Java still risky, even after security update: US
Washington, January 15, 2013
The US Department of Homeland Security warned that a security update of Oracle Corp's Java software for Web browsers does not do enough to protect computers from attack, sticking to its previous advice that the program be disabled.
"Unless it is absolutely necessary to run Java in web browsers, disable it," the Department of Homeland Security's Computer Emergency Readiness Team said on Monday in a posting on its website.
The software maker released an update to Java on Sunday, just days after the government issued its initial warning on the software, saying that bugs in the program were being exploited to commit identity theft and other crimes.
Security experts have warned that PCs running Java in their browsers could be attacked by criminals seeking to steal credit-card numbers, banking credentials, passwords and commit other types of computer crimes.
The Java software platform, created in the mid-1990s, enables developers to write one set of code that will run on PCs running on Microsoft Corp's Windows, Apple Inc Macs and servers running on the Linux operating system.
Security experts say the bugs only affect one part of the platform - software that plugs into Internet browsers.
While some researchers have long complained the software was buggy, it started generating more public scrutiny last year after a security scare in August..
"It's not like Java got insecure all of a sudden. It's been insecure for years," said Charlie Miller, a computer engineer with Twitter who has previously worked as a security consultant to Fortune 500 firms and as an analyst with the National Security Agency.
Java was responsible for 50 percent of all cyber attacks last year in which hackers broke into computers by exploiting software bugs, according to Kaspersky Lab.
Public interest in the issue surged last week as the Department of Homeland Security advised the general public to stop using Java and consumers turned for information on how to implement the agency's advice.
To disable Java on a Windows PC, go to the machine's Control Panel. Open the Java icon, click on the Security panel and uncheck the box for "enable Java content in the browser."
Further information is available from Oracle on its Java website. - Reuters
More IT & Telecommunications Stories
- Kuwait moves to create telecoms watchdog
- Batelco backs Royal Fund for Martyrs
- Egypt's Global Telecom posts $749m Q4 loss
- Red Hat launches open source BPM suite
- Batelco announces new board
- Batelco offers improved broadband
- You don't own phone numbers, warns TRA
- Tech giants back top Qatar ICT event
- Du to provide wifi access in public areas
- Zain finalises $800m, five-year loan facility
- Ooredoo Q4 net profit falls 36pc to $140m
- Mobily, Etisalat team up for LTE roaming
- Batelco approves $84m dividends for 2013
- Etisalat Q4 profit rises 70pc to $394m
- Kenya telecom firm to join Etisalat SmartHub
- Aruba appoints new sales director
- Du enters $1.17 billion financing deals
- VIVA extends 4G LTE offer
- Batelco to update students with latest technologies
- Etisalat SmartHub seals IPX agreement
- Etisalat picks Alcatel for LTE network expansion
- Boeing, QCRI host machine learning forum
- Mobily provides 4G LTE international roaming
- Viva Kuwait, Huawei to set up innovation centre
- Etisalat, Airtel deal to boost network services
- Batelco offers 4G LTE backup solution
- Arbor unveils ‘Peakflow’ solution
- Etisalat launches enterprise mobility services
- STC launches advanced 4G network
- Dubai to host ITU global summit