Slashdot Mirror


Why You Can't Dump Java (Even Though You Want To)

snydeq writes "Since so many recent exploits have used Java as their attack vector, you might conclude Java should be shown the exit, but the reality is that Java is not the problem, writes Security Advisor's Roger Grimes. 'Sure, I could opt not to use those Java-enabled services or install Java and uninstall when I'm finished. But the core problem isn't necessarily Java's exploitability; nearly all software is exploitable. It's unpatched Java. Few successful Java-related attacks are related to zero-day exploits. Almost all are related to Java security bugs that have been patched for months (or longer),' Grimes writes. 'The bottom line is that we aren't addressing the real problems. It isn't a security bug here and there in a particular piece of software; that's a problem we'll never get rid of. Instead, we allow almost all cyber criminals to get away with their Internet crime without any penalty. They almost never get caught and punished. Until we solve the problem of accountability, we will never get rid of the underlying problem.'"

3 of 402 comments (clear)

  1. Re:This is a stupid article by GIL_Dude · · Score: 5, Informative

    Well, in the enterprise space you have a huge catch-22. I deal with this at work all the time. Since Oracle / Sun Java doesn't actually do patches (they just do full versions that introduce new features, break existing code, and deprecate other features), you can't deploy it. You have this trade off of known security vulnerabilities vs. enterprise software that won't work with the new versions. You have banks that require you to run Java versions that are a year old in order to move money. You have vendors whose code won't work with the current version of Java - ever (since they take longer to get their code working on new versions that it takes Oracle to release the next new version). We try as hard as we can to get app owners to test - but every last time we ship a new Java versions apps come out of the woodwork with emergency requests to "stop the push". You can't win. Bust people's critical apps and you lose. Allow machines to get owned by insecure versions of Java? Yeah, you lose there too. Oracle needs to figure out how to do security patches that just fix the vulnerabilities and don't introduce (and remove) features. Until they can do that - yes, it is their fault.

  2. Re:less risk? by errandum · · Score: 4, Informative

    You can also not use windows and opt for linux. But is it worth it? For some, yes, I'd say that for most people it isn't.

    Java runs some cool software that most have no idea it actually is Java (it can copy the look and feel of your OS). The only way to mostly fix java is to have chrome like updates. Silent, forced on you but safe.

  3. Re:Accountability by Grishnakh · · Score: 4, Informative

    The whole idea of accountability is utterly stupid as long as you have a single data network that spans multiple countries. If someone in Nigeria sends you a virus or does something else illegal, WTF are you going to do about it? Nothing. There's absolutely no way you're going to make people entirely accountable for their actions as long as there's multiple governments, and worse different laws in different places. The only rational thing to do is to protect yourself.