{"id":67,"date":"2013-01-24T14:53:28","date_gmt":"2013-01-24T21:53:28","guid":{"rendered":"http:\/\/dshsolutions.com\/wordpress\/?p=67"},"modified":"2013-01-24T14:53:28","modified_gmt":"2013-01-24T21:53:28","slug":"the-java-security-risk","status":"publish","type":"post","link":"https:\/\/dshsolutions.com\/wordpress\/the-java-security-risk\/","title":{"rendered":"The JAVA Security Risk"},"content":{"rendered":"<h1><span style=\"font-size: medium;\">Why everyone should be concerned about Java<\/span><\/h1>\n<div><em>An <a title=\"Windows Secrets\" href=\"http:\/\/windowssecrets.com\/\" target=\"_blank\" rel=\"noopener\">article <\/a>by <a title=\"Woody Leonhard\" href=\"https:\/\/windowssecrets.com\/author\/woody-leonhard\/\" target=\"_blank\" rel=\"noopener\">Woody Leonhard<\/a>, Microsoft Office Expert<\/em><\/div>\n<p>Woody Leonhard is a Windows Secrets senior editor and a senior contributing editor at InfoWorld. His latest book, the comprehensive 1,080-page <a href=\"http:\/\/www.amazon.com\/exec\/obidos\/ASIN\/1118119207\/askwoody-20\">Windows 8 All-In-One For Dummies<\/a>, delves into all the Win8 nooks and crannies.\u00a0 His many writings tell it like it is \u2014 whether Microsoft likes it or not.<\/p>\n<p><strong>Please note, right from the start that Java is NOT JavaScript!\u00a0 Disabling or removing Java on your devices will not cause the wonderful JavaScript apps on most websites to stop running.\u00a0 You can disable or remove Java with impunity!<\/strong><\/p>\n<blockquote><p><span style=\"font-size: 24px;\">&#8220;<\/span><span style=\"font-size: small;\">In the computing world, Java is very nearly ubiquitous. As noted on Oracle&#8217;s Java FAQ <a href=\"http:\/\/www.java.com\/en\/download\/faq\/whatis_java.xml\">site<\/a>, it runs on lots of PCs, but it also runs on &#8220;billions of devices worldwide, including mobile and TV devices.&#8221; Java is not JavaScript, as Susan Bradley notes in her companion <a href=\"https:\/\/windowssecrets.com\/known-issues\/java-more-than-the-usual-cup-of-coding-coffee\/\">piece<\/a>, &#8220;Java: More than the usual cup of coding coffee,&#8221; about what Java is and isn&#8217;t.<\/span><\/p>\n<p><span style=\"font-size: small;\">In this article, I focus on one task \u2014 disabling Java in your Web browser(s). It&#8217;s the most effective way to protect yourself from most Java-based threats. Yes, some PC users still need Java in their browsers to work with specific websites. But most of us have little to lose and much security to gain by keeping our browsers Java-free. (And yes, Mac users should block Java, too.) Java in browsers has been a malware magnet for years \u2014 it&#8217;s unlikely that fact will change anytime soon.<\/span><\/p>\n<p><span style=\"font-size: small;\">I&#8217;m not going to review the most recent round of Java exploits, their patches, or new exploits built onto the backs of Java fixes. Java updates are routinely covered in the twice-monthly Patch Watch column. Brian Krebs has an interesting <strong><i>Krebs on Security<\/i><\/strong> <a href=\"https:\/\/krebsonsecurity.com\/2013\/01\/new-java-exploit-fetches-5000-per-buyer\/\">post<\/a> detailing the latest war between Java security and hackers.<\/span><\/p>\n<h2><span style=\"font-size: medium;\">Scorched earth: Remove Java from all browsers<\/span><\/h2>\n<p><span style=\"font-size: small;\">These days, it&#8217;s common for PC users to use multiple browsers. Most versions of Windows have Internet Explorer installed, and many \u2014 if not most PC users \u2014 are running Firefox or Chrome \u2014 or both. On any PC with multiple browsers, the most effective security policy is to disable Java in <strong><i>all<\/i><\/strong> browsers; then see what, if anything, breaks. Most likely, you&#8217;ll never miss it.<\/span><\/p>\n<p><span style=\"font-size: small;\"><!--more-->Websites requiring Java are on the decline, but if you hit one, you can just move on to a different site. On the other hand, if your bank, brokerage company, or some other critical site requires Java, then you need to limit your Java exposure. (I&#8217;ve been running Java-free for about six months now, and I haven&#8217;t missed it one bit.)<\/span><\/p>\n<p><span style=\"font-size: small;\">Here&#8217;s how to disable Java in all your browsers simultaneously. (Note: some of this information was provided in the Jan. 17 Patch Watch column.)<\/span><\/p>\n<ul type=\"square\">\n<li><span style=\"font-size: small;\"><strong>Step 1. Make sure you have the latest version of Java.<\/strong> My personal preference is to run Secunia PSI (see Fred Langa&#8217;s July 26, 2012, <a href=\"http:\/\/windowssecrets.com\/top-story\/software-that-updates-your-other-software\/\">Top Story<\/a>) and automatically keep up to date on all sorts of software, including Java.<\/span><span style=\"font-size: small;\">If you don&#8217;t have PSI installed, go to the main Java <a href=\"http:\/\/www.java.com\/en\/\">page<\/a> and, under the bright-red &#8220;Free Java Download&#8221; button, click the <strong>Do I have Java?<\/strong> link. Now click the <strong>Verify Java Version<\/strong> button. You should be running Java 7 Update 11 (or later, depending on when you read this column and whether Oracle has its act together). If you don&#8217;t have Java 7 Update 11, go back to the main Java page and click the Java download button. <\/span><\/li>\n<li><span style=\"font-size: small;\"><strong>Step 2. Crank up the Java Control Panel.<\/strong> It&#8217;s typically found in the Windows Control Panel. If you don&#8217;t see it, try typing &#8220;Java&#8221; into the Control Panel&#8217;s search box (upper-right corner of the CP window). In some unusual circumstances, you might have to go directly to the Java Control Panel applet by navigating to it \u2014 <strong>C:\\Program Files (x86)\\Java\\jre7\\bin<\/strong> or <strong>C:\\Program Files\\Java\\jre7\\bin<\/strong> (or something similar) \u2014 and clicking <strong>javacpl.exe.<\/strong> <\/span><\/li>\n<li><span style=\"font-size: small;\"><strong>Step 3. Disable Java in all browsers.<\/strong> In the Java Control Panel, click the Security tab and uncheck the <strong>Enable Java Content in the Browser<\/strong> box (see Figure 1).<\/span><span style=\"font-size: small;\">There&#8217;s a small problem with this setting&#8217;s labeling: The checkbox should say &#8220;Enable Java Content in <strong><i>all<\/i><\/strong> browsers.&#8221; Once unchecked, this setting should disable Java in every browser installed on your system.<\/span>\n<div>\n<p><img decoding=\"async\" title=\"Java Control Panel\" alt=\"The Java Control Panel\" src=\"https:\/\/windowssecrets.com\/wp-content\/uploads\/2013\/01\/W2012-01-24-TS-JavaCP.jpg\" \/><span style=\"font-size: small;\">Figure 1. Unchecking the <i>Enable Java content in the browser<\/i> box disables Java in all installed browsers, simultaneously.<\/span><\/p>\n<\/div>\n<\/li>\n<li><span style=\"font-size: small;\"><strong>Step 4. Click OK and close the Java Control Panel.<\/strong> A couple of important notes on this process. Java is still installed on your PC; it&#8217;s just disabled in browsers. With Java disabled, the Java site will no longer be able to verify the installed version of Java. <\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: small;\">You&#8217;re ready to start surfing the Web with Java reliably turned off in all your browsers.<\/span><\/p>\n<h2><span style=\"font-size: medium;\">Turn off Java in each browser separately<\/span><\/h2>\n<p><span style=\"font-size: small;\">If you must use a site that depends on Java, the best way to limit your Java-exploit exposure is to leave Java enabled in just one browser. Use that browser for sites that need Java, and use a browser with Java disabled for general Web access.<\/span><\/p>\n<p><span style=\"font-size: small;\">That means you&#8217;ll have to leave the &#8220;Enable&#8221; box in the Java CP checked and manually disable Java in specific browsers. It&#8217;s easy to turn off Java in Firefox, Chrome, and Safari, but it&#8217;s unbelievably difficult to turn off Java in Internet Explorer. (Don&#8217;t shoot me \u2014 I&#8217;m just the messenger.)<\/span><\/p>\n<p><span style=\"font-size: small;\">In a perfect world, it&#8217;s best to turn off Java in IE and Firefox but leave it enabled in Chrome, which is smart enough (and polite enough) to explicitly ask you for permission to run a Java program whenever it encounters one (see Figure 2).<\/span><\/p>\n<div>\n<p><img decoding=\"async\" title=\"Chrome's Java warning\" alt=\"Chrome's Java warning\" src=\"https:\/\/windowssecrets.com\/wp-content\/uploads\/2013\/01\/W2012-01-24-TS-ChromePrompt.jpg\" \/><span style=\"font-size: small;\">Figure 2. By default, Chrome always asks before running a Java app.<\/span><\/p>\n<\/div>\n<p><span style=\"font-size: small;\">But as I said, turning Java off in IE is difficult \u2014 so difficult, it isn&#8217;t worth the effort. Here are the steps for disabling Java in Chrome and Firefox \u2014 and, if you&#8217;re feeling lucky, IE.<\/span><\/p>\n<ul type=\"square\">\n<li><span style=\"font-size: small;\"><strong>Chrome:<\/strong> In the browser&#8217;s address bar, type <strong>chrome:\/\/plugins<\/strong> and hit Enter. Scroll down to the entry <strong>Java (2 files) \u2013 Version: 10.7.2.11<\/strong> (or 10.7.2.21), and click the Disable link. Restart Chrome and you&#8217;re done. <\/span><\/li>\n<li><span style=\"font-size: small;\"><strong>Firefox:<\/strong> By default, Firefox disables outdated Java plugins. If you have an old version, it might not show up on the Firefox Plugins list. To check, click the <strong>Check to see if your plugins are up to date<\/strong> link at the top of the Plugins list.<\/span><span style=\"font-size: small;\">To disable Java, click Firefox&#8217;s Tools menu option and select Add-Ons. Select the Plugins tab (&#8220;plugins&#8221; and &#8220;add-ons&#8221; are used somewhat interchangeably) on the left, and scroll down to <strong>Java(TM) Platform SE 7 U11.<\/strong> Select it and click Disable. Repeat for any add-ons you see that refer to Java, then restart Firefox. Easy. <\/span><\/li>\n<li><span style=\"font-size: small;\"><strong>Internet Explorer:<\/strong> I&#8217;ve looked all over the Net and talked to several of my security-enhanced friends, and I&#8217;ve not found a better way than the one documented by (gulp!) the Department of Homeland Security\/Carnegie Mellon&#8217;s <a href=\"http:\/\/www.kb.cert.org\/vuls\/id\/636312#solution\">CERT site<\/a>. <\/span><\/li>\n<\/ul>\n<p><span style=\"font-size: small;\">With the CERT approach, you download and run a Registry-altering file that zaps almost 800 possible Java entry points in Internet Explorer. You then delete two files which you have to find manually. It&#8217;s ugly. More to the point, nobody&#8217;s absolutely certain that the CERT approach (or Microsoft&#8217;s method, given in <a href=\"http:\/\/support.microsoft.com\/kb\/2751647\">KB 2751647<\/a>) will protect IE from future attacks. So running through this process is not only difficult; it might be insufficient.<\/span><\/p>\n<p><span style=\"font-size: small;\">So now you know why I recommend that you disable Java for all your browsers and take your lumps.<\/span><\/p>\n<p><span style=\"font-size: small;\">I have no idea why Microsoft made it so hard to disable Java in IE, particularly when it&#8217;s such a simple process in Firefox and Chrome.&#8221;<\/span><span style=\"font-size: 24px;\">&#8220;<\/span><\/p><\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>Why everyone should be concerned about Java<\/p>\n<p>An article by Woody Leonhard, Microsoft Office Expert<\/p>\n<p>Woody Leonhard is a Windows Secrets senior editor and a senior contributing editor at InfoWorld. His latest book, the comprehensive 1,080-page Windows 8 All-In-One For Dummies, delves into all the Win8 nooks and crannies.  His many writings tell it like it is \u2014 whether Microsoft likes it or not.<\/p>\n<p>Please note, right from the start that Java is NOT JavaScript!  Disabling or removing Java on your devices will not cause the wonderful JavaScript apps on most websites to stop running.  You can disable or remove Java with impunity!<\/p>\n<p>&#8220;In the computing world, Java is very nearly ubiquitous. As noted on Oracle&#8217;s Java FAQ site, it runs on lots of PCs, but it also runs on &#8220;billions of devices worldwide, including mobile and TV devices.&#8221; Java is not JavaScript, as Susan Bradley notes in her companion piece, &#8220;Java: More than the usual cup of coding coffee,&#8221; about what Java is and isn&#8217;t.<\/p>\n<p>In this article, I focus on one task \u2014 disabling Java in your Web browser(s). It&#8217;s the most effective way to protect yourself from most Java-based threats. Yes, some PC users still need Java in their browsers to work with specific websites. But most of us have little to lose and much security to gain by keeping our browsers Java-free. (And yes, Mac users should block Java, too.) Java in browsers has been a malware magnet for years \u2014 it&#8217;s unlikely that fact will change anytime soon.<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-67","post","type-post","status-publish","format-standard","hentry","category-general-and-non-specific-topics"],"_links":{"self":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/posts\/67","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/comments?post=67"}],"version-history":[{"count":0,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/posts\/67\/revisions"}],"wp:attachment":[{"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/media?parent=67"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/categories?post=67"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dshsolutions.com\/wordpress\/wp-json\/wp\/v2\/tags?post=67"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}