Ship Mint 17.3+ with Adobe Flash disabled or click-to-play by default

Bug #1475031 reported by deutrino
10
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Linux Mint
New
Undecided
Unassigned

Bug Description

In light of the Hacking Team disclosures, multiple Adobe Flash 0-days in the wild, and moves by major browser developers and content providers to deprecate Flash, I believe Mint 17.3+ should ship with Flash disabled (or set to click-to-play at a minimum) in at least the following packages, if not more:

* Chromium
* Firefox
* any other web browsers capable of using Flash

I am not sure why Steam requires Flash. It's probably not worth investigating though.

Flash has long been on its way out, most web sites work without it and many of the stragglers will be cleaned up in the next 6 months. Its usefulness is declining rapidly but it presents a huge attack surface when browsing the web.

Please help usher Flash into the dustbin of history by disabling per default in Mint 17.3+.

Tags: security
deutrino (deutrino)
tags: added: security
Revision history for this message
Jens Reimann (ctron) wrote :

Or at least provide a simple way to uninstall flash. Removing the package "adobe-flashplugin" automatically triggers a removal of "mint-meta-codec" which you probably do not want to uninstall. So maybe remove it at least as a hard dependency.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.