One veteran's perspective on the Iran deal » The White House, Washington I was in the first company of Marines to enter Baghdad in 2003. As a co... Muhammadu Buhari: A Nepotist and Mujahid in Govern... » SERIES: BUHARISM AND THE FIERCE URGENCY OF NOW Acts of a President with a mustard seed-mind and a ... Muhammadu Buhari: A Nepotist and Mujahid in Govern... » SERIES: BUHARISM AND THE FIERCE URGENCY OF NOW Acts of a President with a mustard seed-mind and a ... UK lockmakers meet the lock attack challenge » UK police are continuing to warn householders about the vulnerability of domestic entrance door lock... Executive cyberstrategy sessions unite senior ex... » Medford, NJ: Watchful Software has announced the launch of its new Global Thought Leadership Program... Matrix42 launches new package manager for Microsof... » London: Matrix42 has announced the latest release of its new Package Manager solution. Administrator... Peplink helps innovative Sao Paolo School solve ... » Peplink has announced a successful project with Colégio Next, a school in Sao Paolo, Brazil that has... Certifigate Found In the Wild on Google Play » New insights on the extent, exploitation, and mitigation of this threat Three weeks ago, Check Poin... TACKLE WORLDWIDE WATER SHORTAGES WITH DIET, SAYS ... » At the start of World Water Week - the forum tackling global water challenges - The Vegan Society ha... 2015 Presidential Election Isuues » After that historical backgrounder in Part I, I shall now examine 4 election issues, the two on ever...

CLICK HERE TO

Viewpoints Header

In response to the news that Oracle has carried out an emergency security update on Java, Lamar Bailey, Director of Security Research and Development at nCircle has the following comments:

 

Here we go yet again. 2013 has seen a surge of critical vulnerabilities in IE, Java and Ruby on Rails. Attackers are targeting cross platform applications to try to obtain access to as many systems as possible using as few exploits as possible.

Oracle has taken a beating this year on Java. It is good to see they are fixing critical vulnerabilities in a code base they want to quit updating but it is past time for them to get serious and do a deep dive on Java to fix the security issues.

I have always thought Oracle did a good job of securing their products but I am losing some of my faith in them with the rash of Java vulnerabilities. I hope these security problems are not found in their other products. My advice to end users is to remove Java from your system and only install it when is needed to access a business critical application, then if possible run Java in a VM or an isolated environment. This is easier said than done as my Windows box had no less that 4 Java versions with various updates. I hope Oracle will assign a team of their best security engineers to Java to squash any of the remaining security issues. Until then many users will be updating Java as often as they update AV signatures.