Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

java stopping saying security reasons


  • Please log in to reply
7 replies to this topic

#1 ujjwaljoshi78

ujjwaljoshi78

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:03 AM

Posted 22 July 2014 - 03:03 PM

When I open a site some programs wants 2 run java. I allow it then a message shows your security settings has stopped java. What to do?



BC AdBot (Login to Remove)

 


#2 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,937 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:33 AM

Posted 22 July 2014 - 04:29 PM

Why are Java applications blocked by your security settings?

BTW, using Java is an unnecessary security risk...especially using older versions which have vulnerabilities that malicious sites can use to exploit and infect your system.Although Java is commonly used in business environments and many VPN providers still use it, the average user does not need to install Java software.I recommend just uninstalling Java if you don't use it.
* How to Completely Remove Java Using JavaRa
* How do I uninstall Java on my Windows machine?
* Information about the Java Uninstall Tool for Windows

If you're going to use Java, many security researchers and computer security organizations caution users to limit their usage and to disable Java Plug-ins or add-ons in your browsers.

If you need Java for a specific Web site, consider adopting a two-browser approach. If you normally browse the Web with Firefox, for example, consider disabling the Java plugin in Firefox, and then using an alternative browser (Chrome, IE9, Safari, etc.) with Java enabled to browse only the site(s) that require(s) it.

Krebs On Security: ...Java


To defend against this and future Java vulnerabilities, consider disabling Java in web browsers until adequate updates are available. As with any software, unnecessary features should be disabled or removed as appropriate for your environment.

US CERT: Disable Java in web browsers

* How to disable Java Plug-ins or add-ons in common web browsers .
* How to turn off Java on your browser
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#3 rp88

rp88

  • Members
  • 3,069 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:33 AM

Posted 30 July 2014 - 12:09 PM

what you should do is get rid of java entirely or, if it is needed for a desktop exe program(i used to have one such program but later found a version that didn't need java) go into the java control panel and disable the web plugin element of java("disable java in the browser" was the name of the tick box i think). whatever the site is it probably doesn't need java, unless you have a desktop program that needs it you don't need java either. java's developer has apparently failed to update certain elements of it even years after they were shown to be vulnerable, they try and bundle the ask toolbar into security updates and they don't have any online contact facility, deduce from that what you can. you were lucky that your settings stopped java from running, who knows what it would have done.


Back on this site, for a while anyway, been so busy the last year.

My systems:2 laptops, intel i3 processors, windows 8.1 installed on the hard-drive and linux mint 17.3 MATE installed to USB

#4 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,937 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:33 AM

Posted 30 July 2014 - 04:39 PM

As I said, although Java is commonly used in business environments and many VPN providers still use it, the average user does not need to install Java software.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#5 Veitch

Veitch

  • Members
  • 31 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:33 AM

Posted 31 July 2014 - 04:02 AM

There is no reason to deinstall the JRE from the system. It is not less secure than, e.g., the .NET Framework (see http://blogs.gartner.com/neil_macdonald/2010/06/01/is-net-more-secure-than-java/ ). Standalone programs written in Java are more secure than, e.g., C or C++ programs, because it has protection from buffer overflows and over-reads (something like the heartbleed bug couldn't have happened with Java). There are desktop programs for end-users that need the JRE, so why telling that users don't need it? That depends highly on the user.

Using the JVM to run programs is actually more secure than executing any native software, which doesn't provide a sandbox to run untrusted code in.

 

The real problem are Java-Drive-Bys, which is malware you download and execute unwillingly while browsing certain websites. For that reason the Java plugins of the browser should be deinstalled or at least deactivated as there have been many vulnerabilities found in the past that allow to escape Java's sandbox.

 

But again, there is no reason to deinstall the JRE from the system. I really don't know why this is suggested everywhere and why people don't differentiate.


Edited by Veitch, 31 July 2014 - 04:14 AM.


#6 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,937 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:33 AM

Posted 31 July 2014 - 05:45 AM

There is no reason to deinstall the JRE from the system.

Most security experts I know disagree...that's why they recommend to remove Java if folks don't use it.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif

#7 rp88

rp88

  • Members
  • 3,069 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:05:33 AM

Posted 31 July 2014 - 11:30 AM

i did mention that you can keep it and disable the web component if you have desktop programs using it. for a while i did and on my xp machine i still do, the little program in question was a 3d model conversion "script" and it needed java on my xp machine. on my windows 8 machine however the same program will run as a .net version so i don't need java at all on here.


Back on this site, for a while anyway, been so busy the last year.

My systems:2 laptops, intel i3 processors, windows 8.1 installed on the hard-drive and linux mint 17.3 MATE installed to USB

#8 quietman7

quietman7

    Bleepin' Janitor


  • Global Moderator
  • 51,937 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Virginia, USA
  • Local time:12:33 AM

Posted 31 July 2014 - 11:42 AM

i did mention that you can keep it and disable the web component...

I mentioned that too in Post #2.
.
.
Windows Insider MVP 2017-2018
Microsoft MVP Reconnect 2016
Microsoft MVP Consumer Security 2007-2015 kO7xOZh.gif
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

If I have been helpful & you'd like to consider a donation, click 38WxTfO.gif




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users