Oracle knew about critical Java flaws since April
theregister.co.uk
theregister.co.uk
Microsoft does not wait for Patch Tuesday when there is a zero day exploit. Or at least not always, as the article implies.
That creates a near-constant stream of updates which is difficult for users & sysadmins to manage, and is why Microsoft and others have a "Patch Tuesday".
(I know that Oracle didn't do that here, but that's what the GP post was talking about)
If the sysadmins know when the patches are coming out then they can schedule downtime in advance and get things patched very soon after they're released.
They have one of the worst records on this. (Is SGI still is business?)
It's merged with Rackable (and called SGI), but I don't think they still support IRIX.
Despite sale of assets and similar names, they're separate companies.
http://searchhub.org/dev/2011/07/28/dont-use-java-7-for-anyt...
I can handle breaking changes if they are community driven; I will not accept excuses for something that is maintained by a large corporation that has the resources and staff to prevent such issues. Oracle is rotting the fish from the head.
Golang, for example, does not use a VM, but it is a managed language.
that's even (slightly) worse than a java applet.
They are all highly regulated and with very little incentive to innovate. So they can screw around and do pretty much nothing at all. The fascist/socialist banking system that exists across the globe is even more pronounced here.
For those of you that can read portuguese, I recommend this article: http://www.mises.org.br/Article.aspx?id=1387
I have accounts on three banks that work well with Ubuntu and Firefox. Only one of them mandates a Java runtime to be installed (and only enforces the requirement on Windows and OSX).
One example of one who manages to get authentication right, through HTML alone is Skandiabanken. No Java, nonsense or security pains required. They allow you to use BankID too if you like to, but you don't have to.
I prefer not to.
If you are to promote mobile apps, why not go for the big platform, Android?
0: http://www.kanai.net/weblog/archive/2007/01/26/00h53m55s
1: http://blog.mozilla.org/gen/2012/05/29/browser-competition-i...
> Microsoft Internet Explorer 사용자만 사용가능합니다.
Translation: Only Microsoft Internet Explorer users can use the site.
if(typeof(navigator.appName)=='undefined' || navigator.userAgent.indexOf("MSIE")<0) {
top.wgmain.location.href='about:blank';
alert('Microsoft Internet Explorer 사용자만 사용가능합니다.');
return false;
}An alternative solution would be to use an SSL client certificate[3] or the WebCrypto[4] API (still under development).
[1] http://security.stackexchange.com/questions/3605/certificate...
[2] http://en.wikipedia.org/wiki/Public-key_infrastructure
[3] http://www.mozilla.org/projects/security/pki/psm/help_21/glo...
I don't trust my bank with a signed applet (why the hell do they need that?), so obviously I only access my internet banking using a VM.
Smart thing to do. Also, you can make the VM disk reset itself to a base state on every boot.
You can go to "about:config" and enable the option "plugins.click_to_play" if you want to see it. I disabled it as it caused issues with Flash for me, but I've straight up disabled the Java plugin anyway.
They've definitely used this to block older Java versions, but in those cases there was always a newer version available that you could use instead.
For out-of-date and perennially vulnerable plugins (like Java) Chrome uses the second mode, which blocks the plugin unless the user accepts it through an infobar. It's not a perfect defense, but we've found it to be extremely effective at preventing exploits because the vast majority of the users don't let the potentially vulnerable plugin run. I'd really like to see this approach catch on more broadly, but other browser makers are understandably cautious about how they should handle plugins.
We often have slightly out of date plugins, simply because it takes a while to get new versions tested and rolled out. When Firefox blocks them it breaks functionality and can cause a few awkward problems. Generally that just means that the user will use IE instead, so the protection is lost.
I understand from other comments that banks in some require Java. I have or have had accounts or credit cards with nearly all major banks in the USA and many smaller institutions and none have required any plugins. Some require 3rd party cookies to use services like bill pay or ACH transfers.
On the other hand, I'm pretty sure my browser asks me every time it wants to run an applet, so I think that as current behavior is fine.
But yeah, I take your point.
In a perfect world bugs won't exist. Less perfect - they will be dealt with as soon as someone notifies the company (and there will be no blame on that someone). Our world isn't perfect, but as an optimist I see many great business opportunities in this.
Not to say that really matters to Oracle, the desktop has never been Java's strong point.
Why woulc Oracle be so tardy in fixing security issues is the big question as it appears there approach recently is:
1) get told of a security issue. 2) ???? 3) Release fix once issue is out in wild/publicly known
Given there history and how they got started and there connections thru large contracts then it is not impossible that they were asked to hold back and/or offered to hold back on a patch. Rememebr security issues are more than that these days, they are after all gradualy replaceing Nuclear weapons as they can be used and abused as the fallout is less unferstood and in that they are not the stand-off weapons which nukes are and given that they are opening up entirly new theartes of war.
Thing is until Oracle explains there delays in addressing recent security issues in there database and now java, then people will and rightly so speculate as to there motivations in acting in the way they have.
[EDIT ADD] some background on Oracles patch approach this year http://www.esecurityplanet.com/network-security/oracle-datab...
Not sure what the final status of their JRockit + Hotspot merge is going to be though.
So forgive me if this is a dumb question: what is the nature of the Oracle closed source extensions? Are they anything I'm going to care about in playing with JVM languages, or deploying apps in a web startup (ie. non-corporate) environment?
For the actual JVM I don't think there is anything big missing, except maybe some support for SPARC. The big question will be what happens in the future when they start merging JRockit with Hotspot. JRockit has quite a few extensions for monitoring that I think Oracle will keep closed (and expensive.)
Note that starting with Java 7, OpenJDK is the reference implementation.
A lot has been written about software liability, but not much has happened (except lots of countries have adopted US style "EULA click through makes a contract" stupidity)
See eg. this article about a staged debate about it between Bruce Schneier and Marcus Ranum at RSA 2012: <http://www.law.com/jsp/lawtechnologynews/PubArticleLTN.jsp?i...;