Opt-in activation for plugins: Difference between revisions

Jump to navigation Jump to search
no edit summary
No edit summary
No edit summary
Line 71: Line 71:
* Manage plugin run settings on a per-site basis
* Manage plugin run settings on a per-site basis
* Control plugins on a per-plugin basis for a given site
* Control plugins on a per-plugin basis for a given site
* Mitigate attacks where user chooses to interact with site (clickjacking, or simply wants to run vulnerable plugin)
* Mitigate attacks where user interacts with site (clickjacking, or simply wants to run vulnerable plugin)
|Feature non-goals=We can't prevent users getting owned up by vulnerable plugins if they choose to activate a plugin on a site hosting malicious payloads.  That is why driving plugin updates is important.
|Feature non-goals=We can't prevent users getting owned up by vulnerable plugins if they choose to activate a plugin on a site hosting malicious payloads.  That is why driving plugin updates is important.
|Feature ux design=When plugins are found on a page, their start up will be delayed until a user performs interaction with the browser to enable the running of the plugin.
|Feature ux design=When plugins are found on a page, their start up will be delayed until a user performs interaction with the browser to enable the running of the plugin.
Confirmed users
717

edits

Navigation menu