Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Riverbed Stingray in AWS
The only full-featured ADC
available for Amazon EC2 today

www.riverbed.com
Wednesday, May 22nd 
Introducing Simpana® 10 software
Home
Data Centers
Storage Solutions
Storage Networks
Data Storage Issues
Data Security
Enterprise I.T.
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement

Data Security

Apple Awards Java a Circle-with-Slash Due to Security Issues

Apple Awards Java a Circle-with-Slash Due to Security Issues
January 31, 2013 2:09PM

Bookmark and Share
Java's security issues became much more visible when the Department of Homeland Security urgently recommended that users disable Java because of its vulnerabilities. Security researchers reported that several popular exploit kits -- packages of tools used by criminals to attack computers -- had been updated to exploit the newly discovered flaw.

CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.

Apple has updated its blocking of Java in its OS X operating system. The company did so a few days after the discovery that the latest version of the Java Web plug-in, which was intended to fix security issues, is itself vulnerable to attacks.

This move is the latest by the technology giant to shun Java, which has been cited by no less an authority than the U.S. Department of Homeland Security as being a security risk. Apple uses its XProtect mechanism for its Safari browser, which requires a particular version of Flash or Java plug-ins once an issue has been discovered with another version. The XProtect list defines which plug-in version is acceptable, and Apple can thus block others.

The XProtect list is being used in this case to block Java by indicating that it will only accept a version number that has not yet been released. This is how the company blocked the Java Web plug-in earlier in January, following the discovery by researchers of security flaws.

Chrome and Firefox

Oracle, which owns Java, had released a new version of the plug-in, JRE version 1.7.0_11-b21, to counter the issues from early January. But a vulnerability for the new version was reported. To counter that issue, Oracle set the plug-in so that users would have to approve running any unsigned or self-signed Java applets -- that is, ones that did not have certificates by trusted authorities. Applets with trusted credentials could run without any input from the user.

This past weekend, however, researchers discovered that a bug in Java's framework allowed attackers to bypass those security protections, thus enabling unsigned applets to run without user permission.

If Mac users require Java for any regular functionality, they can use Chrome or Firefox browsers. However, both Google and the Mozilla Foundation, which issue those browsers, have indicated that they are also considering blocking Java plug-ins.

A 'Mess'

Earlier this month, Java's security issues became much more visible when the Department of Homeland Security issued an urgent recommendation that users disable Java software Relevant Products/Services because of security vulnerabilities. Security researchers reported that several popular exploit kits -- which are packages of tools used by criminals to attack computers -- had been updated to exploit the newly discovered flaw.

One security expert has described Java to news media as a "mess," and another has said the situation was "like open hunting season on consumers." Java is not needed in browsers for most activities, but it is used in some online activities, such as Citrix's widely used online collaboration Relevant Products/Services software, GoToMeeting.

Oracle, which acquired Java when it bought Sun, has a page that describes how to disable Java for all browsers on Windows machines, or individually by browser on any platform. The instructions, "How do I disable Java in my web browser," are at http://www.java.com/en/download/help/disable_browser.xml.

Tell Us What You Think
Comment:

Name:

Advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Dell Kills Its In-House Public Cloud
  China Hackers Resume U.S. Attacks
  Cyberattacks Could Help Syrian Raids
  Financial Times Latest Hacking Target
  HP and SAP Team on HANA Database

 Technology Marketplace

BYOD & MDM
Build a business case for a BYOD program.
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Mobile Apps
Build great mobile apps that drive engagement.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Hardware Spotlight

Dell Kills Its Public Cloud Effort, Will Offer Partner Marketplace
Putting the kibosh on its efforts to build out a public cloud, Dell has announced a new program to offer a choice of cloud Infrastructure-as-a-Service through a central marketplace of partners.

Dell's Dismal Quarter Shows PC Maker's Challenges
Dell's financial decay worsened during its latest quarter as the company slashed its personal computer prices in response to the growing popularity of smartphones and tablets in the beleaguered industry.

U.S. Defense Department Gives iOS 6 Security OK
In a vote of confidence for Apple's iOS devices, the Defense Department has given the all-clear for employees to use iPads and iPhones for work. But only those running iOS 6, and only if issued by the government.

Advertisement
Navigation
Data Storage Today
Home/Top News | Data Centers | Storage Solutions | Storage Networks | Data Storage Issues | Data Security | Enterprise I.T.
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.