[CentOS] Is Java insecure ?

Mon Oct 7 06:24:22 UTC 2013
Fernando Cassia <fcassia at gmail.com>

On Sat, Oct 5, 2013 at 6:21 PM, Mark LaPierre <marklapier at aol.com> wrote:

> Java, which runs on a Java Virtual Machine (JVM) is know in
> the trade as (J)ust (A)nother (V)ulnerability (A)nnouncement
>

Let's try to be serious here. Theres funny definitions based on
acronyms,based on everyone's agendas. Some who opposed SNMP called it
"security is not my problem", because of shortcomings in the first version.
Last time I checked, SNMP was mature and used throughout corporate LANs.
Security is a process, not a definitive state. FOSS software is patched all
the time too, and for good reason.

http://www.mail-archive.com/blueonyx@mail.blueonyx.it/msg05233.html



> .  Java
> should never be enabled in a web browser.
>

To quote Icedtea-web* Red Hat developer Andrew Haley :
"Andrew Haley <aph at redhat.com> wrote:
I think this [removing the plug-in] is truly dreadful reasoning.  Either we
think that the
plugin is safe enough for people to use, or we don't ship it."

Anyway, enough said I think that by now the original poster's question has
been throrougly answered.

FC
* (Icedtea-web is the FOSS version of the Java plug-in for OpenJDK, as Sun
open sourced Java in 2006 but never the browser plugin, that need was
filled by the FOSS community via Icedtea-web)

-- 
During times of Universal Deceit, telling the truth becomes a revolutionary
act
Durante épocas de Engaño Universal, decir la verdad se convierte en un Acto
Revolucionario
- George Orwell