Homeland Security says: "Disable Java"

Discussion in 'The Lounge' started by gman863, Jan 12, 2013.

  1. gman863

    gman863 MajorGeek

    According to the US Dept. of Homeland Security, having a good anti-virus program is not enough. Based on their analysis of things like ID theft and making your PC part of an ad-hoc attack network, Homeland Security is now advising people to disable Java in all browsers:

    http://www.chicagotribune.com/busin...sers-to-disable-java-20130111,0,5686660.story

    Based on the story, it appears Oracle is in "no comment" mode. Again, it appears this warning is directed to users of all OS (Win, Mac, Linux - possibly even Android) and all browsers (IE, Firefox, Safari, Chrome, etc.).

    I'm anxious for the Malware Experts to weigh in on this one.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. gman863

    gman863 MajorGeek

    Tim: Sorry that I missed that link.
     
  4. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    I'm using Palemoon. I don't see Java in my add-ons (which I'm surprised at). Does that mean it's not installed?

    Jeez...if these idiots would use their abilities for things that are good, I bet a lot of problems in this world could be eradicated.
     
  5. Goldenskull

    Goldenskull I can't follow the rules

    I am pretty sure they will get it fixed in next patch if they haven't got it fixed all ready.
    I think it is just another scar tactic bye the government.
    If it every happens to me all i need to do is wipe my Hdd and reinstall lol:-D
    I never have back ups be cause i do not need them this is a gaming computer.

    That is way i can do a Full format of HD.

    I never keep any thing to important on my HD My desktop is scanned nightly and cleaned nightly auto.Any thing i do have important i remember every thing or my bank has all ready taken care of it.

    And if i do keep important stuff on my computer it is backed up on a big flash drive and not my main HD.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  7. solaris89

    solaris89 First Sergeant

    Yup, you got it. I work for a government agency and in a meeting the other day they discussed micro-chipping everyone and putting out fake Java warnings.

    rolleyes
     
  8. cipher

    cipher Major Geek Extraordinaire


    Did I miss Yet Another Secret Meeting? I should go ahead and turn in my decoder ring now I suppose... ;)
     
  9. solaris89

    solaris89 First Sergeant

    The newer model Decoder rings use Java; might want to turn it in ASAP. :-D
     
  10. Triaxx2

    Triaxx2 MajorGeek

    Strange. My decoder ring doesn't use Java.
     
  11. Goldenskull

    Goldenskull I can't follow the rules

    kinda joking a little :-D
     
  12. cabbiinc

    cabbiinc Staff Sergeant

    I can't decode anything without having three or four cups of Java first.
     
  13. satrow

    satrow Major Geek Extraordinaire

    Check the Plugins section (anything there can be enabled/disabled 'on the fly' anyway - unlike Java in IE!) then check Control Panel > All Control Panel Items for the Java applet - even if you don't find it there, it could still be on the system as the Java installer can be buggy, search for javacpl.exe, usually found in C:\Program Files\Java\jre7\bin or C:\Program Files (x86)\Java\jre7\bin.



    Some (fairly) easily digestible details on this latest Java vulnerability here: What You Need to Know About the Java Exploit

    One of the basic 'problems' is that Oracle only patch their products on a 4 monthly cycle and patches out of cycle are pretty rare - even then, take up of the latest version is very slow, this gives the bad guys a big target to aim at over an extended period.
     
  14. solaris89

    solaris89 First Sergeant

    I should have figured that; I usually get a laugh reading your posts anyway ;)
     
  15. gman863

    gman863 MajorGeek

    Since Java is also used in cars, appliances and parking meters does this mean Stephen King's "Maximum Overdrive" may become reality? :-D
     
  16. Goldenskull

    Goldenskull I can't follow the rules

    I many ways that would be sweet :-D:-D
     
  17. Sgt. Tibbs

    Sgt. Tibbs Ultra Geek

    Dammit! My sister promised me if something like that came up she would let me know! Unless she doesn't work for the agency in charge of this one...:confused
     
  18. Triaxx2

    Triaxx2 MajorGeek

    That's what we get for trusting all these Javanese programmers with national security. They just want to be left alone...
     
  19. Phantom

    Phantom Brigadier Britches

    So when I drink my daily cup of Java at Starbucks, I will always wonder if I'm being exploited :confused. .roflmao
     
  20. Caliban

    Caliban I don't need no steenkin' title!

  21. Goldenskull

    Goldenskull I can't follow the rules

    May be he he may be there all so putting tiny micro chips into your coffee :-D:-D
     
  22. sibeer

    sibeer MajorGeek

    I only allow Windows to update automatically, so I think I'm behind in my update. My Java Version is 1.6.0_31. Am I ok?
     
  23. dyamond

    dyamond Imelda Marcos of Majorgeeks

    When I opened Firefox to disable Java (thanks to this thread) I noticed it had already been disabled. It's nice to see that Firefox is taking preventive measures for it's users.

    Chrome I had to disable myself. Shame on you Chrome! lol
     
  24. ShelaghRoyale

    ShelaghRoyale Sergeant

    I've disabled JAVA and java scrips and removed all Java updates and program from my hard-drive yesterday when I read it via email security thingy.... I, also removed the java pluggins from my browsers as directed from the Oracle website....anyways... now the Opera browser is frustrating me. I always used Opera, but now I cannot mange my website, because you need java + java scripts to run some stuff.... I am forced to use Internet Explorer, which I hate because that browser is not secure enough.... proof is that Internet Explorer lets me use my website without glitches..... hmmm.... not sure what to do here.... :(
     
  25. Phantom

    Phantom Brigadier Britches

    Yeah, it's a P.I.T.A., I know, but about all you can do is to leave Java disabled by default, but enable it if you are sure what you wish to view/use is 'trusted'. A bit like Active-X used to be not long ago. Hopefully, these buggy, security weak plug-ins will become extinct soon. ;)
     
  26. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Was today's update ( Version: 10.11.2.21) a fix for this?
     
  27. satrow

    satrow Major Geek Extraordinaire

  28. satrow

    satrow Major Geek Extraordinaire

    Allegedly, yes rolleyes until the next hole is found.

    Given that insecure Java is the mainstay route to inject malware these days, by a large margin (~50% of infections?), I'd still suggest people uninstall it fully - only reinstall it (carefully) if it's found that it's really needed.

     
  29. LauraR

    LauraR MajorGeeks Super-Duper Administrator Staff Member

    That's what I did. Just installed it all...figured I'd see if it ever gets used.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds