reputable site and still get served a malicious ad that tries to run a Flash exploit through the ad slot. The site did nothing wrong. The ad network is the problem, and ad networks are basically the digital equivalent of leaving your front door unlocked because the landlord promised the building has security.

The annoying part, and this is my actual complaint for the week, is that there are still sites out there that flat out require Flash for basic functionality and give you no alternative. I had to log into an old freelance timesheet portal a couple months back that literally would not render the hours grid without Flash enabled, no fallback, nothing. Somebody built that in like 2011 and nobody has touched it since. Click-to-play means I can turn Flash on for that one specific site and leave it off everywhere else, which is really the only sane way to run a browser in July 2015. Whitelist the handful of things you actually trust, block everything else by default.

Its not a complicated fix. It takes ten minutes, it doesnt cost anything, and it means the next time some surveillance vendor gets hacked and dumps a pile of zero-days onto the internet, you're not sitting there as exposed as you were yesterday morning. Do it now, not after the next patch Tuesday reminds you that you meant to.