3 ms·
How can Java actually be safe when it is such a huge cause of constant security compromises that most security experts recommend disabling or uninstall in it?
by TwoBit 12y ago
How can Java actually be safe when it is such a huge cause of constant security compromises that most security experts recommend disabling or uninstall in it?
- the_why_of_y 12y agoThe majority of Java CVEs are about ways by which sandboxed Java applets can escape the JVM sandbox (which is implemented in C++), which is a kind of error that is only possible in the very few language runtimes that can run untrusted code in a browser (like JavaScript and ActionScript/SWF). If you run a Java application outside a web browser, e.g. a server-side application, it won't run untrusted code and it isn't sandboxed by the JVM (like any other language), so those CVEs are irrelevant in that case.