Earlier quoted context omitted.
If you visit a malicious site and click anywhere on the page (not on a plugin) then you could enable a click 2 play plugin. i raised this as a chrome bug and they said click 2 play is not a security feature. there may be even worse bypasses :( the only way to have proper security is to disable the plugin. there is a button on the address bar that allows you to enable plugins on a page when they have been disabled. th…
Wow...well thats good to know! Doesn't really make sense, especially when you load say a YouTube webpage and it says "click to RUN adobe flash". That is really misleading! :\
New Java 0-Day Vulnerability Being Exploited in the Wild
21–30 of 80 posts
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#22Earlier quoted context omitted.
Are you sure? As far as i understand it until you click on the plugin the plugin is not loaded at all.
I can't reply further down the comment thread, but can you provide an official source on this. I enabled this feature last week, and there's no way of interacting with the plugin until I click on it.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#23Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#24Earlier quoted context omitted.
Yes - also even a user who only wants to use client side Java outside of the browsers may be in trouble because of the automatically installed browser plugins that are part of the Java installation process. It's incredible how far and fast client side Java has fallen because of Oracle's tepid response to security concerns. I've developed many internal apps for client-side Java and supported them for over a decade. I…
It has nothing to do with Oracle's response -- the Java sandbox is simply broken, and has been known to be broken for at least the last 5 years. There's no fixing it, the approach is fundamentally flawed and fundamental to Java. This doesn't mean that Java for client-side applications is broken, as long as you don't rely on web based distribution and browser sandboxing.
I don't know. Java on the desktop requires administrator privileges to be able to notify me that an update is available. Also, it tries to install a virus in the form of "Ask toolbar" every frigging time.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#25Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#26To disable the java plugin temporarily in Chrome, you can use chrome://plugins
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#27To disable the java plugin temporarily in Chrome, you can use chrome://plugins
Or permanently. I have never found a use for the Java plugin in my browser. And for all other plugins I have click-to-play enabled.
We have a web based VPN tool that has to use Java.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#28...Maybe we could post news stories and not statements about 0 days being used because they're 0 days(especially if it's a Java or Flash 0 day)?
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#29Earlier quoted context omitted.
Or permanently. I have never found a use for the Java plugin in my browser. And for all other plugins I have click-to-play enabled.
I use Java in the browser. The way you use your computer is not the same other people may use theirs. We have a web based VPN tool that has to use Java.
Re: New Java 0-Day Vulnerability Being Exploited in the Wild
#30Earlier quoted context omitted.
It has nothing to do with Oracle's response -- the Java sandbox is simply broken, and has been known to be broken for at least the last 5 years. There's no fixing it, the approach is fundamentally flawed and fundamental to Java. This doesn't mean that Java for client-side applications is broken, as long as you don't rely on web based distribution and browser sandboxing.
"This doesn't mean that Java for client-side applications is broken[...]" I don't know. Java on the desktop requires administrator privileges to be able to notify me that an update is available. Also, it tries to install a virus in the form of "Ask toolbar" every frigging time.