DHS warns on Java security

Status
Not open for further replies.
Originally Posted By: 97tbird
This is what my plug-in page looks like...I guess I am ok?


No. Facebook is there..
 
lol
smile.gif
who can live without FB ? (j/k)
 
Originally Posted By: bubbajoe_2112
or just uninstall java from control panel


Is there any negative to uninstalling Java completely?

Is it used for anything other than the web browser?
 
OpenOffice uses Java. So does Adobe Photoshop.

Sadly, i don't know of any easy way to verify which of your currently installed applications rely on Java.
 
My Lord, I swear that Java is the MOST insecure platform ever used. It is so heavily exploited...... yet there are applications that RELY on it, particularly in the medical field. This could be a nightmare for me
frown.gif
 
Originally Posted By: Quattro Pete
OpenOffice uses Java. So does Adobe Photoshop.

Sadly, i don't know of any easy way to verify which of your currently installed applications rely on Java.


Here's a start. By and large, most people won't notice it gone. I don't.

And if you absolutely need it, you can disconnect from the network/inet to be totally safe.

programs that use java
 
Originally Posted By: 97tbird
Originally Posted By: friendly_jacek
Originally Posted By: 97tbird
So how the heck does one disable JAVA? or is it automatically being done for me by FF? my version of FF is 18.0


It's under options. As soon you do it, you can't post on BITOG.


I think you're talking about java-SCRIPT.


Yes, I am. I just went by the first post here that was misleading. I went to the add-ons and Java was still active (FF up to date). I disabled there.
 
Hmm, Firefox 17.0 claims Java 6 Update 36 or 37 was still running - so I updated to Java 7 Update 10.

And Firefox just issued an update to FF 18.0
 
Follow drew99gt's second link.

It is not disabled completely, but it is supposed to require specific permission to run.
 
Last edited:
It's totally blocked/disabled within FF and will in no circumstance run unless the user manually enables it.

It's been blocked/disabled since Oct 30 according to the note at the bottom of my Java plug in page (click the "more information" link)...
 
Last edited:
Originally Posted By: DuckRyder
Depends on the version.

See:

https://blog.mozilla.org/security/2013/01/11/protecting-users-against-java-vulnerability/

If you are running one of the listed versions of the plug in it will not automatically say "disabled" when you check your ad ins.


"To protect Firefox users we have enabled Click To Play for recent versions of Java on all platforms (Java 7u9, 7u10, 6u37, 6u38). Firefox users with older versions of Java are already protected by existing plugin blocking or Click To Play defenses."
 
Last edited:
I have now completely uninstalled java from my HTPC. My other PCs unfortunately still rely on it because of Adobe Lightroom.
 
Originally Posted By: bubbajoe_2112
Originally Posted By: DuckRyder
Depends on the version.

See:

https://blog.mozilla.org/security/2013/01/11/protecting-users-against-java-vulnerability/

If you are running one of the listed versions of the plug in it will not automatically say "disabled" when you check your ad ins.


"To protect Firefox users we have enabled Click To Play for recent versions of Java on all platforms (Java 7u9, 7u10, 6u37, 6u38). Firefox users with older versions of Java are already protected by existing plugin blocking or Click To Play defenses."


Right, but this is why there are a couple of people saying it isn't automatically disabled, for instance:

Originally Posted By: NJC
Hmm, Firefox 17.0 claims Java 6 Update 36 or 37 was still running - so I updated to Java 7 Update 10.

And Firefox just issued an update to FF 18.0


That is the expected behavior, according to the article.

But you can certainly disable it.

Also can be tested at:

http://www.java.com (click do I have Java)
 
I uninstalled Java last night from the control panel on my Win 7 IE 9 machine, and have not noticed anything different. Youtube and all my other usual websites are working. I love how there is no mention of this on the Java website.
 
Java doesn't appear on my list of programs, when I go to control panel and 'uninstall a program' (win 7 pro).
FF 18.0

Hope I don't have Java - info is conflicting...
 
Heads up. I still had virus issues and FF redirects even after viruses removal and disabling Java in FF. The AVG antivirus would remove threats but they would came back later. After turning Windows Task Manager, it turned out that the malware found a way of turning on MSIE without showing up on the screen. I disabled Java in MSIE and the malware didn't come back.

I may need to install Java completely.

Bottom line, AVG alone is not entirely successful, even though it partially blocked it. I'm going to bring up some bigger guns now.

My other PC had AVG and Teatimer running and sounds like the teatimer intercepted the thread completely.

The bottom line is, don't forget the java plug in in MSIE, even if you don't use it.
 
Originally Posted By: OVERKILL
My Lord, I swear that Java is the MOST insecure platform ever used. It is so heavily exploited...... yet there are applications that RELY on it, particularly in the medical field. This could be a nightmare for me
frown.gif



My sentiments are the same as yours. Some Java versions I have to support 1.5r6 (IIRC), 1.6.07, FUN!

Disabling them means goodbye entire web-based medical app for the entire institution.


HAPPY HAPPY JOY JOY!!


Oracle needs to rename Java to Junka.
 
Status
Not open for further replies.
Back
Top