The Ottumwa Courier

Southeast Iowa

August 30, 2012

Slate: Why you should probably disable Java now

Hackers have found a flaw in Oracle's Java software that allows them to break into users' computers and install nasty malware, security experts report. The attack, first spotted on Sunday by researchers at the security firm FireEye, is what security types call a "zero-day" threat, exploiting a previously unknown vulnerability for which there is currently no fix available.

The loophole appears to affect Java Version 7 (also known as 1.7) on all browsers. So far the attacks have been against PCs, but Mac users are vulnerable as well. Businesses should be especially concerned about targeted attacks, but just about anyone who uses Java on the Internet is at risk, especially since the attack has been added to the Internet's most popular hacking kit, BlackHole.

Given the potential seriousness and pervasiveness of the attacks — and Oracle's reputation for being slow on the draw in response to Java vulnerabilities — experts say that everyday Internet users should probably just disable Java entirely. Like, right now.

"Java has been the most exploited program for well over a year now and it simply isn't worth the risk," Chet Wisniewski of the security firm Sophos told me in an email. "I would recommend removing Java entirely, if you can."

That's not as problematic as it might sound. Java is not as popular on websites as it once was, and the average browser will rarely run across it, Wisniewski says.

To disable Java, you usually don't have to uninstall it from your operating system — you can just disable it in the main browsers that you use. The procedure is slightly different for each browser, but it's actually pretty simple for all of them except Internet Explorer. (One important note: Java should not be confused with Javascript. Disabling Javascript will result in a bunch of websites not working properly, and it won't do anything to address this threat.) Here are the basics for disabling Java:

In Firefox, select "Tools" from the main menu, then "Add-ons," then click the "Disable" button next to any Java plug-ins.

In Safari, click "Safari" in the main menu bar, then "Preferences," then select the "Security" tab and uncheck the button next to "Enable Java."

In Google Chrome, type "Chrome://Plugins" in your browser's address bar, then click the "Disable" button below any Java plug-ins.

If you're an Internet Explorer user, the process is a bit more complex. The blog Krebs on Security summarizes a procedure that "may or may not work." Alternatively, you could uninstall Java from your system, provided you don't need it for some particular application or website that's important to you.

For those who can't live without Java, Wisniewski's blog post at Naked Security offers a few other suggestions.

One final point: This flaw does not appear to affect the previous version of Java (Version 6, aka 1.6), which is the default on most Macs. So while Mac users are theoretically as vulnerable as Windows users, only those who have specifically installed Java 1.7 should be at risk.

Text Only
Southeast Iowa
  • Twitter.jpg Twitter introduces website security tool after AP account hacked

    Twitter is adding a new security tool to its website, making it harder for outsiders to gain access to accounts, a month after a false posting triggered a stock-market decline.

    May 23, 2013 1 Photo

  • chinese restaurant survivors.jpg Siblings withstand storm in fridge

    Brother and sister co-owners of a Chinese takeout restaurant huddled inside a refrigerator to survive Monday’s deadly tornado that claimed 24 lives.

    May 23, 2013 1 Photo

  • 05 23 13 Wayne Chase Pursuit that began in Marion County ends in Wayne County CORYDON — A pursuit that began in Marion County Tuesday evening ended in Wayne County Tuesday night. The two-hour, high speed chase that went through several counties, with an alleged short stint in Missouri as well, involved several agencies with a

    May 23, 2013 1 Photo

  • taylortornadofamily Mom delivered baby as tornado struck

    Shayla Taylor was so far along in labor that her nurses at Moore Medical Center decided not to move her when Monday's tornado hit. They waited out the storm in an operating room, where the wall disappeared as the tornado hit the building.

    May 23, 2013 1 Photo

  • Helping Hands Offering a few helping hands

    Two area women formed a business around the idea that people who have lost loved ones may need assistance in getting estates squared away.

    May 23, 2013 1 Photo

  • preview4.jpg TIMELAPSE: Take a tour through the damage in Moore

    Take a driving tour of the damage in Moore caused by Monday's tornado.

    May 23, 2013 1 Photo

  • Mayor wants tornado shelters in new homes

    Moore Mayor Glenn Lewis wants tornado shelters in all new homes in his city, where an EF-5 tornado damaged or destroyed more than 12,500 homes Monday afternoon. A proposed ordi­nance would require a shelter inside or outside each new residence.

    May 23, 2013

  • Officials release storm survey results

    DES MOINES -- Officials with the National Weather Service have released a report on this week's severe weather, confirming that three tornadoes hit Iowa. That broke a nearly year-long streak without tornadoes in the state.

    May 23, 2013

  • import 1.jpg AUDIO: Residents share their tornado experiences

    Moore, Okla., residents talk about living through Monday's EF-5 tornado.

    May 23, 2013 1 Photo

  • computer.jpg In fan fiction, your favorite characters do what you want them to

    When J.J. Abrams took over the "Star Trek" franchise in 2009, he boldly went where the series hadn't gone before — romantically — pairing Uhura with Spock. Many fans disliked the change. Some loved it. Others didn't care, because they just wanted to see Kirk and Spock make out.

    May 22, 2013 1 Photo

Obituaries

Facebook
Must Read
Community Calendar
Loading…
Events by eviesays.com