Equipped To Survive Equipped To Survive® Presents
The Survival Forum
Where do you want to go on ETS?

Page 1 of 3 1 2 3 >
Topic Options
#255388 - 01/12/13 07:21 AM Way OT - huge PC security warning
dougwalkabout Offline
Crazy Canuck
Carpal Tunnel

Registered: 02/03/07
Posts: 3221
Loc: Alberta, Canada
Way OT even for the campfire, but I thought I should pass this Reuters piece along. CYA.

http://business.financialpost.com/2013/0...-java-software/

The U.S. Department of Homeland Security urged computer users to disable Oracle Corp’s Java software, amplifying security experts’ prior warnings to hundreds of millions of consumers and businesses that use it to surf the Web.

Hackers have figured out how to exploit Java to install malicious software enabling them to commit crimes ranging from identity theft to making an infected computer part of an ad-hoc network of computers that can be used to attack websites.

“We are currently unaware of a practical solution to this problem,” the Department of Homeland Security’s Computer Emergency Readiness Team said in a posting on its website late on Thursday.

“This and previous Java vulnerabilities have been widely targeted by attackers, and new Java vulnerabilities are likely to be discovered,” the agency said. “To defend against this and future Java vulnerabilities, disable Java in Web browsers.”

Java was responsible for 50 percent of all cyber attacks last year in which hackers broke into computers by exploiting software bugs, according Kaspersky. That was followed by Adobe Reader, which was involved in 28 percent of all incidents.

Top
#255395 - 01/12/13 06:25 PM Re: Way OT - huge PC security warning [Re: dougwalkabout]
bws48 Offline
Old Hand

Registered: 08/18/07
Posts: 831
Loc: Anne Arundel County, Maryland
Thanks for the heads up Doug.

I disabled the Java plug in both Chrome and Firefox this morning. I don't use Internet Explorer.
_________________________
"Better is the enemy of good enough."

Top
#255396 - 01/12/13 07:11 PM Re: Way OT - huge PC security warning [Re: dougwalkabout]
UTAlumnus Offline
Old Hand

Registered: 03/08/03
Posts: 1019
Loc: East Tennessee near Bristol
Originally Posted By: dougwalkabout


The U.S. Department of Homeland Security urged computer users to disable Oracle Corp’s Java software, amplifying security experts’ prior warnings to hundreds of millions of consumers and businesses that use it to surf the Web.


Doesn't this also impair a large fraction of the websites?

Top
#255398 - 01/12/13 07:33 PM Re: Way OT - huge PC security warning [Re: UTAlumnus]
dougwalkabout Offline
Crazy Canuck
Carpal Tunnel

Registered: 02/03/07
Posts: 3221
Loc: Alberta, Canada
Originally Posted By: UTAlumnus
Doesn't this also impair a large fraction of the websites?


That was my first thought too. The problem appears to be with Java, not JavaScript. From what I gather these are two very different things, but the similar names are creating a lot of confusion out there.

FWIW, when I checked last night, only two of my PCs had Java installed. The rest, including Windows and Linux boxes, never had it and I haven't had had any problems using websites.

Anyway I'm just the messenger, not a programmer, so please don't consider this to be an expert opinion.

Top
#255400 - 01/12/13 11:10 PM Re: Way OT - huge PC security warning [Re: UTAlumnus]
Arney Offline
Pooh-Bah

Registered: 09/15/05
Posts: 2485
Loc: California
A lot of websites still use Java on the server-side, but not necessarily piped down to your browser. A security flaw like this really impacts corporations more than most regular web surfers realize if it needs to be disabled/removed. Mobile devices use Java, maybe your big screen TV even. It's found in a lot of technology, but this warning only applies to computers connected to the web.

You may find that certain features of your favorite website may not work for a while until a patch is distributed or they come up with a workaround.

Java was Sun's love child but ever since Oracle bought out Sun, Java's been kind of a step-child that doesn't fit in with the rest of the Oracle family so it doesn't get the attention it deserves.

This isn't the first major security flaw discovered recently with Java. ALL software has flaws so it's mostly the effort put into responding to and also proactively looking for flaws that sets the bar on security. Remember how Microsoft products were the butt of jokes not that long ago for the number of high profile security flaws that kept surfacing? Well, Microsoft invested a lot of money and attention to the matter and now how often do you hear about major MS security flaws with their IIS webserver, Internet Explorer, etc?

Top
#255404 - 01/12/13 11:49 PM Re: Way OT - huge PC security warning [Re: ]
UTAlumnus Offline
Old Hand

Registered: 03/08/03
Posts: 1019
Loc: East Tennessee near Bristol
Quote:
remove any shred of Java (Not to be confused with JavaScript, though)


That explains it. I was thinking of Java Script.

Top
#255409 - 01/13/13 02:56 AM Re: Way OT - huge PC security warning [Re: UTAlumnus]
haertig Offline
Pooh-Bah

Registered: 03/13/05
Posts: 2322
Loc: Colorado
For security, I run Linux (therefore, I obviously don't use IE either). But even with this, I don't allow Java in a web browser (certainly not - never have), but neither do I allow JavaScript or Flash. When I run into friends who ask for computer help and they are unaware enough to be allowing ActiveX, I advise them to disable that. I haven't messed with many Windows computers lately, so I really don't know much about Windows and IE anymore. I abandoned that long ago because of all the security flaws, and just never looked back. Windows could have improved since then, but I really don't care anymore.

I do have a few websites whitelisted and they are allowed to use JavaScript (ETS being one of those), and other specific websites are allowed to run Flash. Very few however. Cookies are disallowed for most sites, I enable that on a site-per-site basis. For example, ETS can set permanent cookies, and when I'm actively buying a product off a website I usually enable cookies (temporarily) for "session only" since most online purchases won't work without that. Ads are blocked as well. The main reason is not because I don't want to support advertisers (although I admit I DO hate intrusive ads!), but because allowing all that stuff into your computer is just another road to potential disaster, as well as a bandwidth hog.

You don't want websites running software on your computer. I may be old-school and hard-assed about this, but my computers don't get compromised.

Top
#255417 - 01/13/13 01:40 PM Re: Way OT - huge PC security warning [Re: dougwalkabout]
chaosmagnet Offline
Sheriff
Carpal Tunnel

Registered: 12/03/09
Posts: 3822
Loc: USA
I have gone through the house and uninstalled Java on all our computers. It won't be reinstalled. I would urge you all to do the same.

Top
#255419 - 01/13/13 04:25 PM Re: Way OT - huge PC security warning [Re: chaosmagnet]
Russ Offline
Geezer

Registered: 06/02/06
Posts: 5357
Loc: SOCAL
I've been playing with the Java & JavaScript settings in Firefox (version 18.0). I lost some functionality when I disabled Firefox's JavaScript (pulldown Tools/Options/Content) but lost nothing when I disabled the runtime environment settings in Java.

So as has been suggested, I removed Java using Windows "Add or Remove Programs" in the control panel. As far as I can tell nothing has been lost.

Thanks to all for the suggestion.
_________________________
Better is the Enemy of Good Enough.
Okay, what’s your point??

Top
#255421 - 01/13/13 05:31 PM Re: Way OT - huge PC security warning [Re: dougwalkabout]
Roarmeister Offline
Old Hand

Registered: 09/12/01
Posts: 960
Loc: Saskatchewan, Canada
The fix is in the works. Oracle says that they will be releasing the fix on Tuesday. http://www.pcworld.com/article/2025171/oracle-says-java-update-coming-tuesday.html

I wouldn't be any more apprehensive about the Java issue than problems with any other software. MS has smaller fixes every Tuesday and the occassional major fix that is just as exploitive as this Java issue. Obviously, Homeland Security has a zero tolerance for this type of problem, your personal computer is much less at risk.

BTW, this flaw is in the JDK7 (Java Development Kit) version of the software and it "does not affect Java applications directly installed and running on servers, desktops, laptops and other devices," the company said. If you aren't a software developer, you won't have this installed on your computer and this won't be an issue for you.


Edited by Roarmeister (01/13/13 06:25 PM)

Top
Page 1 of 3 1 2 3 >



Moderator:  Alan_Romania, Blast, chaosmagnet, cliff 
April
Su M Tu W Th F Sa
1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30
Who's Online
0 registered (), 537 Guests and 91 Spiders online.
Key: Admin, Global Mod, Mod
Newest Members
Explorer9, GallenR, Jeebo, NicholasMarshall, Yadav
5368 Registered Users
Newest Posts
Bird Flu (H5N1) found in cattle -- are Humans next
by dougwalkabout
04:00 AM
People Are Not Paying Attention
by Bingley
03:24 AM
Corny Jokes
by wildman800
04/24/24 10:40 AM
USCG rescue fishermen frm deserted island
by brandtb
04/17/24 11:35 PM
Silver
by brandtb
04/16/24 10:32 PM
EDC Reduction
by Jeanette_Isabelle
04/16/24 03:13 PM
New York Earthquake
by chaosmagnet
04/09/24 12:27 PM
Bad review of a great backpack..
by Herman30
04/08/24 08:16 AM
Newest Images
Tiny knife / wrench
Handmade knives
2"x2" Glass Signal Mirror, Retroreflective Mesh
Trade School Tool Kit
My Pocket Kit
Glossary
Test

WARNING & DISCLAIMER: SELECT AND USE OUTDOORS AND SURVIVAL EQUIPMENT, SUPPLIES AND TECHNIQUES AT YOUR OWN RISK. Information posted on this forum is not reviewed for accuracy and may not be reliable, use at your own risk. Please review the full WARNING & DISCLAIMER about information on this site.