Security Experts Advise Users to Ditch Java

Status
Not open for further replies.

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
After installing an operating systems on their computing machines, most individuals rush to install applications that help them browse the web. While many believe that without components such as Flash and Java they won’t be able to access certain content, there are always safer, more secure, alternatives.

F-Secure researchers report that many people use Java, but in reality they don’t need it, its presence only giving cybercriminals the opportunity to exploit the device it’s installed on.

The main issue is that a lot of Internet users confuse Java with JavaScript, a crucial component for the web.

“If you're running Java, but not the latest version, you're vulnerable. So either you have to check at all times that you have the latest version of Java — or get rid of it altogether,” said F-Secure’s Mikko Hypponen

After studying the infamous Blackhole exploit kit’s control panel, the experts discovered that more than 16,000 computers were taken over using the Java Rhino vulnerability.

If you really need Java for online banking or other Internet apps, it’s recommended that you install the Java plug-in in a separate browser that you utilize only for the specific tasks, allthough, many have discovered that after uninstalling the dangerous component, their daily activities are not affected in any way.

Read More
 

moonshine

Level 7
Verified
Apr 19, 2011
1,264
I ain't ditching Java because I use Java for some applications. I'm protected because I always use the latest version and I'm using EMET.

P.S I'm aware of the consequences.
 

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
Just decided last week to removed Java since there is no reason to use it beside if its really necessarily. Adobe Flash player is a must since mandatory of the videos around the web were used.
 

MrXidus

Super Moderator (Leave of absence)
Apr 17, 2011
2,503
jamescv7 said:
Just decided last week to removed Java since there is no reason to use it beside if its really necessarily.

If necessary, I open up a Windows 7 VM that has Java installed. Then flash wipe the VM afterwards.
 

Tom172

Level 1
Feb 11, 2011
1,009
If you require Java, keep it updated. If you don't need it, remove it. What more needs to be said.

True, if you want to be more cautious, run it Sandboxed/Virtual environment.

I removed it promptly after my need for it ended.
 

Ink

Administrator
Verified
Jan 8, 2011
22,490
I need Java for the software I use to transfer media to my PlayStation 3 or stream to TV.

Two issues I have:
1. Runs a process to schedule updates, if not running. No updates received.
2. Updates are set to check every month, by default.
 

MetalShaun

Level 1
Mar 3, 2011
424
Earth said:
I need Java for the software I use to transfer media to my PlayStation 3 or stream to TV.

Two issues I have:
1. Runs a process to schedule updates, if not running. No updates received.
2. Updates are set to check every month, by default.

Ditto. Need it for Ps3 Media Server. I also run it under EMET.
 

Jack

Administrator
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
This Java exploits aren't something new, they have been happening from years now ... Most of the exploit are successful because people don't update their Java and cyber criminals take advantage of those security holes.....Like the guys from F-Secure said Java is need it only by a few people so if you don't need it , just unistall it because it's hard to always keep your eyes open for updates... For instance I have checked my Firefox Java plugin an found that it was out of date.......
 

Tom172

Level 1
Feb 11, 2011
1,009
Jack said:
This Java exploits aren't something new, they have been happening from years now ... Most of the exploit are successful because people don't update their Java and cyber criminals take advantage of those security holes.....Like the guys from F-Secure said Java is need it only by a few people so if you don't need it , just unistall it because it's hard to always keep your eyes open for updates... For instance I have checked my Firefox Java plugin an found that it was out of date.......

That's where something like Secunia PSI comes into play ;)
 

Prorootect

Level 69
Verified
Nov 5, 2011
5,855
Hey, maybe I'm also 'security expert'?:D I'm kidding.

But look at this, Posted: 02 February 2010 at 4:22pm: http://forum.sysinternals.com/topic21844.html
 

Ramblin

Level 3
May 14, 2011
1,014
I got rid of Java more than 2 years ago. I think if a user has no use for it, its better off to uninstall it. If its needed sporadically then it can be installed in a sandbox that gets deleted after using it. In my opinion, only users that need Java for work should have it in their computer.

Bo
 

jamescv7

Level 85
Thread author
Verified
Honorary Member
Mar 15, 2011
13,070
Any OS were vulnerable especially like Java is installed and can be easily exploit at any kind of vectors.
 

LochNess

New Member
Apr 2, 2011
87
"Ditched" long ago... one less exploit, but not the 'target' it once was... too bad that 'Web-Forest' if full of so many 'Scarey Creatures'... :-(
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top