It's a way easier to download a binary and execute that.
It's dead for the end-user for every meaningful definition of "dead".
Also ActiveX was the MS answer to Java, not the other way round.
It's a way easier to download a binary and execute that.
It's dead for the end-user for every meaningful definition of "dead".
Also ActiveX was the MS answer to Java, not the other way round.
Unfortunately not, there are MANY institutions that still rely on Java Applets.
Even if the webbrowser that displays the intranet applets is used to surf the internet it's not a attac surface as you have to whitelist every site that's able to use applets.
Is that "end-user" enough for you? All busness owners in the country and all other general population doing eGovernment?
That's for OTP though, users with tokens or keyfile have to use the OpenSign applet still. Haven't seen any stats, but OpenSign usage is probably pretty small compared to standard NemID/OTP.
You must be either exaggerating or not up to date (not aware that not every applet is automatically run). I don't think anybody is getting harmed. What do you think a realistic attack scenario using Java applets looks like? You'll have to break RSA, or how are you going to fool the browser plugin to run your exploit?
Except ActiveX goes back to Windows 3.1 and OLE 2.0.