'Java is a mess. It's not secure. You have to disable it'
ibnlive.in.com
ibnlive.in.com
Here is the original article (with quote) from Reuters: http://www.reuters.com/article/2013/01/10/us-java-security-i...
So much Internet "journalism" is simply a summarising of stories from other sources, in the name of "curation". Please post original source when possible folks. /rant
It is an abomination of ancient times (and imho worse than flash).
But the article totally neglects that Java != the Java plugin. Yes, Java has bugs and I ran into most of them being a Java developer for years now, but it still is a very solid (if clumsy and inconvenient) system to build your applications upon.
Certain online banks (almost every single one in Norway) require an Java applet for two-factor authentication, so uninstalling the plugin is simply not an option.
Most modern browsers (atleast Chrome) require the user to whitelist domains where applets are allowed to run. In addition, applets that contain a digital signature will notify you that it has been verified and you are given a choice wheter you want to run it.
And as others have mentioned: Java and the Java browser plugin are not the same thing.
All software has bugs and security holes. The thing is that we haven't found them all. Its a constant game of cat and mouse which will never end.
Java has had a lot of bad press recently, but that doesn't suddenly make it useless. In fact, all it does is improve it as an identified hole is usually a fixed hole.
What is happening at the moment is that instead of reporting these issues to the vendor and giving them time to fix, people are throwing stuff out into the wild immediately for either fame or fortune.
The real issue here is an ethical one I.e the ethics are non existent for a recently larger proportion of the hacking community. Perhaps a bold statement, but they give all of us a bad name and should be chucked in jail.