3 ms·
Now imagine if you'd written 10x as much code in Java and hit a Java vulnerability. The U.S. government told its citizens to uninstall Java recently. There have
by hakaaaaak 14y ago
Now imagine if you'd written 10x as much code in Java and hit a Java vulnerability. The U.S. government told its citizens to uninstall Java recently. There have been a few other high profile Java vulnerabilities in the past few years. Does that mean Java is the wrong choice? Most jobs available in development are in Java (check indeed.com).
For years Microsoft was the butt of most security jokes. .Net dev jobs are #2 under Java in indeed.com.
Find me a well-used platform that hasn't had a massive security hole or a community that hasn't tended to write insecure code at some point.
- X-Istence 14y agoA lot of jobs in Java are not for Java Applets running on peoples machines, a lot of the Java work is for client side apps, and for server side apps (think app development like RoR). Java applets are not necessary. The reason why the US government said to uninstall Java is because it is the quickest and easiest way for the layman to remove the ability for Java applets to run. If Sun^H^H^HOracle provided a way to just install Java so it can be used for client side apps without turning on Java applets in the browser, then it is not any less unsafe than C++/C#/Obj-C apps running on the same system.
- hakaaaaak 14y agoYou missed my point, which was that well-used languages and platforms have vulnerabilities and we still use them. And Java web apps have had security issues too. Do you remember this one? http://www.oracle.com/technetwork/topics/security/alert-cve-2010-4476-305811.html http://www.oracle.com/technetwork/topics/security/alert-cve-...
- X-Istence 14y agoI am not sure I missed your point. I was simply pointing out that people looking for Java developers has nothing to do with the fact that Java's applet stuff is completely vulnerable. Yes, other vulnerabilities exist, and they too had to be patched, I don't think dropping an entire language if a flaw is found is a good idea, we wouldn't be left with any, however Ruby on Rails is a framework built on top of Ruby, that is what contains the issues, not Ruby.
- dredmorbius 14y ago"Java" is a bunch of different things that run in a bunch of different places. It's a language, a bytecode interpreter, and a virtual machine. The virtual machine may run on a server, or client side. Most of the more significant Java security issues of late have been on the client-side JVM plugin support for browsers, which affects the ability to run Java applets client-side. For most contemporary Web development, "Java development" translates as "server-side Java programmer". Which isn't without its warts (trust me on this), but it's not the place that has seen a lot of heat, despite Oracle's best efforts to fuck everything up. The recent situation with RoR has been vastly worse, and has been server-side. As for that well-used platform and community with few security holes, I'd suggest you look up the OpenBSD folk, if you count an OS as a platform. They take a preemptively secure approach on all system code, to the point of rewriting major libraries. Yes, it's a bit less free-form than all the cool kids like to play these days, but damned if it's not a solid platform. And that "secure by default" mentality means they avoid much of the pain other OS developers (including Linux, which I much prefer to admin myself) encounter. RoR and Ruby have, to my mind and experience, a cultural problem with regards to security. And they're becoming widely enough used that it's starting to show.
- hakaaaaak 14y agoSince you brought up OpenBSD- there is an example of an OS where so much time and effort was spent on security, the adoption was lower. It's a fine OS, but if you have to wait for years for the DoD to start promoting it and you don't have the consumer adoption that you have with Windows, OS X, and Linux, then I'm sorry but no.
- cookiecaper 14y agoMarket share isn't everything. OpenBSD is a perfectly suitable platform for a certain set of applications. If you're doing free-wheeling experimentation type stuff, you may want to use Linux, but if you're serving a fairly conventional web app that isn't going to depend on new language functionality any time soon, *BSD is probably better as a server platform.
- cookiecaper 14y ago