Facebook computers compromised by zero-day Java exploit
arstechnica.com
arstechnica.com
I'd like to think that we're almost to the point of viewing Java in the same light as Bonzi Buddy or Comet Cursor; IT discovers you got Java on your computer again, they just sigh and re-image it, with some stern warnings to please not download such sketchy software.
Ahh to be 11yrs old again...
Large companies tend to have important enterprise applications that require Java to run and, even worse, in some cases upgrading the version of Java on the user's desktop will break the application. You then end up with hundreds or thousands or users with vulnerable versions of Java on the PC that you can't upgrade until the software vendor fixes whatever is wrong with their application.
I've seen it countless times at my previous job (.edu with 1000s of staff and faculty) where we were basically helpless to do anything because absolutely critical applications would break if we upgraded Java on the desktop.
Solution: closely monitor traffic to/from user's PC's, hope for the best, and re-image when they inevitably got pwned.
Before someone chimes in with the obvious "switch to a different application", it's not that easy when you have millions invested and training the user base sometimes takes months.
Yeah, I hate Java.
What about C and C++ induced security holes?
In Chrome: go to chrome://plugins and disable all
Safari: Preferences, Security uncheck 'Enable Plugins'
Firefox: Tools > Addons > Plugins Tab > disable all
Don't use Flashblock or Javablock or similar extensions, they hide the applet, they don't stop execution.
You should always use a browser with all plugins disabled as your default browser. Run a second browser for trusted sites where you enter the URL in yourself.
IMO all browsers should implement 'click to run' by default for all plugins on all sites
If you happen to have the newest Java version which hasn't been publicly announced as exploitable, it will not be blocked unless you enable `plugins.click_to_play` in `about:config`.
Anyway it's still a very good move from Mozilla side to minimize the risks.
I don't like the monolithic design of modern browsers - it is rendering engine, javascript interpreter, sandbox, audio, video, webgl, user management, local store etc. all in one big heap.
We will need features to let users swap parts out, highly customize them, apply advanced ACL's to each component (since the browser becomes the new OS) and disable them (chrome://flags)
Apple also has a poor record at security patching, which allows for more drive by downloads, especially through Java. Further reading: http://voices.washingtonpost.com/securityfix/2009/06/apple_p... http://krebsonsecurity.com/tag/mac/
As for instances where they have not preserved support and compatibility, Silverlight comes to mind, and they dumped that largely in favour of frameworks targeting HTML+JS.
(I'm not a Microsoft employee, just a user who appreciates the APIs I cut my teeth on 20 years ago remain applicable today)
| when the thick layers of gelatinous hivemind diatribe
| are pealed away what's left are sound, conscientious
| engineering decisions
Like waiting years to take security seriously? :PSo it may be a legitimate concern (only blown out of proportion)
It doesn't seem to be holding up too well against normal use, never mind deliberate attempts to exploit it: it's not uncommon for WebGL demos to crash at least one browser/hardware combo. Example from the last WebGL submission I read a few days ago: http://news.ycombinator.com/item?id=5211211
Wow, thanks. I was under the (false, obviously) impression that Flashblock effectively turned Flash objects into "click-to-run".
The OP is wrong about this. At least for Safari/ClickToPlugin – I just verified it myself. After all, it'd be fairly pointless otherwise...
Chrome extensions are nothing more than loading a JS file onload
Go to chrome://chrome/settings/content and look under plug-ins. There is Run automatically (default), Click to play and Block all.
I'd rather have complete separation
Doing a proof-of-concept on a 'click to play' to run a plugin is something that I have been meaning to do
Moreover, you have to right-click and then click "Run this plugin" from the native Chrome menu. I doubt you can create any overlay over native browser's menu.
It must be different on Windows. I have it enabled on my Mac and it requires a single click to enable a plug-in.
For Flashblock on Firefox, at least, this is incorrect. And if it were true, you would lose the main benefits of using Flashblock to begin with: better security, privacy, lower CPU and memory use. Which makes using such a plugin rather pointless, so I doubt any blocking plugin works this way.
That sounds like an assumption based on how you would implement it. Until Chrome implemented its native click to play, most of "click to play" plugins were targeted at advertising and simply blocked visual rendering and audio playback. It's not for lack of trying, the underlying framework for the plugin to stop execution simply didn't exist.
Go to chrome://chrome/settings/content and look under plug-ins. There is Run automatically (default), Click to play and Block all.
about:config, search for "plugins.click_to_play". Enable!
To enable all plugins on page, click the play/puzzle icon in the address bar. To permanently enable plugins on certain pages: right click -> Edit site preferences... -> Content.
I have this enabled both in Opera and in Chrome. Certain sites are permanently whitelisted. Much better browsing experience.
> "The attack was injected into the site's HTML, so any engineer who visited the site and had Java enabled in their browser would have been affected," Sullivan told Ars, "regardless of how patched their machine was."
It seems it's high time now to start working with two separate profiles in a browser if you're forced to use Java - one internal-only with Java enabled, and the second for browsing the internet, with Java disabled (of course this works as long as your internal apps do not get hacked...).
Rather easy to achieve with Firefox (probably there are command line switches for Chrome as well):
1. Create two profiles, `external` and `internal`, using `firefox -p`
2. Open external profile and disable Java (will be kept in profile settings)
Then, run first `firefox -p external`, then `firefox -no-remote -p internal`, that way links opened e.g. from email clients will go to the external instance.
To differentiate the two instances, you can install some theme: http://www.getpersonas.com/en-US/
Total paranoiacs could try to find/write some extension that will block all the pages other than approved internal ones in the internal profile (perhaps AdBlock Plus will do?).
I know I can turn on `plugins.click_to_play` in general, but that's hardly convenient.
Noscript even let's you block webgl depending on if the site is whitelisted/blacklisted.
The great thing about RP is that you can let some sites make requests to facebook (for instance, nothing special about FB) and not allow all other sites to make requests to facebook.
The hole in question was patched in the February 1st Java release.
This is news because it shows how Facebook was affected by the many unaddressed security holes that were present in Java (and how it could be run -- last month -- silently), but this is NOT news of new holes in Java.
So far the latest (quite significant) fixes seem to have been effective.
It's criminal how Oracle can release production code with so many security holes. It seems like every week there is a new new Java based exploit.
But that is only half of the way, because thanks to C and C++ runtimes, they are still open to security exploits triggered by buffer overflows, strings misuse, use after free, double deallocation, array access out of bounds, stack overflow, pointer misuse...
The only safe way is to use a separate VM for browsing, or failing that, run the browser under a different user account with limited user rights.
I run Windows 7 and Server 2012 along with various versions SQL Server in VMWare on a Ubuntu host with no issues.
How can one find out if one has been infected?
Perhaps there is a mole at Oracle leaking security holes elsewhere.
Company-wide install of NoScript? But that wouldn't save you if a trusted site got compromised.
Maybe they should prohibit use of all commonly targeted software? (Flash, Acrobat Reader, Java..)
This seems really serious. Surely someone must be working on a better way to protect against this kind of thing?
1. Acrobat Reader plugin: use some less popular PDF reader which is not that commonly attacked
2. Flash: you shouldn't play Flash games in the office ;) For Youtube, you can enable HTML5 version in modern browsers
3. Java: IMO it's mostly needed in IE6-dating web apps but I might be very naive here...
Regarding Acrobat: there's a built-in PDF reader coming in Firefox soon (pdfjs). Currently I do not use any plugin, just make the browser download a PDF and render it in SumatraPDF or PDF Xchange Viewer.
That is not really relevant to a browser plugin. You can download and fill in PDFs with whatever application you like without browser plugins.
"Hopefully they intend to make it federated though, rather than keeping it Facebook-only."
What part of Facebook's history suggests that they wouldn't make it tied to a Facebook account?
Web browsers sometimes have bugs like this. I believe iPhone 1.1 had a bug in TIFF images that people used to jail break the phone
Yep, there was a buffer overflow in the libtiff. http://theiphonewiki.com/wiki/LibTiff_Exploit
VM software is often free and extremely useful anyway for developers or security.
Also this must be (more) very negative pr to Oracle
First, yes, Java is that prevalent. There's no a single corporate company out there were there's not Java devs. As simple as that. Then Java is also on so many systems even outside the corporate world: both Windows on OS X. It's typically not there by default but on Windows it depends on who ships the machine. On OS X now at least they don't ship it by default but it's trivial to install.
But really the problem ain't Java but Java applets.
Java as in "The JVM" is actually not bad at all on the server side: on the contrary, it's very robust. There are have been two very lame exploits in 2011 allowing Denial of Services on Java webservers, but no remote exploit working on Java servers.
The problem is Java on the client-side: i.e. on people's computers. In other word: the issue is pathetically lame Java applets.
Java applets have to be the most stupid, silly and insecure lame technology ever invented by Sun.
You should have been there in comp.lang.java.programmer back in the nineties when people were saying how stupid, silly and insecure a lame tech Java applets were... Only to be laughed at by the like of Jon Skeet (the most upvoted user today on StackOverflow). To most Java early adopters Java applets were "the nuts". Supposedly the one tech going to solve all our problems.
It "only" took close to 15 years to prove wrong all the retards who thought Java applets were a good thing.
And now we're in this big mess.
For end-users it's easy: remove Java or disable Java applets.
But for the corporate world it's not so simple: many devs are, well, Java devs. Because Java is pretty much what powers the corporate world (hint: no, it's not Excel).
Then even if most apps tend to be webapps now, there are still a lot of in-house apps which are Java apps and corporate drones do need to use these apps.
Then there are all the Android / dalvik devs: world is moving to mobile and Android is huge. Hence Java is huge.
Hence you can count on many, many, many more Java exploits being used to infiltrate companies.
Companies whose users / devs are using very poor security practices anyway.
Don't know about you but I find it fascinating how many comments fail to make a distinction between the vulnerable 'javaws' (i.e., applets) and the far more common 'java' vm. This 'mistake' illustrates both java competitor astroturfing and simple ignorance on the part of those commenting. Are there other potential reasons so many don't know or intentionally obfuscate the difference between java and javaws?
Many don't even make a difference between Java the language and Java the VM with all its multiple implementations from vendors all around the World.
This security exploits most of the time are only relevant to Oracle's VM.
People should really all consider doing what I do: install a throwaway VM on your system from which you surf the Web. For all the sites that I don't trust I do surf from a VM which can be erased / re-installed at will.
For sites I trust, like my GMail / Google Docs, I surf from a separate user account. I'm using a firewall that can do "per user" rules and I'm only using whitelists. By default no packets can be emitted. Then the user account used to access GMail / Google Docs is configured so that it can emit HTTP/HTTPS trafic.
No Java in the user accounts / VM that do surf the Web: and I'm a "Java" dev (Java + Clojure). Java can be installed only for one user account on Linux, without needing to be root.
Wanna do online banking / MoneyBookers / etc.: boot a read-only Linux CD / DVD.
Yes, it is slightly more inconvenient than using your main user account to surf the Web. But so far security and conveniency haven't exactly been good matches yet.
The state of security today is really terribly bad. It is so bad that I'm going back to a "stupid" Nokia S40 phone until things settle down.
That's not just inconvenient, it's verging on paranoia. Most people haven't got the time or the processor cycles to spare to run a separate VM. What's wrong with just disabling plugins for all but trusted sites?
Processor cycles? If I run Firefox inside a Windows VM on my MBP it's faster than the native version.
Seems like a good convenience/security tradeoff to me.
In case some people don't know it: http://www.qubes-os.org
Hard to find details on that, anyone know?