Security of Java takes a dangerous turn for the worse, experts say
arstechnica.com
arstechnica.com
How is this news? The more popular a piece of software is, and the longer a specific version of it has been in use, the more bugs will be found and exploited. Duh?
No, it's just alarmist and mis-leading, the answer is upgrade. That's the answer for Java, Operating Systems (example Windows XP), Smart Phones, it's how software has worked for decades. There's nothing new about it.
Someone got a wild hair and posted a sensationalist title that JavaScript people on HN would like and want to jump on.
So again which one?
Typical enterprise stuff.
You encounter these problems if:
- People write unix-style tools on the JVM (imagine if ls was a Java program). Thankfully almost no one does this, but...
- When you use tooling for things that involve JVM languages, such as Clojure's lein or Scala's sbt. Starting lein / sbt is annoyingly slow. Using Scalaiform to format scala code takes a noticeable chunk of time because it's booting up a jvm each time. So noticeable that as much as I'd like to have it happen every time I save a file it makes SublimeText way too choppy.
This is less noticable on faster computers (my current work box is a i7 laptop with 12GB and an SSD) but on older computers it's still a real pain. Working with Clojure on a 2009MBP can be an exercise in frustration.
There are JVMs on the market that compile to native code, and others that cache the JITed code from previous executions. Aonix and Websphere Real Time JVMs are two possible examples.
I really think developers should broaden their horizons. Oracle's JVM is only the reference implementation.
Anyone who has attempted to run an applet on any modern browser in the past 6 months will know it now involves a lot of work -- clicking through several dialogs and warnings even if you do have the latest version.
If you don't have the latest version, some browsers make it impossible, and others let you go ahead only after you acknowledge that you're putting your immortal soul in dire peril (or something along those lines).
Java on OS X will self-disable if you don't use it for a while, so then you have to figure out how to enable it, again, if you even figure out what has happened.
In Safari even when everything is enabled you see a gray box with small text saying something like "plugin disabled" in it. You have to click the small text (though it doesn't look like a link or button) to access the menu to enable it and continue.
I suppose they must be targeting corporate machines running XP and IE7 or something like that? I don't think most other people are succeeding in running legitimate Java applets, let alone anything that would be a security risk.
Some hundrends of millions of people still running XP, Windows 2000 or Vista, with IE or Firefox?
AFAIK FF still supports XP (though probably not per-service-packs XP), though I haven't checked recently.
For IE, you're probably right.
The security holes are only an issue in the context of Java applets -- Java applications don't run in the sandbox anyway (i.e., they're like other applications).
Unless the bulk of the population knows what symlinking is, but I doubt it.
So specifically, to exploit these, you write a dodgy applet, then convince users to run these applets locally (by hijacking websites or whatever), whereby you break out of the sandbox and do bad shit.
So then, in terms of how Java is generally used: on servers, on android, to execute code that runs locally on your box outside of a sandbox anyway (e.g. minecraft) these issues are in fact complete non-issues?
It seems to me that if they just split off the applet part into its own thing the world would be a far better place.
But I feel like you already knew that.
Sadly, now it's getting harder and harder to run applets. And I'm not going to code a different web-based version of my system (which would involve not only rewriting a lot of code, but finding different libraries to handle MP3, OGG, SVG graphics, etc.) so I suppose my system will just slowly fade into obsolescence.
For some things, applets are still the best choice... or would be, if users were not aggressively discouraged from using them due to what amounts mostly to PR campaigns (as i.e. Flash is by no means more secure than Java applets, and browsers don't make you click through four layers of scary dialogs to run it).
What I hate about coding projects for end users that need to run on shiny platforms (like the web) is that you always get caught on politics. Stuff like company X not allowing running software written in language Y on platform Z so as to promote its own platform, and making you port everything several tiems. Or company X including a crippled distribution of software Y because it hates company Y (this happened with Ubuntu and Java and has brought me scores of bug reports to handle). I guess my future hobby projects will be in C/C++ and directed to technical users that don't expect to run their machine learning software (for example) on a tablet browser...
Of course, you could always use C/C++ with emscripten, and target the web that way...
With Java on the other hand, I had a desktop app and an applet sharing the vast majority of the codebase, only very specific parts of the code (a small part of the UI and I/O code) differ. This is what was allowing me to maintain the project and support both desktop and browser, until the applet paranoia growed out of proportion and browsers put applets in permanent quarantine.
Of course, if I started this project now rather than in 2000, I would probably make different decisions regarding language and technologies used. Although it would still be a bit annoying not to be able to use Java. It's not my favorite language, but I definitely prefer it to JS by a mile.
I agree that re-writting an app of that size is a giant PITA.
You could always use GWT though, and compile Java to Javascript. Altough you would probably have to re-write code as you're not targeting an applet anymore.
But yeah, at least I could try and see if I can get a subset of the system working, even if it's only to learn some GWT :)
No sane Java developer would start a new project with Applets.
How is that even possible?