|
|
#26 |
|
But not before the Pavlovian faithful start chanting their pre-emptive counter spells.
![]() Maybe you want to help this person out, now that you've done your duty. |
|
|
|
4
|
|
|
#27 |
|
The downside being relative platform insecurity.
__________________
Early 2011 17" MBP - Early 2011 13" MBP - Mid 2011 11" MBA - 2 x 2008 MB - 2006 15" MBP iPhone; iPhone 3G; iPhone 3GS; iPhone 4; iPhone 4S; iPad, iPad v2 |
|
|
|
0
|
|
|
#28 |
|
They are also blocking Apple Java 1.6! Don't know where XProtect.meta.plist screenshot is from, but that is not what Apple pushed out this morning.
Here's what it really is! Code:
<?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd"> <plist version="1.0"> <dict> <key>JavaWebComponentVersionMinimum</key> <string>1.6.0_37-b06-435</string> <key>LastModification</key> <string>Thu, 31 Jan 2013 04:41:14 GMT</string> <key>PlugInBlacklist</key> <dict> <key>10</key> <dict> <key>com.macromedia.Flash Player.plugin</key> <dict> <key>MinimumPlugInBundleVersion</key> <string>11.3.300.271</string> </dict> <key>com.oracle.java.JavaAppletPlugin</key> <dict> <key>MinimumPlugInBundleVersion</key> <string>1.7.11.22</string> </dict> </dict> </dict> <key>Version</key> <integer>2028</integer> </dict> </plist> Code:
sudo /usr/libexec/PlistBuddy -c "Delete :JavaWebComponentVersionMinimum" /System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.meta.plist Code:
sudo defaults write /System/Library/CoreServices/CoreTypes.bundle/Contents/Resources/XProtect.meta.plist JavaWebComponentVersionMinimum \"1.6.0_37-b06-434\" Code:
<string>1.7.11.22</string> Code:
<string>1.7.11.19</string> https://twitter.com/sonynair/status/296935103383347201 Hope that helps someone! |
|
|
|
7
|
|
|
#29 |
|
Java is just one tiny part of the BankID security system. I wish they'd ditch it, but that's not going to happen quickly. The layers of security beyond Java aren't threatened by the Java holes, apparently, and they claim there's no threat from Java in the way it's implemented into a bigger solution. I don't know the technicalities, just that for better or worse, we need it.
|
|
|
|
0
|
|
|
#30 |
|
Flash, Java, what's next? Internet access to Apple approved sites only?
|
|
|
|
9
|
|
|
#31 | ||
|
Quote:
However, your point about Windows machine is good. I haven't heard of any actual attacks on OS X in the wild yet - anyone? ---------- Quote:
|
|||
|
|
4
|
|
|
#32 | |
|
Quote:
About NemID |
||
|
|
1
|
|
|
#33 | |
|
Quote:
|
||
|
|
1
|
|
|
#34 |
|
I downloaded the current version and installed several times but that didn't work. Finally closed all browsers before installing again and took a look at Firefox's Tools/Ad-in's menu to make sure Java is still enabled. Then I tried the work site I need to use and this time it finally worked (also saw a Firefox warning asking me if I wanted to enable Java (although I thought it already was enabled). Strange. Anyway it finally worked.
Totally agree with some of the comments here. Totally irresponsible for Apple to block this critical function without commenting on it or advising on a workaround, override, etc. I need Java so I can work at home and access my work PC (I work for a large bank). This is the only way I can work remotely. |
|
|
|
2
|
|
|
#35 |
|
|
3
|
|
|
#36 | |
|
Quote:
|
||
|
|
1
|
|
|
#37 |
|
SOOOO IRRITATING APPLE YOU ****
Thank god I also have Windows on my iMac |
|
|
|
0
|
|
|
#38 | |
|
Quote:
|
||
|
|
0
|
|
|
#39 |
|
Difference between Java plug-in and Java run-time environment on the Mac.
They are not the same thing. Java plugins in Safari: blocked. Photoshop CS3: still works fine Wake me up when Apple starts blocking up-to-date Flash. |
|
|
|
1
|
|
|
#40 |
|
|
1
|
|
|
#41 | |
|
Quote:
THAT is the Microsoft definition of "professionalism". The moment you turn it on, you're at risk of losing everything. |
||
|
|
5
|
|
|
#42 | |
|
Quote:
I was just on my 401k website attempting to make changes. Now I know why I could not do it. I see a lot of java required sites in my business of finance; I guess we are the only ones who use it heavily? Whatever the reason, it is making my life difficult.
__________________
Quicker than two shakes of a lambs tail
|
||
|
|
2
|
|
|
#43 |
|
This is a real pain. I work for a school district and the software we use for the online gradebook uses Java. So now teachers can't update their grades. Plus, it's not that easy just to switch software platforms.
I understand Apple wanting to keep its platform secure and not degrade its good name, but users & companies really need the option to easily override these blocks. |
|
|
|
3
|
|
|
#44 |
= Troll
|
|
|
|
1
|
|
|
#45 |
|
What a pain in the ass. Who cares that we use ADP for our time off / scheduling....
|
|
|
|
0
|
|
|
#46 |
|
Why can't Apple just pop up a dialogue window that says Java may have security issues instead of disabling it?
__________________
Mid-2010 15" MBP ML, 64GB iPhone 5 (AT&T), 64GB iPad Mini (AT&T), 8GB iPod Nano |
|
|
|
3
|
|
|
#47 |
|
Now, we are having trouble processing checks. If this keeps up, we will be forced to send someone to the bank with a stack of checks in a bag.
Welcome back to the 20th Century. |
|
|
|
1
|
|
|
#48 |
|
The article by MacRumors states that it's unknown why Apple took this step. I received an email advisory from MS-ISAC on January 28th which spoke of a new vulnerability. I am pasting it below.
-- MS-ISAC ADVISORY NUMBER: 2013-008 - UPDATED DATE(S) ISSUED: 01/28/2013 SUBJECT: Security Bypass Vulnerability in Oracle Java Runtime Environment Could Allow Remote Code Execution OVERVIEW: A vulnerability has been discovered in Oracle Java Runtime Environment (JRE) that can lead to remote code execution. The Java Runtime Environment is used to enhance the user experience when visiting websites and is installed on mostdesktops and servers. This vulnerability may be exploited if a user visits or is redirected to a specifically crafted web page. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the JRE application. Depending on the privileges associated with the application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attempts will likely result in denial-of-service conditions. SYSTEM AFFECTED: Oracle JRE 1.7.0 Update 10, prior versions may also be affected. UPDATED SYSTEM AFFECTED: • Oracle JRE 1.7.0 Update 11, prior versions may also be affected. RISK: Government: Large and medium government entities: High Small government entities: High Businesses: Large and medium business entities: High Small business entities: High Home users:High DESCRIPTION: A vulnerability has been discovered in Oracle Java Runtime Environment that can lead to remote code execution. In order to exploit this vulnerability, an attacker must first create a web page with a specially crafted applet designed to leverage this issue. When the web page is visited, the attacker suppliedcode is run in the context of the affected application. Successful exploitation of this vulnerability could result in an attacker gaining the same privileges as the JRE application. Depending on the privileges associated with the application, an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Failed exploit attemptswill likely result in denial-of-service conditions. Please note that there is no patch available from Oracle to mitigate this vulnerability at this time and this vulnerability is being sold in the underground markets. RECOMMENDATIONS: We recommend the following actions be taken: Apply the patch from Oracle, after appropriate testing, as soon as one becomes available. Consider disabling Java completely on all systems until a patch is available. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. Remind users not to open e-mail attachments from unknown users or suspicious e-mails from trusted sources. REFERENCES: Security Focus: http://www.securityfocus.com/bid/57563 Full Disclosure: http://seclists.org/fulldisclosure/2013/Jan/241 Multi-State Information Sharing and Analysis Center 31 Tech Valley Drive, Suite 2 East Greenbush, NY 12061 (518) 266-3460 1-866-787-4722 soc@msisac.org |
|
|
|
5
|
|
|
#49 |
|
|
2
|
|
|
#50 |
|
This is unacceptable silent communication or rather lack of communication.
There should be at least be visible hints/error messages and there should be a way to manually override this for experienced users. Many online brokers use Java and WebStart. There are people trading with lots of $ who couldn't start their broker applications today. There was no way to find this error easily unless you go into the console, this is complete mis-communication on Apple's part. |
|
|
|
2
|
![]() |
|
«
Previous Thread
|
Next Thread
»
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
All times are GMT -5. The time now is 04:19 AM.















Linear Mode
