4 ms·
"How will java's recent security vulnerabilities affect its popularity?" This is the one question the infographic takes the time to ask. It's a poor question,
by examancer 13y ago
"How will java's recent security vulnerabilities affect its popularity?"
This is the one question the infographic takes the time to ask. It's a poor question, but one many people seem to ask after the recent java plugin vulnerabilities.
Java hasn't been popular for in-browser development for many years now, and even at its height it was never that popular. These security vulnerabilities only affect Java use cases where untrusted java code is expected to be restricted to limited system access. This is not the environment mainstream java software will ever run in, so the mainstream use cases for java are entirely unaffected by these security issues.
The majority of Java software falls into two classes: desktop/native software and enterprise/server software.
Desktop/native software, like Minecraft or Android apps is either intended to have full system access (Minecraft) or is already restricted to making system calls through a rigid API that requires user permission to have access to (Android apps). In addition, Android uses its own Dalvik VM, so issues with Oracle's JVM are immaterial. Security of browser applets is a non-factor in both cases (android phones can't even run them).
Enterprise/server software are Java web applications, Java services, and other enterprise/web/server architecture pieces. These don't run on end user machines and are trusted applications, so JVM sandboxing is not really a concern.
There is absolutely nothing insecure about Java as a language. Occassionaly, there are issues with certain implementations of Java. These latest security flaws were in an implementation of Java that very few people use. Yes, everyone should remove Java from their browser, but if they were even using Java it almost certainly wasn't in the browser to begin with. The plugin has stuck around far long than it was useful, so good riddance.
Removing Java from a system altogether, as I have seen many people recommend, is in general too far and may break desktop apps users depend on that are not a security threat.
Sorry for the rant... I'm actually an ex-Java developer who has fallen for Ruby. There are plenty of legit problems with Java, but security generally isn't one of them.