Polish Researcher: Oracle Knew For Months About Java Zero-Day
dutchwhizzman writes "Polish security researcher Adam Gowdiak submitted bug reports months ago for the current Java 7 zero-day exploit that's wreaking havoc all over the Internet. It seems that Oracle can't — or won't? — take such reports seriously. Is it really time to ditch Oracle's Java and go for an open source VM?"
You sound like someone who shouldn't be giving technical advice.
C/C++ has advantages over Java, just like Java has advantages over C/C++
Saying you should use one over the other for every purpose is foolhardy.
Mod me down, my New Earth Global Warmingist friends!
This is the programming language that still bundles the "Ask Toolbar" crapware with their installer. Nuff said.
Ditch Java applets entirely.
Go green: turn off your refrigerator.
The real problem here is the quarterly patch cycle that seems to ignore the severity of security bugs. If you want to do a quarterly cycle that's fine - but you need to make exceptions for security bugs.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
Unless an SVP gets involved, it's unlikely that it will be rushed.