Java security problems
Thread Starter

Joined: Apr 2007
Posts: 958
Likes: 20
From: The Luberon
Java security problems
There has been a lot of publicity about Java recently which leaves computers vulnerable to attacks by hackers. Many sources suggest disabling Java until a proper fix is found.
I am using Windows 7, 64 bit, and Firefox as my preferred browser. Can anyone suggest what effect disabling Java will have?
If anyone wants to heed the warnings and disable their Java, instructions can be found here.
I am using Windows 7, 64 bit, and Firefox as my preferred browser. Can anyone suggest what effect disabling Java will have?
If anyone wants to heed the warnings and disable their Java, instructions can be found here.
Joined: Aug 2002
Posts: 3,663
Likes: 0
From: Earth
Can anyone suggest what effect disabling Java will have?
If you use Java apps, things will break.
To be honest, for your average punter, disabling Adobe Flash is more likely to have a pronounced effect.
Why not try it and see ?
Last edited by mixture; 16th January 2013 at 08:10.
Joined: Aug 2002
Posts: 3,663
Likes: 0
From: Earth
Ok I will bite, what won't work if people disable Adobe Flash?
Last edited by mixture; 16th January 2013 at 08:47.
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
important security tip is to uninstall all old versions of the Java VM
Installing a new version does not remove the old ones by default. They get left behind and are available to be hacked (even if not active).
Obviously if you need a specific old JVM version for a specific application then you can't remove that, but otherwise remove old versions as soon as a new one comes along.
Also in the Java applet in the control panel, on the general tab > temporary internet files > settings > UNTICK the box which says "keep temporary internet files on my machine"
Its not a lot, but it helps
Installing a new version does not remove the old ones by default. They get left behind and are available to be hacked (even if not active).
Obviously if you need a specific old JVM version for a specific application then you can't remove that, but otherwise remove old versions as soon as a new one comes along.
Also in the Java applet in the control panel, on the general tab > temporary internet files > settings > UNTICK the box which says "keep temporary internet files on my machine"
Its not a lot, but it helps
Joined: Nov 2000
Posts: 3,443
Likes: 1
From: Cambridge, England, EU
important security tip is to uninstall all old versions of the Java VM
There are two main reasons for having Java installed.
(1) You are running some desktop applications that are written in Java.
(2) You wish to run some Java applets embedded in web pages.
The security risks are mostly with (2), and the suggested workarounds, such as disabling Java in the browser, are mostly aimed at this scenario.
If however you are in scenario (1) it is quite likely the case that each Java application you rely on needs a specific version of Java (each version has its own bugs, so each application might be targetted to a specific version). In this case uninstalling old versions will kill the applications that rely on them.
Joined: Aug 2002
Posts: 3,663
Likes: 0
From: Earth
If however you are in scenario (1) it is quite likely the case that each Java application you rely on needs a specific version of Java
I know of at least one well established professional stockmarket data feed tool that relies on Java Applets and the developers recommend specific versions of Java.
Last edited by mixture; 16th January 2013 at 20:42.
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
What you say is correct, but for most home users there isn't that need to use old versions. Few use version-dependent programs. For the average home user, the simple fact is that they should have one JVM installed: the newest available
Joined: Apr 2008
Posts: 218
Likes: 0
From: Uk
For a few days I've had an alert 'Java Update Available' and I really don't know whether to trust it.
Program name: jucheck.exe
Verified publisher: Oracle America, inc.
File origin: Hard drive on this computer
Any thoughts?
Program name: jucheck.exe
Verified publisher: Oracle America, inc.
File origin: Hard drive on this computer
Any thoughts?
Per Ardua ad Astraeus
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
ts a security patch, and an important one
I have a friend locally who's business is based on a large security prog written in Java. I wonder what the future holds?
Joined: Jun 2009
Posts: 29
Likes: 0
From: UK Manchester
I have been told that it's best to delete older versions when you have installed the latest update. You can do this by looking in your 'add remove' programms application (in xp) or 'uninstall program' (in 7 etc) and that way
circumventing any risk that any exploit created to intercept that version cannot be used if it has been deleted - just make you check you have the latest version before doing that.
circumventing any risk that any exploit created to intercept that version cannot be used if it has been deleted - just make you check you have the latest version before doing that.
Joined: Jan 2012
Posts: 2,173
Likes: 0
From: .
Java IS flawed, period. And this "kerfuffle" won't die down as malware writers are increasingly targetting it in preference to Windows itself.
However, if you are browsing the web, you probably need it. Especially if you shop online, bank online, pay your bills online, play games online......
The suggestion of using Flash instead is a non-starter: that has a completely different set of uses, and is not an alternative product. Also, its just as flawed and vulnerable as Java
To try to be secure, you need to have installed the latest version of Java, and ensure thats the only version installed, unless you need an earlier version for a specific piece of software. Most home users don't.
Make sure you have up to date reputable security software (McAffee and Norton are not reputable in my book).
And most importantly - practice safe browsing. Browsing and sex are similar in that if you take risks, then both will give you a pox
However, if you are browsing the web, you probably need it. Especially if you shop online, bank online, pay your bills online, play games online......
The suggestion of using Flash instead is a non-starter: that has a completely different set of uses, and is not an alternative product. Also, its just as flawed and vulnerable as Java
To try to be secure, you need to have installed the latest version of Java, and ensure thats the only version installed, unless you need an earlier version for a specific piece of software. Most home users don't.
Make sure you have up to date reputable security software (McAffee and Norton are not reputable in my book).
And most importantly - practice safe browsing. Browsing and sex are similar in that if you take risks, then both will give you a pox
Joined: Nov 2000
Posts: 3,443
Likes: 1
From: Cambridge, England, EU
but what about my last line regarding the future for JAVA-based programmers?
Per Ardua ad Astraeus
Joined: Mar 2000
Posts: 18,575
Likes: 4
From: UK
That's what he told me - something to do with financial transactions I believe. I was quite impressed when I first heard about 2 years back, but now..........................I even got a library book out to look at Java



