Richard Brown composed on 2015-07-13 21:00 (UTC+0200):
David Disseldorp wrote:
Considering the seemingly endless stream of CVEs[1], as well as the recent uptake of HTML5 video, I propose that flash-player be removed from the default package install list in future openSUSE releases.
Any thoughts?
I think it's a great idea. We probably want to keep it as an option for those who can't live without, but I think you should opt-in to a package that constantly exploited.
When not installed, users are subjected to constant bombardment about missing plugin. plugins.hide_infobar_for_missing_plugin=true will probably need to be set in default Firefox prefs, and probably a relnote provided. Setting that pref would result in any other missing plugins failing to be announced. There may need to be an upstream change that omits Flash from ever being reported so that that pref setting can remain false until such time as all plugins are no longer supported. -- "The wise are known for their understanding, and pleasant words are persuasive." Proverbs 16:21 (New Living Translation) Team OS/2 ** Reg. Linux User #211409 ** a11y rocks! Felix Miata *** http://fm.no-ip.com/ -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse-factory+owner@opensuse.org