The Java Nightmare

From: Ken (SHIELDSIT)18 Jan 2013 20:31
To: ALL1 of 20
Can someone much smarter than me answer this question?

Q: Since all this mess with Java is coming out, does it effect Android? Android is all Java isn't it?
From: johngti_mk-ii18 Jan 2013 20:58
To: Ken (SHIELDSIT) 2 of 20
What mess?
From: Ken (SHIELDSIT)18 Jan 2013 21:02
To: johngti_mk-ii 3 of 20
You haven't heard of the big security mess with Java in the last couple of weeks?  I'm on my phone or I'd find some links.  But Google and you'll see.
From: johngti_mk-ii18 Jan 2013 21:52
To: Ken (SHIELDSIT) 4 of 20
The most I know about the current state of java is that the bastard keeps asking me to update it whenever I turn our increasingly shit laptop on. And that's after I told it not to. The fucker.
From: Ken (SHIELDSIT)18 Jan 2013 21:55
To: johngti_mk-ii 5 of 20
If you don't use it uninstall it.  No shit and no kidding.  It's a fucking mess.  I'm home now so let me find you a few links.
From: Ken (SHIELDSIT)18 Jan 2013 22:07
To: johngti_mk-ii 6 of 20
From: johngti_mk-ii18 Jan 2013 22:10
To: Ken (SHIELDSIT) 7 of 20
Nope. I'm ridiculously uneducated in terms of anything computer based now.
From: Ken (SHIELDSIT)18 Jan 2013 22:16
To: johngti_mk-ii 8 of 20
OK, well if you don't need it for anything the best thing is to remove it.
From: CHYRON (DSMITHHFX)19 Jan 2013 03:23
To: Ken (SHIELDSIT) 9 of 20
From: Ken (SHIELDSIT)19 Jan 2013 04:01
To: CHYRON (DSMITHHFX) 10 of 20
I appreciate the link, and I read it, but it makes no sense to me. I've tried to learn java and made a few android apps, but I still don't get it.  My brain isn't wired correctly to use that kind of language.  I'm more at home with php or cfml.
From: CHYRON (DSMITHHFX)19 Jan 2013 16:41
To: Ken (SHIELDSIT) 11 of 20
My point is that Android's dalvik isn't java (though obviously a very similar, and arguably derivative work). So it may not be subject to the particular security vulnerabilities that were recently uncovered.
From: Mouse22 Jan 2013 12:22
To: Ken (SHIELDSIT) 12 of 20
Hopefully someone with more clevers can correct or corroborate, but it's Java running as a plugin within a browser that has security issues.  Stand alone things written in Java aren't as hackworthy, so Android and indeed things like Minecraft are OKish.
From: Matt22 Jan 2013 13:38
To: Mouse 13 of 20
The browser plugin is just the attack vector.

The security flaw (or flaws, because another has been found) exists in Java whether you use it stand-alone or via a browser plugin.

To be able to affect people who do not have the plugin installed you would need to get them to download the JAR file containing the exploit and run it locally, which while not impossible is a lot harder to do compared to hosting the exploited code on a website and sending people a link to it.
From: Ken (SHIELDSIT)22 Jan 2013 14:21
To: Matt 14 of 20
You could embed it in the bee logo.  Then you can have your own personal botnet.

Then, I think, you should use that botnet to make posts to forums.
From: ANT_THOMAS22 Jan 2013 14:29
To: Ken (SHIELDSIT) 15 of 20
Selling kitchens and bags.
From: Ken (SHIELDSIT)22 Jan 2013 14:32
To: ANT_THOMAS 16 of 20
Of course! 
From: koswix22 Jan 2013 17:00
To: Ken (SHIELDSIT) 17 of 20
You think you aren't already part of Matt's botnet? :'D
From: milko22 Jan 2013 17:24
To: ANT_THOMAS 18 of 20
and Thomas The Tank Engine jewellery.
From: Drew (X3N0PH0N)23 Jan 2013 00:17
To: milko 19 of 20
*Ant Thomas the Tank Engine jewellery.
From: Ken (SHIELDSIT)23 Jan 2013 02:22
To: Drew (X3N0PH0N) 20 of 20
Choo choo!