Security too risky with Java
By Kim Komando Special For USA Today
Published: Friday, February 1, 2013, 12:01 a.m.
Updated: Friday, February 1, 2013
The weekly — sometimes daily — security scares that occur with the Java programming language are starting to remind me of the old whack-a-mole arcade game.
Researchers or hackers discover a major flaw in Java. Java's developer, Oracle, whacks it with a patch. Another mole pops up. Oracle whacks it with a patch.
Many experts say Oracle is losing this game or isn't trying very hard to win. And computer users are paying the price.
When a vulnerable version of Java is active in a web browser, visiting a compromised website is all it takes for crooks to sneak malware onto your computer. In most cases, you won't even know the site is compromised until it's too late.
Here's how to stay safe: Stop using Java — or stay on top of the upgrades and use Java a lot more guardedly.
I'm going to help you do just that.
But first: What the heck is Java? And why is it capable of scalding your computer?
First developed back in 1995, Java became ubiquitous almost overnight because it allowed programmers to write one program and use it on Windows, Apple OS X and other operating systems.
Today Internet browsers use Java for interactive web content, such as popular online games. Computers use it to run useful programs such as the free Office alternative LibreOffice, and Adobe Creative Suite. And Java is pre-installed on most systems. It's estimated that Java is running on 850 million computers in the world.
Java's security holes woke up Apple users last year when more than 600,000 Macs became infected with the Flashback malware that targeted Java.
Since then, moles have kept popping up through other holes. In response to the most recent exploit, the Department of Homeland Security a couple of weeks ago recommended that all Internet users disable Java. Apple and Mozilla have turned off Java plug-ins automatically in the latest editions of the browsers Safari and Firefox. But it doesn't hurt to double-check that Java is turned off.
Fortunately, the latest version of Java has a one-click button just for that purpose. That's handy because disabling it manually was a hassle, especially in Internet Explorer.
First, make sure you have the most recent version of Java from Oracle's site. The latest release as of this writing is Version 7 Update 11.
To bring up Java's new security settings, go to Start>>Computer and type “Javacpl.exe” in the search bar.
Mac users can find the setting by going to System Preferences and clicking on the Java icon — it looks like a steaming cup of coffee.
This will disable Java in your browser but still let you use it for desktop programs.
Although it's safer to run Java for a desktop program, it's best to get it off your machine if you don't need it.
Kim Komando hosts a talk radio show about consumer electronics. For details, visit www.komando.com.
- Kovacevic: Matt Cooke 1, Ottawa Senators 0
- Letang dazzles with dynamic play in Game 5 win
- Penguins rout Senators, return to Eastern Conference final
- Alfredsson ponders his future
- 16-year-old girl shot and killed on Rankin street
- Pirates notebook: Bucs shut down injured Karstens
- Penguins notebook: Tickets for Eastern Conference final on sale today
- Bank sues to stop $235,000 payment
- Steelers hope new blocking scheme kick-starts running game
- Senators notebook: MacLean puts onus on veterans
- Pirates waste strong Burnett start, fall again to Brewers at Miller Park
You must be signed in to add comments
To comment, click the Sign in or sign up at the very top of this page.
Subscribe today! Click here for our subscription offers.