4 ms·
Does anyone know if this is the infamous 7u51 which will disable unsigned applets from running AT ALL in a browser? (Yes, I know about the whitelist jar)
by pudquick 13y ago
Does anyone know if this is the infamous 7u51 which will disable unsigned applets from running AT ALL in a browser? (Yes, I know about the whitelist jar)
- rickette 13y agoIt is, this one raises the security baseline. In case you need to make applets compatible with 7u51 take a look at https://blogs.oracle.com/java-platform-group/entry/new_security_requirements_for_rias https://blogs.oracle.com/java-platform-group/entry/new_secur...
- 0x0 13y agoSo now all applets will have to be signed, and users will be trained to accept running the signed applets with that horrible GUI for confirming it. Did you know that popup about running a signed applet also confirms you're OK with running the applet outside the sandbox? So from now on, all applets will by default run outside the sandbox? How is this an improvement?
- brazzy 13y agoIt's an improvement because all applets will by default not run at all, and most users don't need to use any applets and thus will not in fact be trained to agree to run applets. Basically, it acknowledges that the Java sandbox is as leaky as a sieve and that securitywide, running an applet not much different from downloading and running a regular executable file, so you should only do it if you trust the source.
- 0x0 13y agoIt's a shame if poorly written applets end up being signed cluelessly. At least the sandbox used to prevent accidents, if not malicious code. Plenty of things like "lights-out" server admin tools seem to ship with semi-dodgy applets for KVM stuff etc.