Firefox/Click To Play: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
(Link up tracked bugs where appropriate)
(fix links, clarify)
Line 22: Line 22:
User research study: testing the user reaction and experience when Flash is made click-to-play:
User research study: testing the user reaction and experience when Flash is made click-to-play:


* Tracked bugs: [https://bugzilla.mozilla.org/buglist.cgi?status_whiteboard_type=allwordssubstr;status_whiteboard=[CtPUR%3A%2B];resolution=---;resolution=DUPLICATE;query_format=advanced CtPUR:+ in the whiteboard]
* Tracked bugs: [https://bugzilla.mozilla.org/buglist.cgi?status_whiteboard_type=allwordssubstr;status_whiteboard=CtPUR%3A%2B;resolution=---;resolution=DUPLICATE;query_format=advanced CtPUR:+ in the whiteboard]. This list triaged and maintained by bsmedberg.


Turning on click-to-play by default:
Turning on click-to-play by default:


* Tracked bugs: [https://bugzilla.mozilla.org/buglist.cgi?status_whiteboard_type=allwordssubstr;status_whiteboard=CtpDefault%3AP;resolution=---;resolution=DUPLICATE;query_format=advanced CtPDefault:P in the whiteboard]
* Tracked bugs: [https://bugzilla.mozilla.org/buglist.cgi?status_whiteboard_type=allwordssubstr;status_whiteboard=CtpDefault%3AP;resolution=---;resolution=DUPLICATE;query_format=advanced CtPDefault:P in the whiteboard]. This list triaged and maintained by bsmedberg.


Security Improvements for blocked plugins:
Security Improvements for blocked plugins:


* Primarily this means making the UI non-clickjackable for known-insecure plugins, and is tracked in {{bug|832481}}
* Primarily this means making the UI non-clickjackable for known-insecure plugins, and is tracked in {{bug|832481}}.


Usability Improvements (for security-blocked and CtP-by-default plugins):
Usability Improvements (for security-blocked and CtP-by-default plugins):

Revision as of 16:19, 2 February 2013

Contact Points

  • Michael Coates
  • Alex Keybl (release priority, monitoring enterprise feedback)
  • David Keeler (Security Engineering, wrote CTP code)
  • Justin Dolske & Jared Wein (Firefox frontend engineering)
  • Benjamin Smedberg & Georg Fritzsche (Stability/Plugins Engineering)
  • Matthew Grimes (User Advocacy team)
  • Mary Trombley (User Research on CTP)
  • Dan Veditz
  • Stephen Horlander (Visual Design)
  • Larissa Co (User Experience)

Communication

Items Under Development

User research study: testing the user reaction and experience when Flash is made click-to-play:

Turning on click-to-play by default:

Security Improvements for blocked plugins:

  • Primarily this means making the UI non-clickjackable for known-insecure plugins, and is tracked in bug 832481.

Usability Improvements (for security-blocked and CtP-by-default plugins):

  • will be refined based on data from the user research study. It is very likely that we will need to implement bug 834749 or something like it to make "always for this site a more prominent option (perhaps the most prominent option).
  • The doorhanger itself may also need to be refined
  • The behavior of the doorhanger/notifications when small/hidden plugins are present may need work. This especially impacts sites that use plugins to play audio or do special processing (file upload controls that use Flash can also be affected)

Feedback to Prioritize

https://etherpad.mozilla.org/CTP-feedback

Links

Flash Population Data

  • [1/29] Blocking 0-10.2.*: ~2.8% of users will be CTP
  • Blocking non-current 10.3.*: ~2.47%
  • Blocking 11.0.*-11.2.*: ~6.9%
  • Blocking 11.3.*-11.4.*: ~4.5%
  • Blocking non-current 11.5.*: ~7.4%

Flash Uptake Data

  • ~1/7 (.146 released) - 11.5.502.135 is 77.8% of our population
  • ~1/14 - 11.5.502.146 is 68.9% of our population
  • 1/28 - 11.5.502.146 is 75.9% of our population

So in 1 week, ~89% of users who are automatically updating get on the latest version. After 2 weeks, 97.5% of users are automatically updated.

Current proposal for blocking non-current versions of Flash:

  • 2 weeks must pass since the latest release
  • previous_minor_version_population/(previous_minor_version_population+current_minor_verison_population) must be less than 5%

Planned UX Changes

Several UX changes are planned to refine the CTP experience. A few notes:

  • We won't be using the terminology that there is a security risk with a plugin unless it is actually the situation
  • We're exploring the best way to highlight/make visible the "always enable plugins" for this site option