5 ms·
Fine, go read the bug trackers for them. Your point was? Oh, probably better to spend the time patching your desktop and servers given the massive drive through
by static_typed 13y ago
Fine, go read the bug trackers for them. Your point was? Oh, probably better to spend the time patching your desktop and servers given the massive drive through holes Java has left there.
- pjmlp 13y agoMy point is that it is easy to escalate Java security issues to average Joe, while forgetting it is just the tip of the iceberg of all attack vectors a computer has, regardless of which programming languages are used.
- fauigerzigerk 13y agoBut the criticism isn't that others have no security issues. It is that others fix them with a greater sense of urgency than Oracle.
- pjmlp 13y agoDo they? I can tell from the companies I worked for, security fixes are handled like any other bug fix.
- fauigerzigerk 13y ago>Do they? The perception is that they do, and I have to say that I share that perception. I'm open to be convinced otherwise ... by facts.
- pjmlp 13y ago> I'm open to be convinced otherwise ... by facts. Well, as you might understand I cannot publish the internal backlog of any Fortune 500 company my employer does consulting for. Either you believe me that security issues get the same priority as any other bug/feature on the backlog, or you don't.
- fauigerzigerk 13y agoThe issue we're talking about has nothing to do with the relative priority of security issues versus other bugs. The OP claimed that Oracle issues bug fixes less frequently (quarterly) than Microsoft or Adobe (monthly). Your claim is completely unrelated to that.
- pjmlp 13y agoSo the world of computing is composed only by Microsoft, Adobe and Oracle, right? No other software requires security fixes, I see.
- fauigerzigerk 13y agoI certainly hope that not many of the major vendors take three months to fix critical, remotely exploitable security issues. If they do, they deserve the same criticism that Oracle got.
- throwawaykf 13y agoNot sure what you meant, but almost all recent security holes were client-side. As far as I remember, server-side Java has been fairly robust.