Apple Finally Patches Java Vulnerability
macs4all writes "Apple has finally addressed the Java vulnerability that nearly everyone else patched months ago. Available now for OS X 10.4 and 10.5, and through Apple's Software Update service, this update patches a flaw in the Java Virtual Machine that could potentially allow a malicious Java applet to execute arbitrary code on the machine. Apple had previously advised users to turn off Java temporarily in their Web browsers."
It is truly sad that Apple still just don't "Get" security. Makes me a sad panda to think it is going to take some sort of devastating worm or virus for them to finally wake up and smell the shit they are pumping out.
...and this means that we can expect Vic20_love to come along any moment now and complain that his OS X 10.1 machine from 19-dickity-6 doesn't have a patch out yet, so Apple sucks.
Not that Apple doesn't suck, but you don't really need to troll for reasons.
(Bye, karma, nice knowing you...)
--saint
Just wondering. PPC Java for OSX is even more out of date than x86 Java.
The latest java on PPC is 1.5, and I'm sure it's out of date too...
That's because it does!
Well, maybe.
First off, pretty much every time we get one of these "OMG!" stories on slashdot about a security flaw going unfixed, we find out that it's not nearly as bad as suggested by the slashdot summary. In this case, the description linked to from the slashdot article says: "The Java plug-in does not block applets from launching file:// URLs. Visiting a website containing a maliciously crafted Java applet may allow a remote attacker to launch local files, which may lead to arbitrary code execution." So that's quite a bit less scary than the slashdot summary makes it sound. If I'm understanding correctly, it apparently doesn't let the attacker launch any code the attacker choses. It only lets the attacker launch code that's already present on the user's filesystem. And doesn't the java sandbox model prevent java applets from writing to the filesystem? So the attacker really may have very little opportunity to execute arbitrary code of the attacker's choosing.
Second: the slashdot summary says, "Apple had previously advised users to turn off Java temporarily in their Web browsers." Wow, that sounds really awful. It makes it sound like a really serious problem. But wait, the apple page doesn't say this. According to the tidbits.com article, Rich Mogull is the one who says the fix is to disable applets. The link to Rich Mogull's advice is a link within tidbits.com.
Find free books.
Even after updating, I've found that's advice I can live with.
Had this been a post about Microsoft instead of Apple, I'd imagine there'd be a lot of "ha ha micro$0ft sucks" posts now.
Instead, there's a lot of "ha ha Apple sucks" posts, as one would expect since the story's about Apple and not MS.
They've been apple's problem since they took over porting java to the mac, and prevent sun from writing their own java for mac.
Apple Guy "Halt who goes there"
Black Haxor "It is I the black haxor, I seek the finest computer coders to join me in my quest"
Apple Guy " You shall not pass"
Black Haxor "What ?"
Apple Guy "Non shall pass"
Black Haxor "I have no quarrel with you, good sir, but I must move on"
Apple Guy "Then you shall first install photoshop and make an offering at the alter of Steve and promise to buy hardware at twice the price from the lords of apple".
Black Haxor "I command you to stand aside! for I am the Black Haxor"
Apple Guy "I move for no man for I am impervious to all your tricks for I run OSX"
Black Haxor "So be it"
[Black Haxor pulls out his laptop and starts to type]
[HAH]
Apple Guy "What have you done ?"
Black Haxor "I have exploited a java script bug on your system and signed you up as the local leader for the "Pedo's Rights" association and then passed the details on to the the local parents and teachers group"
Apple Guy "what is this trickery, for such is impossible, you lie"
[a rabble of middle aged parents turn up]
Crowd "THERE HE IS, GET HIM!!"
Apple Guy "BAH! Tis but a lie"
Black Haxor "run man, they weld clubs and carry petrol containers and mean harm upon you"
Apple Guy "They do not wish me harm as my laptop colour matches my shoes, thus they come to tell me how great my karma is"
[15 minutes later the Black Haxor is staring at a smoldering pile on the ground]
Black Haxor "Sigh"
[Crosses bridge]
The update fails to install on some machines, mine included.
Use your favourite search engine (Bing me no Bings) to find references to:
Rich And Stupid is not so bad as Working For Rich And Stupid.
What's "dial-up"?
Yeah. Those losers should stop running their iTunes store with Java. Lame Java haters!
http://en.wikipedia.org/wiki/WebObjects No, I didn't just edit it, but I suppose it's ripe for vandalism now.
Not like your conjecture is without merit. I mean, what can explain their slowness in Java porting? I wish I knew. It's a real annoyance.
To be mildly fair, us mere mortals aren't getting WebObjects updates anymore, but they don't seem to be slowing down their usage of it at iTunes & the Apple store and dev sites. Perhaps they're going to migrate more things to SproutCore once BitBurger et al gets released. Although that doesn't provide them with a back-end, and I'm not utterly convinced that RoR is up to the demand, inclusion in OS X notwithstanding. If only more Erlang/Mnesia would roll out.
Dooooddd... there's like this totally new thing called Bing! that lets you look stuff like that up! (I hear some pikers down in Cali called googol or something stupid like that are trying to horn in on the action though).