0: http://www.kanai.net/weblog/archive/2007/01/26/00h53m55s
1: http://blog.mozilla.org/gen/2012/05/29/browser-competition-i...
if(typeof(navigator.appName)=='undefined' || navigator.userAgent.indexOf("MSIE")<0) {
top.wgmain.location.href='about:blank';
alert('Microsoft Internet Explorer 사용자만 사용가능합니다.');
return false;
}> Microsoft Internet Explorer 사용자만 사용가능합니다.
Translation: Only Microsoft Internet Explorer users can use the site.
One example of one who manages to get authentication right, through HTML alone is Skandiabanken. No Java, nonsense or security pains required. They allow you to use BankID too if you like to, but you don't have to.
I prefer not to.
An alternative solution would be to use an SSL client certificate[3] or the WebCrypto[4] API (still under development).
[1] http://security.stackexchange.com/questions/3605/certificate...
[2] http://en.wikipedia.org/wiki/Public-key_infrastructure
[3] http://www.mozilla.org/projects/security/pki/psm/help_21/glo...
that's even (slightly) worse than a java applet.
They are all highly regulated and with very little incentive to innovate. So they can screw around and do pretty much nothing at all. The fascist/socialist banking system that exists across the globe is even more pronounced here.
For those of you that can read portuguese, I recommend this article: http://www.mises.org.br/Article.aspx?id=1387
I have accounts on three banks that work well with Ubuntu and Firefox. Only one of them mandates a Java runtime to be installed (and only enforces the requirement on Windows and OSX).
If you are to promote mobile apps, why not go for the big platform, Android?
They've definitely used this to block older Java versions, but in those cases there was always a newer version available that you could use instead.
For out-of-date and perennially vulnerable plugins (like Java) Chrome uses the second mode, which blocks the plugin unless the user accepts it through an infobar. It's not a perfect defense, but we've found it to be extremely effective at preventing exploits because the vast majority of the users don't let the potentially vulnerable plugin run. I'd really like to see this approach catch on more broadly, but other browser makers are understandably cautious about how they should handle plugins.
We often have slightly out of date plugins, simply because it takes a while to get new versions tested and rolled out. When Firefox blocks them it breaks functionality and can cause a few awkward problems. Generally that just means that the user will use IE instead, so the protection is lost.
You can go to "about:config" and enable the option "plugins.click_to_play" if you want to see it. I disabled it as it caused issues with Flash for me, but I've straight up disabled the Java plugin anyway.
I don't trust my bank with a signed applet (why the hell do they need that?), so obviously I only access my internet banking using a VM.
Smart thing to do. Also, you can make the VM disk reset itself to a base state on every boot.
I understand from other comments that banks in some require Java. I have or have had accounts or credit cards with nearly all major banks in the USA and many smaller institutions and none have required any plugins. Some require 3rd party cookies to use services like bill pay or ACH transfers.
On the other hand, I'm pretty sure my browser asks me every time it wants to run an applet, so I think that as current behavior is fine.
But yeah, I take your point.