If you need Java, use this one instead
zdnet.com
zdnet.com
Rather than targeting the JRE itself, I would be looking for vulnerabilities in the shovelware -- which is subject to less scrutiny by developers than the language runtime itself, and which is only installed by users whose security practices are less than perfect.
Before this recent patch, that code would be executed without even prompting the user.
Sure, there's a sandbox, but (as we know) sometimes a sandbox has cracks, particularly when the runtime is designed to let code to only enforce the sandbox for some code it runs, not all. (Compare to JavaScript execution, which also runs downloaded code without prompting, but JS in the browser is always in the sandbox -- there are things it simply can't do, vs. Java's "this is do-able but not for you".
There are a lot of companies who would love to take out Oracle.
I'm not a fan of Oracle or anything, but I have worked for enough big companies (Oracle's paying clients) to see that this won't matter at all to Oracle's bottomline. And probably not much to their reputation either; I used to run OpenJDK on my smaller devices like my pandora; Oracle made an ARM version of the closed source JDK. Now I really want to use open source, but that binary brought tears to my eyes; it's blazingly fast, seems to use less memory than the other versions, is stable compared to openjdk and it showed that Java indeed is in the hands of Larry fully. There is no other option for Java and JVM languages.
How about the day it doesn't prompt you and installs it anyway...
> 64-bit Windows operating systems (which may be Windows 7, Vista or XP) come with a 32-bit Internet Explorer (IE) browser as the standard (default) for viewing web pages. These operating systems also include a 64-bit Internet Explorer browser, however using it is optional and it must be explicitly selected to view web pages. Note that because some web content may not work properly in a 64-bit browser, we recommend using the default 32-bit browser and downloading 32-bit Java.
More details: http://www.java.com/en/download/faq/java_win64bit.xml
If you're doing development, well then shame on you for not already knowing what you need. You also probably won't want the JRE, you'll want the JDK, which doesn't come with the shovelware anyway.
If you're a developer and you just need to run some Java utilities, then you'll probably be fine with the 32-bit JRE.
Basically, if you really need the 64-bit version, you probably already know it.
How will it work? Candidate applications will be submitted via a simple web site, evaluated by Sun for safety and content, then presented under free or fee terms to the broad Java audience via our update mechanism. Over time, developers will bid for position on our storefront, and the relationships won't be exclusive (as they have been for search). As with other app stores, Sun will charge for distribution - but unlike other app stores, whose audiences are tiny, measured in the millions or tens of millions, ours will have what we estimate to be approximately a billion users. That's clearly a lot of traffic, and will position the Java App Store as having just about the world's largest audience.
Java on the desktop failed because of .Net, because the UI widgets on Java looks horrible and nothing like the OS, and because Sun wasn't a consumer focused company and neither is Oracle.
And all it took was a little user-focus and design work. Never happened. Very shortsighted IMHO, but I also believe it was not possible at Sun or Oracle. Just not in their nature.
6 brought with it a much faster UI experience. Unfortunately that happened after the transition of apps from the desktop to the web. So you had slow applet downloads vs Flash on the client. You also had compatibility issues that were more involved than Flash.
Finally, other cross platform frame works like Qt came along. Now you'd get closer native appearance with languages other than Java.
As a result of the confluence of events and changes Java became relegated to server or phone side.
Not true. wxWidgets predates Java, it is cross platform and it does provide a real native appearance. Not emulation, true native widgets.
Browser plugin issues not-withstanding, of course. But who uses Java in a browser anymore?
Webex and GoToMyPC unfortunately. Makes it rather hard to work from home when those are your corporate standards.
There's nothing else as powerful AFAIK.
Java's security problems seem like they'll kill this off, unfortunately.
That said, if your platform lacks an installer and -more importantly- an updater, OpenJDK is not a good alternative. There's no reason to assume it is any more secure than the Oracle package except for the lack of additional toolbars.
I wish JetBrains was compatible with OpenJDK, it's the only reason why I still bother installing Oracle Java.
http://forums.linuxmint.com/viewtopic.php?t=93052&f=42
http://www.upubuntu.com/2012/10/how-to-install-oracle-java-7...
Certainly no "apt-get install whatever-jdk" for me. No, thank you very much. I want to be in control.
So I install the JRE (or JDK) in a user account and, once the .tar.gz file is decompressed/dearchived I do remove the unnecessary crap (examples, applets, etc.).
That's one big advantage right there about not needing to have admin rights to install: you know where all the files have been installed (in the user account, it's not possible to write anywhere else without being root) and you have more control on the crap.
That's not really possible to do as conveniently on Windows seen that you must have admin rights to install Java on Windows.
We even go as far as creating a new user account, deploying a JVM to it and wiping down during our build process so we get a consistent environment every time.