Do you need to uninstall Java to be safe from its vulnerabilities? | Security & Privacy - CNET News (http://news.cnet.com/8301-1009_3-57564316-83/do-you-need-to-uninstall-java-to-be-safe-from-its-vulnerabilities/)
'"
n".self::process_list_items("'.str_replace('
', '', '
- 14 comments (http://news.cnet.com/8301-1009_3-57564316-83/do-you-need-to-uninstall-java-to-be-safe-from-its-vulnerabilities/#postComments)
- Facebook (http://www.facebook.com/share.php?u=http%3A%2F%2Fnews.cnet.com%2F8301-1009_3-57564316-83%2Fdo-you-need-to-uninstall-java-to-be-safe-from-its-vulnerabilities%2F)158
- Twitter (http://twitter.com/share?url=http://cnet.co/13FpQLv&counturl=http%3A%2F%2Fnews.cnet.com%2F8301-1009_3-57564316-83%2Fdo-you-need-to-uninstall-java-to-be-safe-from-its-vulnerabilities%2F&via=CNET&text=Do%20you%20need%20to%20uninstall%20Java%20to%20be%20safe%20from%20its%20vulnerabilities?&&related=)7
- Linked In2
').'")."n[/list]"'
With the latest security holes coming to light, many are recommending removing Java entirely from your system. If you don't want to go that far, here are some things you can do.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset1.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F04%2F04%2Fheadshots_Topher_Kessler_140x100_60x43.jpg&hash=0f73dea232ac9e61bbfbcbe6ca4242d37c46b3d2) (http://www.cnet.com/profile/tkessler/) by Topher Kessler (http://www.cnet.com/profile/tkessler/)
January 16, 2013 6:19 PM PST
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset1.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F04%2F03%2FJavaIconX_90x90.png&hash=e50df64512c35c832c820756e00959459a194eca)
Lately Java has been getting a bit of bad press (http://reviews.cnet.com/8301-13727_7-57563567-263/new-malware-exploiting-java-7-in-windows-and-unix-systems/), thanks to several consecutive security holes that have been exploited by malware developers. One notable occurrence was the Flashback malware (http://reviews.cnet.com/8301-13727_7-57408383-263/flashback-malware-evolves-to-exploit-unpatched-java-vulnerabilities/) threat that affected a number of OS X users, which (though due in part to Apple's negligence about Java upkeep) was rooted in the Java runtime. More recently, Java 7 has seen a new zero-day vulnerability that has been circulating in exploit kits.
In response to these threats, many in the tech community have recommended that people uninstall Java altogether. However, this can be impractical for some, as many people need Java to run applications, including Web apps and a number of technical and creative development tools.
Related stories'"
n".self::process_list_items("'.str_replace('
', '', '
- Homeland Security still advises disabling Java, even after update (http://news.cnet.com/8301-1009_3-57563951-83/homeland-security-still-advises-disabling-java-even-after-update/)
- Oracle releases software update to fix Java vulnerability (http://news.cnet.com/8301-1009_3-57563730-83/oracle-releases-software-update-to-fix-java-vulnerability/)
- New malware exploiting Java 7 in Windows and Unix systems (http://news.cnet.com/8301-13727_7-57563567-263/new-malware-exploiting-java-7-in-windows-and-unix-systems/)
').'")."n
"'
When it comes to the security of your system, uninstalling Java completely is certainly one way to avoid problems arising from it, but it is a bit of an extreme measure. So, how do you secure your system while keeping a potentially faulty runtime installed?
There are two aspects to Oracle's Java installation. The first is the runtime itself, which consists of the libraries and execution environment that allow your system to execute Java programs. The second component of the installation is the Web plug-in, which interfaces these libraries with the browser to allow hosted Web applets to run.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset2.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2013%2F01%2F16%2FSafariEnableJava_270x118.png&hash=701dd137537f824c82d6f050a940755640ce892b) (http://i.i.com.com/cnwk.1d/i/tim/2013/01/16/SafariEnableJava.png)
In older versions of Java (1.6 or earlier) Safari's security preferences could be used to disable Java, but this is now done in the Java Control Panel in the system preferences.
(Credit: Screenshot by Topher Kessler/CNET)
The vast majority of Java's security problems revolve around the use of the Java plug-in. While the vulnerabilities ultimately exist in the runtime, the plug-in is the avenue that malware developers use to exploit these remotely. You are somehow tricked into loading a Web page that contains a malicious Java applet, which exploits the fault and loads malware on to your system. If you close this off or otherwise manage it, then you will vastly improve the security of your system, and can continue to use Java for other purposes without needing to remove it completely.
There are several ways to do this. In the latest Java runtime, you can access the Java Control Panel and in the security settings uncheck the option to "Enable Java content in the browser." This will effectively close the door between Java and Web sites you visit, so Java applets will not run. While technically the security vulnerabilities are still open with this setting, you would need to manually download a Java executable and purposely run it on your system.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset1.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2013%2F01%2F16%2FClickToPluginSafari_270x248.png&hash=0f71d22d170fe2726ed55febd5fcd576452d380e) (http://i.i.com.com/cnwk.1d/i/tim/2013/01/16/ClickToPluginSafari.png)
When ClickToPlugin is enabled, your plug-in content is shown like this, and only is active if you explicitly click it.
(Credit: Screenshot by Topher Kessler/CNET)
The second option is the use of security levels in determining which Java code is allowed to run. Similar to Apple's Gatekeeper feature in Mountain Lion, which can restrict running applications to signed code or apps specifically from the Mac (http://www.cnet.com/apple-mac.html) App Store, Java's security levels can require that you approve any unsigned applications or even approve all code regardless of its signature. To do this, in the same Security section of the Java control panel, you can drag the security level slider to High, which allows only signed programs to run, or Very High, which requires approval for all code.
Beyond Java's built-in security measures, you can also use some third-party tools to help prevent malicious Java applets from running on your system. While disabling the Java plug-in is perhaps best, if you regularly visit Web sites that require Java, then doing this can be a burden to your work flow. Therefore, instead use a plug-in manager such as ClickToPlugin (http://hoyois.github.com/safariextensions/clicktoplugin/) that will block not only Java but also Flash and other plug-in content as well. The benefit here is instead runnng of the blocked content, you'll receive a notification that you can click to quickly allow it to run. Also, you can customize a whitelist of sites that are automatically allowed to work.
Some browsers like Chrome come with a click-to-play option, which can be seen by going to Chrome's content settings (Copy and paste this URL into Chrome to get to these settings: chrome://chrome/settings/content#click) and selecting the "Click to play" option in the Plug-ins section. For those who use Firefox (http://www.cnet.com/firefox-3/), the NoScript plug-in (http://noscript.net) is a very effective approach to managing unwanted execution of plug-ins and other Web-based content.
A final approach to help protect your system is to monitor outgoing traffic using a reverse firewall tool like Little Snitch (http://download.cnet.com/Little-Snitch/3000-2144_4-10753388.html). With such a tool installed, whenever a program tries to contact an external server, the system will notify you and give you options to allow or deny the attempt, and also provide you with information to investigate what process is making the request.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset0.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F09%2F25%2FLittleSnitchResearchAssistant_270x136.png&hash=8518e81d75698dffe38c84d108718684571dc5f3) (http://i.i.com.com/cnwk.1d/i/tim/2012/09/25/LittleSnitchResearchAssistant.png)
When Little Snitch detects an outgoing connection, it will notify you and provide information on what the process is and who it is attempting to contact.
(Credit: Objective Development (http://www.obdev.at/products/littlesnitch/index.html))
While this is a bit of a tangential approach to dealing with faults in Java, it has been a very useful and effective way to detect malicious behavior on systems in the past and was integral to the early detection of the Flashback malware in OS X (http://reviews.cnet.com/8301-13727_7-57519904-263/monitor-outbound-traffic-with-little-snitch-3/). While such firewalls may not prevent malware from exploiting your system, they can prevent it from carrying out its primary purpose, which is to communicate personal information to an external server and open up unwanted command and control ports in the system.
Overall, while Java has seen its fair share of problems and exploits recently, and although the most secure route is to uninstall Java and avoid using it, this is not necessary to keep your system secure. With plug-in management, higher security settings for Java, and reverse firewalls to detect malicious activity, you can still keep Java installed for the purposes you need while giving yourself an advantage in fighting the tricks that malware uses to cause problems in your system.
How to disable Java in IE, Firefox, Chrome, and Safari | How To - CNET (http://howto.cnet.com/8301-11310_39-57523821-285/how-to-disable-java-in-ie-firefox-chrome-and-safari/)
The unpatched Java vulnerability reported last week could be exploited by malware to infect your system, although no such infections have been discovered to date.
(http://www.cnet.com/profile/doreilly/) by Dennis O'Reilly (http://www.cnet.com/profile/doreilly/)
October 1, 2012 4:28 PM PDT
Last week's notice by researchers at Security Explorations (http://seclists.org/fulldisclosure/2012/Sep/170) of an unpatched hole in the Java runtime environment may have left you wondering whether to disable Java until Oracle releases a patch. CNET's Topher Kessler noted in his report on the Java flaw (http://news.cnet.com/8301-1009_3-57520532-83/new-java-flaw-could-hit-1-billion-users/) that no malware exploiting the vulnerability has yet been documented.
Which leads to the question, "Do I need Java?"
The best way to find out is to disable Java in your browser and re-enable it only if you encounter a site that prompts you to download Java before it will open. Then you can activate the Java plug-in by following the steps below in reverse, and perhaps disable the plug-in again after you leave the site.
(While researching this topic I discovered that one of my test PCs has been browsing flawlessly for more than a year without the Java runtime environment installed.)
These steps will disable Java in Internet Explorer 9, Firefox (http://www.cnet.com/firefox-3/) 15.0.1, Google Chrome 22, and Safari (http://download.cnet.com/mac/browsers/2001-2137_4-0.html) 6.0.1. If you're using an older version of these browsers, update to the latest release. (More information on software updaters is found at the end of this post.)
Disable Java in IE 9 via the 'Manage add-ons' option
Click IE 9's gear icon in the top-right corner of the window and choose "Manage add-ons." Select Toolbars and Extensions in the left pane under Add-on Types and scroll to the entry for the Java plug-in under "Sun Microsystems Inc." Choose the Java entry and click Disable in the bottom-right corner.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset2.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F10%2F01%2F10_01_12_Java_IE1_610x424.jpg&hash=4c7ddd00c0052f0851fa4ac9ff9b95fbca8b71e3) Disable Java in Internet Explorer 9 by opening Manage Add-ons, selecting the Java entry, and clicking Disable.
(Credit: Screenshot by Dennis O'Reilly/CNET)
The next time you start IE, a notice will appear at the bottom of the window informing you that the Java plug-in is ready to use. Click the "Don't enable" button or the x on the right of the pop-up to continue browsing Java-free.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset2.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F10%2F01%2F10_01_12_Java_IE5.jpg&hash=ae32243daaef4565fab0caea1099cd64a892a451) After you disable Java in IE you'll be prompted to enable the plug-in the next time you open the browser.
(Credit: Screenshot by Dennis O'Reilly/CNET)
Firefox's Java plug-in can be disabled in a jiffy
To prevent the Java plug-in from running in Firefox, click Tools > Add-ons to open the browser's add-on manager. (If you don't see the menu at the top of the Firefox window, press the Alt key.) Choose Plugins in the left pane, scroll to the entry for the Java plug-in, and click its Disable button.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset1.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F10%2F01%2F10_01_12_Java_Firefox6%283%29_610x292.jpg&hash=f974db252a559625257b4577cd5f67416ad301aa) Disable Firefox's Java plug-in via the browser's Add-on Manager.
(Credit: Screenshot by Dennis O'Reilly/CNET)
(When I checked this Firefox setting on one of the PCs in my home office the Java SE 6 plug-in had been disabled automatically because Firefox identified it as vulnerable. Updating to Java SE 7 re-enabled the plug-in in Firefox automatically.)
Turn off Java in Google Chrome
You can disable Java in Chrome by entering "chrome://plugins" in the address bar and pressing Enter to display a list of the browser's plug-ins. Scroll to the entry for Java and click Disable.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset3.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F10%2F01%2F10_01_12_Java_Chrome4.jpg&hash=864929370033298eeacd346729b2e401b3fa54e2) Click Disable under the entry for Java in Google Chrome's list of plug-ins to prevent the add-on from running automatically.
(Credit: Screenshot by Dennis O'Reilly/CNET)
Put Java on the shelf in Safari
To shut down Java in Safari, click Safari > Preferences (or press Command-,), select the Security tab at the top of the window, and uncheck Enable Java.
(https://www.abibitumikasa.com/proxy.php?request=http%3A%2F%2Fasset0.cbsistatic.com%2Fcnwk.1d%2Fi%2Ftim%2F2012%2F10%2F01%2F10_01_12_Java_Safari7a_610x209.jpg&hash=d70d5a2b398e4f3a741cd5a3cf8d03c0f0e9fc3b) Open Safari's Preferences window and choose the Security tab to disable Java in Apple's browser.
(Credit: Screenshot by Dennis O'Reilly/CNET)
A word about drive-by downloads
Every time I write about Java or Adobe's Flash Player, I begin my making sure I have the most recent versions of the plug-ins. And every time I update the two programs manually I'm prompted to download a free security scanner: McAfee Security Scanner for Java and Norton Security Scan for Flash.
It's bad enough that the scans aren't directly related to Java or Flash, but in both instances the option to scan your system is selected by default. People in a hurry will click OK to install the update without realizing they're getting more software than they expect. Unless you want to prolong the update process by adding a malware scan you may not need, be sure to uncheck the scan options whenever you update either plug-in.
Also, the confusion between Java and JavaScript continues unabated. The two technologies are unrelated despite their similar names. While JavaScript poses its own potential security problems, the scripting language is not affected by Java vulnerabilities.
If your browsers and other programs are updated with the latest versions, there's probably no need to disable JavaScript. For more on keeping your software up-to-date, read my review of three free patch-management utilities (http://news.cnet.com/8301-13880_3-20065201-68.html) from May 2011.
@Ajamu..yup that's what I was talking about, you proved the finite details.