4 ms·
What about using JSP? It's somewhat Java and doesn't require Java on the front end(which is the source of most security problem). On the server side, you have
by fadzlan 13y ago
What about using JSP? It's somewhat Java and doesn't require Java on the front end(which is the source of most security problem).
On the server side, you have to look for the vulnerability of the web container that you are using.
I do not see how would a CA helps you in your concern. Yes, having certs provides you encryption when your data is travelling, and client side cert may also helps you as a method as authentication if you wish, but all those does not help you in the Java security problem itself.
I'd be interested of a different opinion.
- wmnwmn 13y agoSorry, I was not being very clear. We're not concerned with security per se, only with reducing the security-related hurdles that our users have to go through to run our applet. Signing with a proper cert will reduce that, and probably we'll do that, but it's not free and I'm guessing it will have its own inconveniences. We are worried that Java security could become so onerous that it just isn't usable on the public internet, but we're not seeing another similar option.
- deleted 13y ago[deleted]
- lgieron 13y agoThat could be true for general consumers, who could be scared into disabling Java altogether in their browsers(so that some part of the population wouldn't be reached by the app). On the other hand, if you're making B2B/scientific app for a specific niche, your target audience should be interested enough in what you have to offer so that, even if they disabled Java, they'll turn it back to check out your app. In other words, people will gladly suffer minor inconvenience for an app that adds value, while would be probably put off if the app is another social network/messaging app/game etc., where the perceived value is vague at best.
- wmnwmn 13y agoYeah, you're probably right...I hope...and Java still seems to the only game in town for unified web + desktop functionality.I just don't see another choice.
- lgieron 13y agoMy understanding is that web apps have some limitations that can be a show-stopper for scientific apps - for example, there's no way to gain an arbitrary access to file system (something that is easily doable with a signed applet), which can make bulk processing/import etc. impossible. That's the reason I recommended applets in the startup I work for.