Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The ratio between legitimate uses of the quicktime plugin that aren't otherwise covered by chrome, and attempts to exploit the cavalcade of bugs that are regularly developed for it must be quite low indeed. I have no problem believing this is due to security concerns, and I applaud them for making the move. Blindly running plugins that have a history like QT is very poor behavior. Hopefully they will be flagging oracle java for similar treatment soon.

To be clear, you simply have to manually enable QT for a domain you want it to run. All plugins should be set to run this way - "do you trust this domain?". It would cut down on 90% of drive by exploitations where the user never even sees the malicious iframe and has no idea that they visited the domain hosting the exploit code.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: