It seems like the logic could be similar to our pop up blocker. If the plugin 
is shown or created by a user action, we could play it by default.


On 2012-04-06, at 7:18 PM, Jet Villegas wrote:

> We're talking about multiple domains here: the container (eg. 
> and the content (eg.,, etc.) I'm not sure if 
> we need to support fine-grained controls over both types of domains here, or 
> simply allow plug-in content to play back immediately when a click is 
> received on the container. We'll have to try different approaches here and go 
> with what makes the best sense.
> -- Jet
> ----- Original Message -----
> From: "Ian Melven" <>
> To: "Jet Villegas" <>
> Cc: "security-group group" <>, 
> Sent: Friday, April 6, 2012 3:57:36 PM
> Subject: Re: Opt-in activation for plugins (aka click to play)
> My opinion is that click to play absolutely should have an easy 'always allow 
> plugins to play on this domain'
> option for the user for cases like this - this should be persisted unless the 
> user decides to explicitly
> revoke it. Would that address your concern ? 
> thanks,
> ian
> ----- Original Message -----
> From: "Jet Villegas" <>
> To: "Lucas Adamski" <>, "Jared Wein" <>
> Cc: "Asa Dotzler" <>, "Kev Needham" <>, 
> "security-group group" <>, "Madhava Enros" 
> <>, "Stephen Horlander" <>, "Justin 
> Dolske" <>,
> Sent: Friday, April 6, 2012 3:13:45 PM
> Subject: Re: Opt-in activation for plugins (aka click to play)
> Sites like Facebook already have an image preview of their Flash links that 
> users already have to click to play. We may need some way to avoid requiring 
> multiple clicks to get at the plug-in content. 
> -- Jet
> ----- Original Message -----
> From: "Lucas Adamski" <>
> To: "Jared Wein" <>
> Cc: "Asa Dotzler" <>, "Kev Needham" <>, 
> "security-group group" <>, "Madhava Enros" 
> <>, "Stephen Horlander" <>, "Justin 
> Dolske" <>,
> Sent: Wednesday, April 4, 2012 2:16:08 PM
> Subject: Re: Opt-in activation for plugins (aka click to play)
> On Apr 2, 2012, at 6:37 PM, Jared Wein wrote:
>>> How would you implement a checkbox in a normal click-to-play
>>> (in-content) experience?
>>> To be clear that's a 30 day sliding window from last time content was
>>> played there.  So if you visit a given site with plugin content (say
>>> at least once every 30 days, you conceivably should not
>>> see that prompt again unless you become vulnerable to a security
>>> issue.
>> We can put checkboxes in the plugin overlay, similar to what we have for 
>> crashed plugins. When the overlay is too small to use we can add secondary 
>> options in the doorhanger dropdown for users to choose to remember the 
>> settings.
> Ah ok, makes sense.  I'd love to get UX feedback here on these respective 
> proposals (implicit persistence of permission on a sliding time window vs 
> explicit checkbox in overlay).  Thanks!
>  Lucas.
> _______________________________________________
> Security-group mailing list
> _______________________________________________
> Security-group mailing list
> _______________________________________________
> Security-group mailing list

dev-security mailing list

Reply via email to