NIGERIA HIGH COMMISSION, UNITED KINGDOM: CALLING O... » KIND ATTENTION: Dr. Dalhatu Sarki Tafida, OFR, CFR Your Excellency, When are you going to issue a ... Ricardo-led tactical truck technology demonstratio... » Analysis of defense vehicle project proves techniques for reducing fuel consumption – after two year... Defence Secretary visits UK Forces Training Malian... » Secretary of State for Defence Philip Hammond has paid tribute to the Armed Forces personnel helping... SaaSID celebrates company milestones » Basingstoke, UK: Web application security provider, SaaSID, is celebrating a number of company miles... ALVEA infrastructure services chooses Flexiant Clo... » London, UK: Flexiant, a leading international provider of cloud management software, has announced t... A10 Networks and Brocade reach settlement of legal... » SAN JOSE, CA: A10 Networks™, the technology leader in Application Networking, has announced that it ... CESG and Cellcrypt to develop MIKEY-SAKKE technolo... » London, UK: Cellcrypt, a leading provider of encrypted voice calling and messaging for smartphones a... Attack in London » Acting Deputy Spokesperson, Office of the Spokesperson Washington, DC May 22, 2013 Denunciation of the Woolwich - London Horrific Mur... » As a Muslim leader representing many Muslims around the World, especially the UK, I want to express ... What happened yesterday in Woolwich has sickened u... » Statement on Woolwich incident Organisations: DAVID CAMERON, BRITISH PRIME MINISTER Cabinet Office...

Viewpoints Header

In response to the news that Oracle has carried out an emergency security update on Java, Lamar Bailey, Director of Security Research and Development at nCircle has the following comments:

 

Here we go yet again. 2013 has seen a surge of critical vulnerabilities in IE, Java and Ruby on Rails. Attackers are targeting cross platform applications to try to obtain access to as many systems as possible using as few exploits as possible.

Oracle has taken a beating this year on Java. It is good to see they are fixing critical vulnerabilities in a code base they want to quit updating but it is past time for them to get serious and do a deep dive on Java to fix the security issues.

I have always thought Oracle did a good job of securing their products but I am losing some of my faith in them with the rash of Java vulnerabilities. I hope these security problems are not found in their other products. My advice to end users is to remove Java from your system and only install it when is needed to access a business critical application, then if possible run Java in a VM or an isolated environment. This is easier said than done as my Windows box had no less that 4 Java versions with various updates. I hope Oracle will assign a team of their best security engineers to Java to squash any of the remaining security issues. Until then many users will be updating Java as often as they update AV signatures.