From Pine View Farm

Lay off the Java 2

DHS says turn off your java. It can’t be trusted.

The U.S. Department of Homeland Security urged computer users to disable Oracle Corp’s Java software, amplifying security experts’ prior warnings to hundreds of millions of consumers and businesses that use it to surf the Web.

Hackers have figured out how to exploit Java to install malicious software enabling them to commit crimes ranging from identity theft to making an infected computer part of an ad-hoc network of computers that can be used to attack websites.

Oracle does not have a good record on bug fixes.

Remember that “Java” and “Javascript” are not the same thing. Javascript is not implicated in the warning.

More at the link.

Share

2 comments

  1. George Smith

    January 12, 2013 at 5:38 pm

    Interesting, figured it was coming. That does break some things. I do a lot of YouTube and use Opera. If you disable Java in my version, YouTube gives you an error msg but can be forced to play anyway. Plays wonky, though. Could be the Opera implementation of turning it off. Not sufficiently curious to track it down. I work in a virtual sandbox, though, so it doesn’t really matter how wretched the security holes are in whatever’s running. Just another demonstration that there’s now no way to make a new secure environment. The trouble’s too deep and built up over too many years.

     
  2. Frank

    January 12, 2013 at 6:06 pm

    I have javascript enabled in Opera and I run the NotScript extension.  

    There is a java library in /usr/share/java that has three *.jar files.  There’s no evidence I can find that YouTube calls them.  This in on Slackware.

    Maybe I’ll try removing Java from my Windows computer and seeing what happens the next time I get around to booting it out of Linux Mint.

     
From Pine View Farm
Privacy Policy

This website does not track you.

It contains no private information. It does not drop persistent cookies, does not collect data other than incoming ip addresses and page views (the internet is a public place), and certainly does not collect and sell your information to others.

Some sites that I link to may try to track you, but that's between you and them, not you and me.

I do collect statistics, but I use a simple stand-alone Wordpress plugin, not third-party services such as Google Analitics over which I have no control.

Finally, this is website is a hobby. It's a hobby in which I am deeply invested, about which I care deeply, and which has enabled me to learn a lot about computers and computing, but it is still ultimately an avocation, not a vocation; it is certainly not a money-making enterprise (unless you click the "Donate" button--go ahead, you can be the first!).

I appreciate your visiting this site, and I desire not to violate your trust.