<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:s="http://www.techrepublic.com/search" xmlns:dc="http://purl.org/dc/elements/1.1/"  xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
    <title><![CDATA[Discussion on Java insecurity: Options are few for many enterprises ]]></title>
    <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250]]></link>
    <atom:link rel="hub" type="application/rss+xml" href="http://pubsubhubbub.appspot.com/" />
    <atom:link rel="self" type="application/rss+xml" href="http://www.techrepublic.com/forum/discussions/102-401250/rss" />

    <description><![CDATA[]]></description>
    <language>en-us</language>
    <lastBuildDate>2013-05-20T15:32:26-07:00</lastBuildDate>
             

    <item>
        <title><![CDATA[Good post...]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3751844]]></link>
        <description><![CDATA[and thanks! As far as my personal home office computer though, I wished I could get it to do exactly that! I've never been able to, or witnessed the java updater working in my Vista x64 Ultimate PC. Java hides the update tab in the java console, in my version of windows, and if I remember correctly, I used a registry hack to get it to show when opening it in command line. But after several updates it disappeared again, never to return. I end up using Avast's software updater to get java updates from now on.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3751844]]></guid>
        <dc:creator><![CDATA[JCitizen]]></dc:creator>
        <pubDate>Wed, 13 Mar 2013 11:46:16 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Important Point Missing?]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3751606]]></link>
        <description><![CDATA[As someone who deals with application packaging, QA, and deployments -- security isn't the only issue here.  Enterprise anti-virus, firewalls, proxy servers, etc seem to mitigate a lot of the risk.  Personally my biggest issue with Java 1.7 is the forcing of auto-updates and the nag screens that come with it.  This is a huge problem and results in massive numbers of helpdesk calls if not dealt with.  Before Java 1.7, engineers had time to test, package, and pilot Java releases.  Now, each time a new update is released the end users themselves get prompted about insecure versions of Java!  Not good.  I've written a messy workaround for this HUGE issue (in my opinion).  http://www.labareweb.com/java-1-7-auto-update-deployment-with-sccmmdt/]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3751606]]></guid>
        <dc:creator><![CDATA[bretthexum]]></dc:creator>
        <pubDate>Tue, 12 Mar 2013 09:44:35 -0700</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Today's browser-only issue does not mean the the rest of Java is risk-free!]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3742655]]></link>
        <description><![CDATA[While it's true that the current (January) exploit patched by JRE7u11 was only accessible through web-based code, I think it's naive to think that the same level of careless programming that went into the web-based portions of the Java Runtime doesn't also plague the non-browser portions of the code. Possibly the only reason they don't is that much of that code was written prior to JRE7, and thus not subject to what appears to be some very dysfunctional coding practices inside Oracle.Nonetheless, as Scott points out in his article, we all recognize that disabling (or uninstalling) Java completely is not a viable option, and thus the focus continues to be on disabling the Java functionality in the browsers -- which is the primary vector of attack.Then again, related to general patch management and appDeploy practices.. if you don't *need* Java... in any form... it's still Best Practice to uninstall the unneeded product.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3742655]]></guid>
        <dc:creator><![CDATA[Lawrence Garvin]]></dc:creator>
        <pubDate>Wed, 23 Jan 2013 14:15:43 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Corrected article]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3742629]]></link>
        <description><![CDATA[All,Thank you for the feedback indicating that there were factual errors in the article.  I have read your feedback, done additional research and updated the article in question.  Please accept my apologies for the initial misinformation.Scott LoweAuthor]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3742629]]></guid>
        <dc:creator><![CDATA[Scott Lowe]]></dc:creator>
        <pubDate>Wed, 23 Jan 2013 12:56:57 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Back link to article is broken]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741597]]></link>
        <description><![CDATA[I can not access the article... Get &quot;Were sorry, but the page you requested could not be found.&quot;Searching Tech Republic for article gives me the same link:http://www.techrepublic.com/blog/networking/java-insecurity-options-are-few-for-many-enterprises/6302Anyone have a working link to the article?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741597]]></guid>
        <dc:creator><![CDATA[Mo16]]></dc:creator>
        <pubDate>Fri, 18 Jan 2013 09:55:30 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[it is the browser plugin]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741474]]></link>
        <description><![CDATA[and not the JVM that runs Enterprise apps that is at risk]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741474]]></guid>
        <dc:creator><![CDATA[Duke E Love]]></dc:creator>
        <pubDate>Thu, 17 Jan 2013 20:38:42 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Java warning: 2 years to fix all vulnerabilities]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741462]]></link>
        <description><![CDATA[The criticisms are correct on this. The software being exploited is java in the browser. In fact, anarticle on Networkworld references the CMU SEI CERT recommendation: &quot;Unless it is absolutely necessary to run Java in web browsers, disable it, even after updating to 7u11.&quot; So this zero-day security problem seems to be largely focused on java in the browser, not client side applications or server side applications.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741462]]></guid>
        <dc:creator><![CDATA[mla_ca520@...]]></dc:creator>
        <pubDate>Thu, 17 Jan 2013 14:00:07 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Wh no admin console for Java?]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741342]]></link>
        <description><![CDATA[Java is the one product that irks me the most, as an IT admin.  Why does this thing not have a global admin console you can run from a server to manage all systems?  Or does it?  Java is &quot;there&quot;, but I would be fine seeing it disappear.  I do remember the write once, run anywhere selling point.  Problem is/was the code was never efficient.  Somebody needs to sit down and think about a Java 2.0.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741342]]></guid>
        <dc:creator><![CDATA[viProCon]]></dc:creator>
        <pubDate>Thu, 17 Jan 2013 05:40:31 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[It's just a bug!]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741305]]></link>
        <description><![CDATA[It's just a bug they detected. Don't panic it will be resolved soon!]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741305]]></guid>
        <dc:creator><![CDATA[osas1]]></dc:creator>
        <pubDate>Thu, 17 Jan 2013 02:33:16 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Java can and will be phased out of many applications over time]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741269]]></link>
        <description><![CDATA[Aside from the recent issues, Java has a lot of other negatives, not the least being able to get up to speed using it.  Any time there is this much pressure on a given industry need, other solutions come along spurred on by the hugh monetary gains possible for the production of a better alternative.  In the 1800's trains ran on different size tracks.  Was the practicle solution to build a locomotive that fit everthing?  At some point, who knows when, not me, an acknowledged best hardware solution will prove itself and the nonsense will end.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741269]]></guid>
        <dc:creator><![CDATA[maszsam@...]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 21:34:17 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I suspect that concept may be a tad too complex for him,]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741268]]></link>
        <description><![CDATA[...if he can't understand the difference between a browser add-on and a workstation programming language or a runtime environment.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741268]]></guid>
        <dc:creator><![CDATA[radleym]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 21:16:06 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Hey Scott, instead of refering to seasons can you put a month in, as last]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741207]]></link>
        <description><![CDATA[summer for half the world was back in January 2012 and I suspect you mean sometime around June July 2012.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741207]]></guid>
        <dc:creator><![CDATA[Deadly Ernest]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 16:14:07 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[The big concern I see here is that so many smart phones rely on Java at]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741210]]></link>
        <description><![CDATA[the moment. That's one hell of a huge potential botnet if someone takes advantage of the vulnerability to hit a lot of phones via their web access. With the regular surfacing of Java vulnerabilities, I suspect the time really is NOW for enterprise and people to move away from it for all time.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741210]]></guid>
        <dc:creator><![CDATA[Deadly Ernest]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 16:13:14 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[The sky is falling!]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741176]]></link>
        <description><![CDATA[No, it isn't, Chicken Little. It's one cloud that's leaking and needs fixed.Mole hill -&gt; Mountain. Seriously.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741176]]></guid>
        <dc:creator><![CDATA[flotsam70]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 14:12:57 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[I didn't know the silly thing could be disabled.]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741161]]></link>
        <description><![CDATA[I thought it was either installed or not.  Now that I know, if you're going to disable it then why not go ahead and uninstall it?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741161]]></guid>
        <dc:creator><![CDATA[CharlieSpencer_Palmetto]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 13:10:57 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[So I assume]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741139]]></link>
        <description><![CDATA[You run either OSX or linux in your organization, as much of what you say about Java goes double for Windows.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741139]]></guid>
        <dc:creator><![CDATA[radleym]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 12:50:49 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Safe Than Sorry.....]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741144]]></link>
        <description><![CDATA[While I haven't the first CLUE about whether or not my desktop at work is safe or not, becaue I'm in charge of a whole LOT of desktops, and because the information on the servers those desktops connect to is EXTREMELY IMPORTANT (think Level G15 Government Clearance, and you being to get the picture!) I would rather be safe than sorry, there is no reason for Java to be on the network, the most processor intensive applications we have are office / spreadsheet / presentation software, and hwile we don't block all internet access, we sure do monitor it vigorously, there's hardly a complaint from anyone who uses the internet on campus who feels they need to have Java running....so there ARE a few places that truly DO have a Java free network. I doubt that there are many, and I'm almost certain there are a few proplr who have attempted to acess Java-rich sites that might cause problems, but most of our network access (externally) is role monitored, if you're not in a specific role, you don't get access.....simple.....clean.......precise.........brutal?....yes. Might there be another way to do it?....most definitely, but since it works for us.....we'll keep it this way until the powers-that-b decide to do things diferently.]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741144]]></guid>
        <dc:creator><![CDATA[Knighthawk5193@...]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 12:14:40 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[This is not correct]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741119]]></link>
        <description><![CDATA[I agree with arash1988 - it's clearly stated in security alert that no desktop, server or every other major use of java has this kind of problems. I assume that there is a big misunderstanding of Java on Browser vs Java everywhere else in this article!]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741119]]></guid>
        <dc:creator><![CDATA[ergdemirel@...]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 11:19:53 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[What about OpenJDK?]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741071]]></link>
        <description><![CDATA[Anyone know how much of these problems are shared by OpenJDK?]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741071]]></guid>
        <dc:creator><![CDATA[jag022054@...]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 08:52:42 -0800</pubDate>
    </item>
             

    <item>
        <title><![CDATA[Reading FTW]]></title>
        <link><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741090]]></link>
        <description><![CDATA[Glad to see some people actually read the security alerts!]]></description>
        <guid><![CDATA[http://www.techrepublic.com/forum/discussions/102-401250-3741090]]></guid>
        <dc:creator><![CDATA[admin@...]]></dc:creator>
        <pubDate>Wed, 16 Jan 2013 08:49:34 -0800</pubDate>
    </item>
    </channel>
</rss>

