Linked by Amjith Ramanujam on Sat 19th Jul 2008 19:01 UTC, submitted by cypress
Thread beginning with comment 323989
To view parent comment, click here.
To read all comments associated with this story, please click here.
To view parent comment, click here.
To read all comments associated with this story, please click here.





Member since:
2006-01-06
These are fairly irrelevant differences, though, because the basic idea is that someone can install native code which runs in both Firefox and IE. It really doesn't matter whether that code runs from the Firefox plugin directory or from some random place on the hard drive. Maybe it makes you "feel better" to think that the code is somehow sandboxed in the plug-in directory, but it can do just as much (and more) damage as any ActiveX control. I know that people find plug-ins/controls useful; however, the only really secure approach is to turn them off completely. Which will (understandably) break some usage scenarios. But those kinds of tradeoffs are the price for better security.