JDK 7u11 Release Notes
oracle.com
oracle.com
1) Open Java Control Panel, see it says I have an update. Click "OK".
2) Reopen Java Control Panel because OK closes the window. This time click "Update Now"
3) After downloading 50MB another installer opens. Notice that it says 7u10 and not 7u11 (I was running 7u9).
4) Look back at Java Control Panel and see that it claims "Java Update was last run at 5:03 PM".
5) Reopen the JCP several times to try to force it to recognize that 7u11 is the latest, not 7u10.
6) Give up and install 7u10
7) Reopen JCP yet again. Success, 7u11 is available!
8) Click "Update Now" (not falling for your tricks again "OK" button)
10) Curse and post this.
1) Be notified of an update through the automatically running update check (probably with weak crypto and verification, given their track record...)
2) Clicking launches the MSI installer
3) "Java is wasting cycles on 6 billion (right now) insecure devices. Update now."
4) Remember to uncheck the Ask.com toolbar installer (Are you even trying at this point Oracle? Just kill it outright)
5) Installing
6) "Remember, Java is awesome, and for the moment its secure again"
(Not a comparison, just to make the point that the "experience" is equally great on the other side)
I have 3 different JDKs installed at the moment.
Unfortunate that they're dragging their feet on this.
1. Run "Ninite Java installer.exe".
2. Control panel -> Programs and Features -> Uninstall any old versions, if applicable.
If anyone on Windows doesn't know about www.ninite.com, it's probably worth your time to take a look.
I am happy for one thing. After having used the Control Panel feature introduced in 7u10 to allow disabling Java in all browsers via one checkbox, when I ran the 7u11 update and subsequently -- carefully! -- checked, I found that Java remained disabled in all the browsers on the system.
Hallelujah! Finally -- much too late, IMO -- one can apparently (I'd continue to manually verify, for the near if not foreseeable future) disable Java in the browser(s), and the setting sticks.
Prior to this, after each update, I'd have to go into all the browsers on the system and manually disable the Java plugins -- at least I had to until some, but not all, of the browser makers got smart and started ensuring that disabled Java plugins remained disabled, despite the Java installer's attempts.
And even disabling the browser plug-ins was apparently not sufficient, for IE:
http://krebsonsecurity.com/how-to-unplug-java-from-the-brows...
(see the section on Internet Explorer)
That when, next month, the next 0-day exploit targetting Java applets comes out you'll be safe.
It only disable applets, nothing else.
Wish people would cut Oracle a little slack here, although they really need to improve the Java update process. They could and should learn something from Flash (as depressing as that is to say!)
Ideally java/flash plugins will die quickly, and we can replace them with browser native technology that we can hold the browser manufacturers accountable for.
I don't know why you would think browser native technology will be any more secure. Java and Flash aren't heavily exploited because they're worse than other products - they're exploited because they're ubiquitous. And it's not like we don't have manufacturers to hold accountable here, whatever that means.
Security is hard. It's really, really, really hard to add new functionality without leaving a chink in your security armor. This cycle of 0-day exploits is not going away even when Flash and Java are only discussed in nursing homes.
Maybe you're right, we'll see. That having been said, again, with Chrome's track record, update schedule, update mechanics and more, I'm trusting them a huge factor more than Oracle. Also, keeping in mind that having different implementations across 2-3 major web browsers dampens the effect of having an exploit in one.
At some point I'm going to have to bite the bullet and switch everything to HTML5, but applets are failing faster than cross-browser native power is advancing, sadly.
I'm close to being able to do pitch detection in the browser (it's just a question of getting the code polished & integrated into features, not any tech hurdles; it already works), but that'll be toast for at least a few years if I switch.
And I doubt MIDI input will ever be browser-native; I've never even heard whispers about it....
It's a frustrating situation; I just wish it didn't seem like Oracle was so actively hastening the death of the applet.
What we really need is some kind of native virtual machine that can run cross-platform bytecode in the browser.
Someone should make a plugin for this that works with all browsers, it would be genius!
</sarcasm>
(If Oracle improves on the updates, that is, and I'm sure they will, they've got a lot on the roadmap for Java.)
This is a neat idea though!
Sun JRE install once peddled OpenOffice and Google Toolbar, but at least OO is better than Ask. Ugh.
They need to get rid of this, it's an embarrassment.
He had good booze, but otherwise, sort of an asswipe.
Sent the girl home with a police matron.
I am saddened that Google didn't buy Sun. Maybe they'll buy Oracle and the optical barrier over the valley will dissolve and reveal it is actually a portal into Hell.
I don't think being poor or not matters, Java is a gigantic codebase and throwing money at a team doesn't make them code more efficiently. They are doing moderately well at transitioning.
I believe Google ripped Java off hard, and I believe both the ripping off Java and the suing for it were bad moves. Google should have licensed or bought Java and Oracle should have sold it or open-sourced it.
This is why corporate-owned languages are bad, and why Dalvik isn't really any better in the long run.
The best thing, perhaps, would be if HotSpot and OpenJDK were completely community driven all the way down to the release/update/install process, the way IcedTea is.
Hopefully more browsers will stop blocking Java applets by default, as only they seem to be the cause of troubles at this point.