TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Java flaw allows “complete” bypass of security sandbox

130 pointsby scottfrover 12 years ago

6 comments

brown9-2over 12 years ago
The actual announcement: <a href="http://seclists.org/fulldisclosure/2012/Sep/170" rel="nofollow">http://seclists.org/fulldisclosure/2012/Sep/170</a>
评论 #4574611 未加载
boyterover 12 years ago
This isn't that surprising really. Microsoft's focus on security 10 or so years ago has paid off and its hard to find flaws in their OS now. The next most common platform is probably the JVM so its the new attack vector.<p>I would imagine we are going to see more and more of these exploits unless Oracle takes the same approach that Microsoft took, and even then it will be years before the benefits are felt.
评论 #4573596 未加载
评论 #4573537 未加载
foohbarbazover 12 years ago
Another browser plugin hole? Yawn. It's disabled in Firefox and Chrome anyway. Let them disable it for good and enable by exception.<p>Who uses Java in browser anyway? WebEx and some weird VPN solutions?
评论 #4573217 未加载
评论 #4573438 未加载
评论 #4573485 未加载
评论 #4574388 未加载
评论 #4574933 未加载
评论 #4573391 未加载
blinkingledover 12 years ago
It almost sounds like Oracle managed to shoo away all good folks from the JVM team and all they are left with is a bunch of B players. I dont remember it being this bad.
评论 #4573551 未加载
评论 #4573590 未加载
unabridgedover 12 years ago
Java (and flash) should only be ran inside a virtual machine. You have to be a fool to have that installed on your bare computer.
评论 #4575119 未加载
snambiover 12 years ago
who runs java in browser these days?
评论 #4574135 未加载
评论 #4577516 未加载