4 ms·
Apple updates Java for a third time, this time with Flashback malware removal
- ajross 14y agoWhy is the removal tool being executed via an upgrade of the JVM? Seems like lots of users (enterprise sites especially) would want those separated.
- malkia 14y agoSpeculating here... but could it be that this is some reasonable safe and isolated method, where the malware does not interfere? (I'm not familiar at all with the malware).
- dmishe 14y agoi don't think apple cares that much about enterprise
- rollypolly 14y agoMaybe because Software Update doesn't require entering the administrator password.
- warpspeed 14y agoBecause creating an update named "Flashback Malware Removal Update" would admit that Macs can be infected with malware- something Apple has taken great lengths to gloss over.
- alanh 14y agoCitation needed. Apple has admitted that the malware exists. http://support.apple.com/kb/HT5244 http://support.apple.com/kb/HT5244 Not to mention that this JVM update’s description, immediately visible if you show updates before installing them, directly mentions the Flashback malware. Not exactly my definition of pretending it isn’t out there. Also suspect: implication that competitors are less likely to “gloss over” their own products’ vulnerabilities to whatever extent Apple may be.
- warpspeed 14y agoAdmitting something in a support document and naming the update as such are two very different gestures. I guarantee that less than 1% of their user base will ever see that support doc- really most users don't even look at the names of the updates. I see it as the equivalent of fine print. Yes, it's technically there, but just like you won't see "5% Juice!" in bold print on the front of Sunny D, Apple isn't exactly trying to bring it to the user's attention. Hence, they're combining it into the Java update. Besides, this is in response to "why do you think Apple combined this with the Java update," and I'm replying with an opinion. No need to jump all over my case with "citation needed" and a downvote.
- alanh 14y agoI don’t know why, but note that they had to at least issue a JVM upgrade to get the feature/protection noted in the linked article: > "This update also configures the Java web plug-in to disable the automatic execution of Java applets. Users may re-enable automatic execution of Java applets using the Java Preferences application. If the Java web plug-in detects that no applets have been run for an extended period of time it will again disable Java applets." Personally I don’t know why anyone would want one update and not the other. Isn’t it part of the Apple experience to just entrust all this stuff to them?