|
Post by silverdragon on Jan 15, 2013 9:46:18 GMT
I have the Firefox version 18 now...
Well, Java was SUPPOSED to be disabled in this latest Firefox Update by default?....
Can I just mention its worth checking that it is disabled by hand, 'cos on my machine I still had one part running....
You are looking for Java Deployment Toolkit under several different version numbers, make sure all of them are turned off....
For the Moment....
Now on to news feeds from various sources....
Despite "Its all good now" from SOME sources that say Java has been patched and if you download the latest version it contains a patch" from certain places, other reputable sources are stating that there is still vulnerabilities in Java....
As of yet, I am not fully aware of all the facts. Is this reported patch either a myth 'cos they aint done anything yet, a sticky-plaster whilst they work out a full patch, or a full update?....
Various sources are reporting different things, so until I get a fully confirmed "Its fixed" from a reputable source that is conformed by other reputable sources, or a statement from Java people themselves stating a full fix, my advice as of this time is dont trust hear-say, dont use Java at the moment.
Please also note this advice could have been invalidated as soon as you read it, 'cos I just bet the buggers release a patch whilst I was writing this?.. sods law rules apply.....
If anyone gets that conformation before I do, please feel free to post it?.. I have things to do for the rest of the day.....
|
|
|
Post by silverdragon on Jan 15, 2013 9:54:11 GMT
www.oracle.com/technetwork/topics/security/alert-cve-2013-0422-verbose-1896885.htmlAnyone make sense of THAT?... This is the "patch" that is reported to be "The Fix" that has been released by Oracle. However.... what IS that page?... It reports known security flaws, but does it actually say they have been patched?.... It doesnt say "Problem fixed" does it?... From One source.... Erm... NOT fixed then at all?... If you get a message saying "This site uses java can we use it"on your screen, you would tick the "Go ahead" wouldnt you?.... Silent or not, it has just been changed to a "You know the risk, the page isnt signed, go ahead at your own risk" tick box... Confused?... well, so is everyone else. We NEED a clear conformation that the problem has been fixed. Them saying they know the problem exists is what?.. Them saying they will bring the problem to your attention is what?... YOU now have the decision to make either to go ahead with a still unknown risk or not?... How does that help?... I say its confusing the matter. By the way, if I have the choice, if the page is Unsigned, it should be automatically blocked. What is the "Unsigned" significance?... Simplified, the signature says its been tested and is safe...... If its NOT been tested, it may be safe or it may not... that is not, should not, be our problem.... if someone produces a page or app or anything in Java, its their duty to get a signature that says its safe to use, and if they dont, DONT TRUST THEM..... As in, would you trust a person who says he is a electrician rewire your whole house unless you had proof of their qualifications?...
|
|
|
Post by silverdragon on Jan 15, 2013 10:08:59 GMT
By the way, my own opinion, if Java owners Oracle make an update that refuses completely to allow any form of Unsigned App to work anywhere but outside the developers own system, the problem will go away, because it will force all Java developers to get their bloody work signed off before they release it into the wild wouldnt it?.....
I have a simplistic view on how the world should work.?.?.
|
|