Java and Malware-the trend continues

  • 30 January 2013
  • 6 replies
  • 1243 views

Userlevel 7
Yep-it's the end of the day and Java is in the news again (ok, to be fair the story is actually from yesterday, but takes on a familiar theme to that discussed here, here, and here). And that theme is that Java just isn't safe.
 
Now, in the latest news, the fix that was supposed to make it harder for attackers to exploit Java and launch attacks actually won't protect you from malware. Crazy notion, huh?
 
"In practice, it is possible to execute an unsigned (and malicious!) Java code without a prompt corresponding to security settings configured in Java Control Panel", says security researcher Adam Gowdiak.
 
Full story here. What are your thoughts?

 

(Source: SecurityWeek)

 

6 replies

Userlevel 7
I recall many a moon ago, when Java was just coming out.. There was a lot of interest in it, as it is a crossplatform code that made it easy to distribute a program.  There was also a lot of talk about the potential for security risks.  
 
The more things change, the more they stay the same.
 
😃
Userlevel 7
Badge +56
Do you remember when Microsoft had there own Java Virtual Machine?
 
Sun vs. Microsoft
In October 1997, Sun Microsystems, the creator of Java, sued Microsoft for incompletely implementing the Java 1.1 standard.[4]
In January 2001, Sun and Microsoft settled the suit. Microsoft paid Sun $20 million and the two agreed to a plan for Microsoft to phase out products that included the older version of Microsoft Java that allegedly infringed on Sun's Java copyrights and trademarks.
 
And look at the problems facing Oracle these days with Java it's going to cost them more then 20 million if companies start suing them. :p
 
TH
Userlevel 7
Yes.. I remember that!
Userlevel 7
Badge +13
I never ever thought i would hear myself say Flash coding is tight in comparison with java.The only good news about what has happened is that the brass at Oracle now fully realizes that java must be fixed and fixed properly.Hopefully they back up their words with action.
Userlevel 7
I wouldn't be surprised to hear about another Java vulnerability that allows attackers to jump out of your computer and hit you between the eyes.

Just kidding but Java is indeed a bad joke.
Userlevel 7
I've uninstalled Java from all my computers, thanks to all the posts being made on this Community Forum. ;)
Thanks members for the heads up that Java is a piece of , well you know that I'm thinking. 😃

Reply