Ditching Java might be a good move

Discussion in 'other security issues & news' started by ronjor, Dec 22, 2011.

Thread Status:
Not open for further replies.
  1. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
    Is this a default setting? Which version? Stable?
    Or is it a matter of having "click to play" ticked? In which case, it isn't a default property.
     
    Last edited: Dec 23, 2011
  2. wat0114

    wat0114 Guest

    The approach I use for IE 9.
     
  3. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    A better method in IE might be to remove the plugins ability to run on all sites, then you should get a prompt every time it wants to load.
     
  4. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Yes, this is default in all Chrome versions for a while now. Chrome also warns you if your Java plugin is out of date before Java runs.
     
  5. wat0114

    wat0114 Guest

    That might work, although I have Group Policy settings for plug-ins that might make that approach difficult for me, but I'll give it a try. thanks for the suggestion!
     
  6. tomazyk

    tomazyk Guest

    I removed it few months ago and now I realize I don't need it either. It looks like I've been installing it just out of the habit.
     
  7. Carver

    Carver Registered Member

    Joined:
    Feb 5, 2006
    Posts:
    1,910
    Location:
    USA
    I have a 401k at work and Java is needed for the pie charts and stuff and I have online banking which would not too well with out it.
     
  8. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,617
    A fair argument on needing Oracle Sun Java or not here

    JavaRA has moved

    Update your Bookmarks.

    Regards,
     
    Last edited: Dec 26, 2011
  9. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,617
    More evidence presents that ongoing Java vulnerabilities posted by F-Secure indicate a computer without Oracle Sun Java is probably safer.
     
  10. prius04

    prius04 Registered Member

    Joined:
    Apr 14, 2007
    Posts:
    1,248
    Location:
    USA
    Okay, I went ahead and disabled it in IE since I rarely use IE for anything, anyway. However, will I be "safer" if I disable the add-on in Firefox, but not in Chrome, and then use Chrome (and only Chrome) for sites that use Java? I mean, both browsers use the same plugin (npjp2.dll), right?
     
  11. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,617
    Since I don't use Chrome, I could not give you a definitive answer as to what to disable - the consensus is Oracle Java should be removed completely across all Browsers and platforms. I have yet to do this.

    This would be to say, disable all plug-ins, extensions, etc without uninstalling the actual application. As to alternatives to Oracle Java, I have none to offer at this time.

    This is strictly user choice based on Java Exploits noted over a year or more.
     
  12. siljaline

    siljaline Registered Member

    Joined:
    Jun 29, 2003
    Posts:
    6,617
    Download, Release Notes

     
  13. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Have any of these exploits been shown to work against an EMET'd Java?
     
  14. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
  15. MrBrian

    MrBrian Registered Member

    Joined:
    Feb 24, 2008
    Posts:
    6,032
    Location:
    USA
  16. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Interesting. Thank you MrBrian.
     
  17. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    4,020
    Location:
    California
    With the Opera browser, using Java is not a problem.

    I keep plugins disabled in global preferences, so no chance of getting a Java exploit if redirected to a compromised site.

    If the Java plugin is needed on a trusted site, as I encountered this evening in sending some documents to my insurance company -- their page uses Java to upload/scan attachments -- it's just a few clicks to enable it:

    usaa_java.gif


    ----
    rich
     
  18. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
  19. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Heck, it's just like Silverlight... the more I think it's useless, the more I find services using it. Recently, it was a regular expressions website. Java is the same thing. Many may not need it, at all - so uninstall it; those needing it, once in a while - disable it, until you need it. Is this really so hard to accomplish? :argh:

    On a side note, I'm pretty sure a lot are also wishing the good ads thing of Adblock Plus to die too. :D (Sorry folks, I just couldn't resist. :D) Our wishes simply don't come true, most of the times. :shifty:

    -edit-

    I'd like to see Java to work on a low integrity level, though. Or, in other words, a sandbox.
     
  20. constantine76

    constantine76 Registered Member

    Joined:
    Dec 18, 2010
    Posts:
    191
    Yes. I definitely agree. Oracle imho doesn't even try and just bank on the fact that it's hard to "ditch" Java at this time.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.