WARNING: Disable Java! Really?

There has been a lot of warnings about Java in recent days. It’s a
complicated issue. If you want to better understand the issues, Google
“Homeland Security java disable”. There are lots of articles. Here are
a few:

http://www.zdnet.com/homeland-security-warns-to-disable-java-amid-zero-day-flaw-7000009713/?s_cid=e589

http://www.dailymail.co.uk/news/article-2261318/Americans-warned-Homeland-Security-warning-disable-Java-computers-Java-avoid-hacking-attacks.html?ito=feeds-newsxml

This is the alert that started it all:
Oracle Java 7 Security Manager Bypass Vulnerability
http://www.us-cert.gov/cas/techalerts/TA13-010A.html

We know that Java has many unpatched vulnerabilities and has had for
some time but AFAIK this is the first time that the United States
Computer Emergency Readiness Team has recommended uninstalling.

For most of my customers, this is impractical. I’m trusting on my
security software to catch any malicious software before it is
installed. It’s not a perfect solution but what are the alternatives?

How are you dealing with this?


Kevin Boyle - Knowledge Partner
If you find this post helpful and are using the web interface,
show your appreciation and click on the star below…

KBOYLE wrote:
[color=blue]

There has been a lot of warnings about Java in recent days. It’s a
complicated issue. If you want to better understand the issues, Google
“Homeland Security java disable”.

How are you dealing with this?[/color]

Yeah I saw that a day or two ago. Personally the way I think folks
should deal with this is by using ZENworks Patch Management to make
sure they always have the latest version of Java.


Does this washcloth smell like chloroform?

On 12/01/2013 21:11, KBOYLE wrote:[color=blue]

For most of my customers, this is impractical. I’m trusting on my
security software to catch any malicious software before it is
installed. It’s not a perfect solution but what are the alternatives?[/color]

At least in theory, you should be able to run java in a “cloud” style
environment with full isolation; in fact, I am looking forward to the
day when you can run any browser and have that be true (that hardware
accelerated visualization on-chip is used to hard-sandbox each tab)
[color=blue]

How are you dealing with this?[/color]
One way to use Java without exposing it to risk is to have it on a
dedicated citrix host, limited to just talking to the internal resources
that need Java (usually internal CRM and other solutions) and push out
as a delivered app to the users.

Its a lot of work though, to work around the fact that java security is
a joke and Oracle more concentrating on monetizing their “IP” and suing
Google than actually improving the security and functionality.

Dave Howe wrote:
[color=blue]

At least in theory, you should be able to run java in a “cloud” style
environment with full isolation;[/color]

I wonder if ZENworks Application Virtualization could help!


Does this washcloth smell like chloroform?

Joseph Marton wrote:[color=blue]

KBOYLE wrote:
[color=green]

There has been a lot of warnings about Java in recent days. It’s a
complicated issue. If you want to better understand the issues, Google
“Homeland Security java disable”.

How are you dealing with this?[/color]

Yeah I saw that a day or two ago. Personally the way I think folks
should deal with this is by using ZENworks Patch Management to make
sure they always have the latest version of Java.
[/color]

Except the CERT warning includes Java 7 Release 10, which is the latest!

Supposed to be an update by Thursday, they say.

On 1/14/2013 2:59 PM, DE wrote:[color=blue]

Joseph Marton wrote:[color=green]

KBOYLE wrote:
[color=darkred]

There has been a lot of warnings about Java in recent days. It’s a
complicated issue. If you want to better understand the issues, Google
“Homeland Security java disable”.
How are you dealing with this?[/color]

Yeah I saw that a day or two ago. Personally the way I think folks
should deal with this is by using ZENworks Patch Management to make
sure they always have the latest version of Java.
[/color]

Except the CERT warning includes Java 7 Release 10, which is the latest!

Supposed to be an update by Thursday, they say.[/color]

And now this:

http://betanews.com/2013/01/14/java-7-update-11-security-patch-fixes-nothing/?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed±+bn±+Betanews+Full+Content+Feed±+BN

http://preview.tinyurl.com/ajc26q8

Which says all the "emergency patch that quickly fixed everything "
released on Sunday does is set security to “high”.

So the government still says:

“As a result, the Department of Homeland Security’s Computer Emergency
Readiness Team has recommended users should actually disable Java from
running in web browsers – even after applying the latest update”