Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
Home Enterprise I.T. Cloud & Virtualization Applications Unified Communications More Topics...
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Mobile Tech
Introducing Simpana® 10 software
Average Rating:
Rate this article:  
Apple Awards Java a Circle-with-Slash Due to Security Issues
Apple Awards Java a Circle-with-Slash Due to Security Issues

By Barry Levine
January 31, 2013 2:09PM

    Bookmark and Share
Java's security issues became much more visible when the Department of Homeland Security urgently recommended that users disable Java because of its vulnerabilities. Security researchers reported that several popular exploit kits -- packages of tools used by criminals to attack computers -- had been updated to exploit the newly discovered flaw.
 



Apple has updated its blocking of Java in its OS X operating system. The company did so a few days after the discovery that the latest version of the Java Web plug-in, which was intended to fix security issues, is itself vulnerable to attacks.

This move is the latest by the technology giant to shun Java, which has been cited by no less an authority than the U.S. Department of Homeland Security as being a security risk. Apple uses its XProtect mechanism for its Safari browser, which requires a particular version of Flash or Java plug-ins once an issue has been discovered with another version. The XProtect list defines which plug-in version is acceptable, and Apple can thus block others.

The XProtect list is being used in this case to block Java by indicating that it will only accept a version number that has not yet been released. This is how the company blocked the Java Web plug-in earlier in January, following the discovery by researchers of security flaws.

Chrome and Firefox

Oracle, which owns Java, had released a new version of the plug-in, JRE version 1.7.0_11-b21, to counter the issues from early January. But a vulnerability for the new version was reported. To counter that issue, Oracle set the plug-in so that users would have to approve running any unsigned or self-signed Java applets -- that is, ones that did not have certificates by trusted authorities. Applets with trusted credentials could run without any input from the user.

This past weekend, however, researchers discovered that a bug in Java's framework allowed attackers to bypass those security protections, thus enabling unsigned applets to run without user permission.

If Mac users require Java for any regular functionality, they can use Chrome or Firefox browsers. However, both Google and the Mozilla Foundation, which issue those browsers, have indicated that they are also considering blocking Java plug-ins.

A 'Mess'

Earlier this month, Java's security issues became much more visible when the Department of Homeland Security issued an urgent recommendation that users disable Java software Relevant Products/Services because of security vulnerabilities. Security researchers reported that several popular exploit kits -- which are packages of tools used by criminals to attack computers -- had been updated to exploit the newly discovered flaw.

One security expert has described Java to news media as a "mess," and another has said the situation was "like open hunting season on consumers." Java is not needed in browsers for most activities, but it is used in some online activities, such as Citrix's widely used online collaboration software, GoToMeeting.

Oracle, which acquired Java when it bought Sun, has a page that describes how to disable Java for all browsers on Windows machines, or individually by browser on any platform. The instructions, "How do I disable Java in my web browser," are at http://www.java.com/en/download/help/disable_browser.xml.
 

Tell Us What You Think
Comment:

Name:



CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.


 Mobile Tech
1.   Toshiba Offers Retina-Like Display
2.   Is Waze Worth a Billion in Bidding War?
3.   Viva Movil! Buy a Phone from J.Lo
4.   Samsung Sells 10 Million Galaxy S IVs
5.   Chrome Gets Conversational Search


advertisement
Google Glass Raises Privacy ConcernsGoogle Glass Raises Privacy Concerns
House privacy panel wants answers.
Average Rating:
Mandatory BYOD Is Catching OnMandatory BYOD Is Catching On
Will be required by many within 4 years.
Average Rating:
Thorsten Heins Predicts Tablet DemiseThorsten Heins Predicts Tablet Demise
BlackBerry PlayBook may color his view?
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Review: Toshiba Brings High-Res Screen to Windows
Last year, Apple added a visually stunning option to its MacBooks: Retina displays with ultra-high resolution. Now, Toshiba just released a new laptop line with a Retina-level display. How does it compare?
 
Lenovo Sales Soar Amid PC Industry Slump
Computer maker Lenovo says its latest quarterly profit rose 90 percent as sales of smartphones and mobile computing technology expanded, amid a decline in desktop and laptop PC sales.
 
Newest HP PCs Aim for Flexibility, Mobility
Hewlett-Packard is hoping its latest PC innovations will revive buyer interest. The new Envy Rove20 is HP's first mobile all-in-one PC, complete with a built-in battery and touch technology.
 

Mobile Enterprise Spotlight
Review: Toshiba Brings High-Res Screen to Windows
Last year, Apple added a visually stunning option to its MacBooks: Retina displays with ultra-high resolution. Now, Toshiba just released a new laptop line with a Retina-level display. How does it compare?
 
Is Waze Worth a Billion Dollar Bidding War?
There's a bidding war going on over a crowd-sourced map application provider. Or so the rumor mill says. Credible sources are pointing to a competition between Google and Facebook for Waze.
 
Viva Movil! Buy a Phone from J.Lo
Latina pop sensation and entrepreneur Jennifer Lopez is teaming with Verizon Wireless on a new 4G LTE network and wireless service dubbed Viva Movil by Jennifer Lopez, aimed at the U.S. Latino market.
 

Enterprise Technology Spotlight
Newest HP PCs Aim for Flexibility, Mobility
Hewlett-Packard is hoping its latest PC innovations will revive buyer interest. The new Envy Rove20 is HP's first mobile all-in-one PC, complete with a built-in battery and touch technology.
 
New Nvidia Chip Boosts Citrix Graphics for Remote Workers
The latest Nvidia Graphics Processing Unit (GPU) promises to boost remote graphics sharing through the Citrix remote desktop service. The new chip delivers better graphics for remote workers.
 
Security Alert: Beware of Tiffany Trojan on the Attack
Malware writers are using a luxury name to hack your PC. Security watchdog Sophos reports e-mails appearing to be from Tiffany.com carry an attachment that can install a malicious Trojan on your PC.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud & Virtualization | Applications | Unified Communications | Mobile Tech | Hardware | Business Intelligence
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.