Time to uninstall Java?

When do hackers sleep? Seriously. Everyday they are hacking into something new, exposing some security flaw, and freaking out computer users and IT managers. According to Slate:


Hackers have found a flaw in Oracle's Java software that allows them to break into users' computers and install nasty malware, security experts report. The attack, first spotted on Sunday by researchers at the security firm FireEye, is what security types call a "zero-day" threat, exploiting a previously unknown vulnerability for which there is currently no fix available.
The loophole appears to affect Java Version 7 (also known as 1.7) on all browsers. So far the attacks have been against PCs, but Mac users are vulnerable as well. Businesses should be especially concerned about targeted attacks, but just about anyone who uses Java on the Internet is at risk, especially since the attack has been added to the Internet's most popular hacking kit, BlackHole.


Sounds serious, but what’s it mean for me and you? Hint: RUN!!


Given the potential seriousness and pervasiveness of the attacks—and Oracle's reputation for being slow on the draw in response to Java vulnerabilities—experts say that everyday Internet users should probably just disable Java entirely. Like, right now.
"Java has been the most exploited program for well over a year now and it simply isn't worth the risk," Chet Wisniewski of the security firm Sophos told me in an email. "I would recommend removing Java entirely, if you can.


The Slate article explains how to going about disabling Java. The nakedsecurity blog has advice for folks who need to keep using it. MacWorld has published a guide for Mac users to check whether or not they are vulnerable.

About the author

Adriene Hill is a multimedia reporter for the Marketplace sustainability desk, with a focus on consumer issues and the individual relationship to sustainability and the environment.
BostonPeng's picture
BostonPeng - Aug 30, 2012

You forgot some folks, Adrienne. Linux users also run Java, and while I see version 7 is installed on my laptop I'm running version 6. Although my Java-based cell may be a different matter.

I"ll need to share this today, then make a note to come back and blog it tomorrow when I have more time to make sure I'm including everything Linux users need to know to help get the message out to my fellow penguinistas.

cameopilot's picture
cameopilot - Aug 30, 2012

Oracle has released a patch that has been independently confirmed to correct this. You can download it at www.java.com

Buzzworthy

Recent comments on our stories..

JerryCPP's picture

The safety payoff of the big business of gun training

Great story, but I didn't hear the two most important things in firearm safety. A gun is ALWAYS loaded, and don't point a gun at...

Annapolis57's picture

Three life rules from Donald Rumsfeld

Journalism: Practiced. Excellent interview. Thank you.

jgrothues's picture

Three life rules from Donald Rumsfeld

Donald Rumsfeld's interview on Marketplace today was absolutely unbelievable. Really. Is one of his rules not to believe your own spin? I...

rcd43's picture

Three life rules from Donald Rumsfeld

Ryssdal's interview with Rumsfeld was breathtakingly inappropriate. "Marketplace?" If Ryssdal wants to promote his obvious biases...