# Disable Java in your browser

**URL:** https://boards.straightdope.com/t/disable-java-in-your-browser/633102
**Category:** Miscellaneous and Personal Stuff I Must Share
**Created:** [August 30, 2012, 2:12am UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102 "2012-08-30T02:12:19Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Anne\_Neville](https://avatars.discourse-cdn.com/v4/letter/a/b9e5f3/32.png) [@Anne\_Neville](https://boards.straightdope.com/u/Anne_Neville)
#### Post date: [August 30, 2012, 2:12am UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/1 "2012-08-30T02:12:19Z")

</div>

[Java zero-day vulnerability that could result in your computer being infected simply by viewing a malicious webpage.](http://www.slate.com/blogs/future_tense/2012/08/29/java_zero_day_vulnerability_why_you_should_disable_java_on_your_browser_right_now_.html) Here is a link where you can [test to see if you are vulnerable](http://research.zscaler.com/2012/08/are-you-vulnerable-to-latest-java-0-day.html). Both links have instructions on how to disable Java in various browsers. Disabling Java won’t affect your ability to read or post on the SDMB.

---

<div class="post-metadata">

### Author: ![Savannah](https://avatars.discourse-cdn.com/v4/letter/s/b3f665/32.png) [@Savannah](https://boards.straightdope.com/u/Savannah)
#### Post date: [August 30, 2012, 2:58am UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/2 "2012-08-30T02:58:40Z")

</div>

Thanks–I meant to look into this earlier today, but got sidetracked.

---

<div class="post-metadata">

### Author: ![Lukeinva](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lukeinva/32/17872_2.png) [@Lukeinva](https://boards.straightdope.com/u/Lukeinva)
#### Post date: [August 30, 2012, 4:09am UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/3 "2012-08-30T04:09:45Z")

</div>

I feel safer by not testing if I am vulnerable.

---

<div class="post-metadata">

### Author: ![Der\_Trihs](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/der_trihs/32/233_2.png) [@Der\_Trihs](https://boards.straightdope.com/u/Der_Trihs)
#### Post date: [August 30, 2012, 6:13am UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/4 "2012-08-30T06:13:04Z")

</div>

> [@Lukeinva](#):
>
> I feel safer by not testing if I am vulnerable.

I have NoScript running on Firefox, and it won’t let the test work without permission; which I’m nervous about giving, actually.

---

<div class="post-metadata">

### Author: ![njtt](https://avatars.discourse-cdn.com/v4/letter/n/ecd19e/32.png) [@njtt](https://boards.straightdope.com/u/njtt)
#### Post date: [August 30, 2012, 1:52pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/5 "2012-08-30T13:52:53Z")

</div>

NoScript will not protect you (much) from this Java exploit. Basically, if you are running an up to date version of Java (v. 7) you are vulnerable, and there is not expected to be a patch until October (though maybe this will be brought forward with all the publicity now).

It is easy enough to disable Java in Firefox: just go to the Add-ons/Plugins page and disable anything that refers to Java. It is [not so easy in IE](http://www.kb.cert.org/vuls/id/636312#disable_java_in_IE), apparently.

For most people, it is probably best just to uninstall Java, unless you have it for some non-web-related use. Few web sites use Java these days.

Perhaps it is worth saying, as lots of people are confused about this, that Java is NOT at all the same thing as JavaScript. The similar names are misleading. They are essentially unrelated technologies.

This vulnerability affects Java, but _not_ JavaScript. JavaScript does have its own vulnerabilities, but, unlike Java, very many, perhaps most, web sites do rely on JavaScript to work properly (though not the Dope, I think). You can’t uninstall JavaScript, it is built in to modern browsers. You can disable it with add-ons like NoScript if you want. (Personally I think that is overkill for most users, however.)

---

<div class="post-metadata">

### Author: ![Iggy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/iggy/32/3364_2.png) [@Iggy](https://boards.straightdope.com/u/Iggy)
#### Post date: [August 30, 2012, 3:34pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/6 "2012-08-30T15:34:05Z")

</div>

I tried to test but Chrome gives me an error:

Java™ was blocked because it was out of date.  
With choices to Update or Run this time…

Sounds like I won’t be updating. 😃

---

<div class="post-metadata">

### Author: ![Dallas\_Jones](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dallas_jones/32/3277_2.png) [@Dallas\_Jones](https://boards.straightdope.com/u/Dallas_Jones)
#### Post date: [August 30, 2012, 5:46pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/7 "2012-08-30T17:46:03Z")

</div>

So I’ve got Java v 1.6\_29 and am not at risk. Java is not going to automatically update to v 1.7 and put me at risk without my knowledge, is it?

IE 7 user.

---

<div class="post-metadata">

### Author: ![FloatyGimpy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/floatygimpy/32/7750_2.png) [@FloatyGimpy](https://boards.straightdope.com/u/FloatyGimpy)
#### Post date: [August 30, 2012, 5:57pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/8 "2012-08-30T17:57:19Z")

</div>

How do I uninstall Java?

---

<div class="post-metadata">

### Author: ![Khadaji](https://avatars.discourse-cdn.com/v4/letter/k/9e8a1a/32.png) [@Khadaji](https://boards.straightdope.com/u/Khadaji)
#### Post date: [August 30, 2012, 6:14pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/9 "2012-08-30T18:14:57Z")

</div>

I had to check, but would have been surprised if I had Java enabled. I didn’t.

---

<div class="post-metadata">

### Author: ![Covered\_In\_Bees](https://avatars.discourse-cdn.com/v4/letter/c/7ab992/32.png) [@Covered\_In\_Bees](https://boards.straightdope.com/u/Covered_In_Bees)
#### Post date: [August 30, 2012, 9:09pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/10 "2012-08-30T21:09:31Z")

</div>

> [@FloatyGimpy](#):
>
> How do I uninstall Java?

Click the links. Read them.

---

<div class="post-metadata">

### Author: ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)
#### Post date: [August 30, 2012, 9:12pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/11 "2012-08-30T21:12:52Z")

</div>

Java 1.7.07 is out.

[http://www.java.com/en/](http://www.java.com/en/)

---

<div class="post-metadata">

### Author: ![Arnold\_Winkelried](https://avatars.discourse-cdn.com/v4/letter/a/3d9bf3/32.png) [@Arnold\_Winkelried](https://boards.straightdope.com/u/Arnold_Winkelried)
#### Post date: [August 30, 2012, 9:17pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/12 "2012-08-30T21:17:54Z")

</div>

It seems that Oracle has released a patch:

[Oracle Security Alert for CVE-2012-4681](http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html) (discussion of patch)

[http://www.oracle.com/technetwork/java/javase/downloads/index.html](http://www.oracle.com/technetwork/java/javase/downloads/index.html) (download files)

I assume that this is also what beowulff’s link is providing.

---

<div class="post-metadata">

### Author: ![Taomist](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@Taomist](https://boards.straightdope.com/u/Taomist)
#### Post date: [August 30, 2012, 9:30pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/13 "2012-08-30T21:30:15Z")

</div>

I have to keep it installed because I have online forms/sites that require it \<I think\> but definitely have it disabled. And MSE found 3 Java Trojans on the 20th on it’s nightly run last week. 😮 (Sorry, can’t do proper smiles without Java, lol)

---

<div class="post-metadata">

### Author: ![njtt](https://avatars.discourse-cdn.com/v4/letter/n/ecd19e/32.png) [@njtt](https://boards.straightdope.com/u/njtt)
#### Post date: [August 30, 2012, 9:54pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/14 "2012-08-30T21:54:18Z")

</div>

> [@Taomist](#):
>
> I have to keep it installed because I have online forms/sites that require it \<I think\> but definitely have it disabled. And MSE found 3 Java Trojans on the 20th on it’s nightly run last week. 😮 (Sorry, can’t do proper smiles without Java, lol)

No. You do not need **Java** to use smilies on The Dope. You do however (it turns out) need **JavaScript** to use the smiley system. As I pointed out above, **Java** and **JavaScrip** t are two entirely different things, that just happen\* to have similar names. If the Dope smilies are not working for you, you have **JavaScript** disabled, and it is probably **JavaScript** that you need for your forms. However, you may very well still have **Java** enabled, and the problem this thread is concerned with is a problem with **Java** , _not_ **JavaScript**.

You can’t uninstall **JavaScript** anyway, you can only disable it. You _can_ uninstall **Java** (or just not have it installed in teh first place).  
\*Actually the confusion was originally semi-intentional on the part of the designers of **JavaScript** - **Java** was new and trendy at the time, and they were trying to piggyback on its popularity - but they are still different things. As things worked out, **JavaScript** became much the more important, and more widely used, web technology.

---

<div class="post-metadata">

### Author: ![Der\_Trihs](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/der_trihs/32/233_2.png) [@Der\_Trihs](https://boards.straightdope.com/u/Der_Trihs)
#### Post date: [August 30, 2012, 10:06pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/15 "2012-08-30T22:06:23Z")

</div>

> [@njtt](#):
>
> This vulnerability affects Java, but _not_ JavaScript. JavaScript does have its own vulnerabilities, but, unlike Java, very many, perhaps most, web sites do rely on JavaScript to work properly (though not the Dope, I think).

The little formatting buttons in the Post Message screen don’t work if you disable JavaScript. You have to type everything by hand and hope you remember the proper syntax.

---

<div class="post-metadata">

### Author: ![njtt](https://avatars.discourse-cdn.com/v4/letter/n/ecd19e/32.png) [@njtt](https://boards.straightdope.com/u/njtt)
#### Post date: [August 30, 2012, 10:11pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/16 "2012-08-30T22:11:24Z")

</div>

> [@Arnold\_Winkelried](#):
>
> It seems that Oracle has released a patch:
> 
> [Oracle Security Alert for CVE-2012-4681](http://www.oracle.com/technetwork/topics/security/alert-cve-2012-4681-1835715.html) (discussion of patch)
> 
> [Java Downloads | Oracle](http://www.oracle.com/technetwork/java/javase/downloads/index.html) (download files)
> 
> I assume that this is also what beowulff’s link is providing.

I am not sure? I updated my Java late last night (after reading about this issue on another site), and it still came up as vulnerable on the test site. I take it that the patch is brand new. Has it been integrated into the regular release yet?

> [@FloatyGimpy](#):
>
> How do I uninstall Java?

In Windows, the easiest and surest way is to do it through uninstall programs in control panel. The instructions on those web pages are for disabling it from running in your browser (but leaving it on your machine in case it is needed for something else), which, it turns out, is not to hard to do in Firefox and probably in Chrome, but really difficult and complex in IE. I think very few people actually use Java for anything that is not browser based, and there are really not very web sites that use it now either, so just uninstalling is almost certainly OK.

On the other hand, from what **Arnold** and **beowulff** say, maybe the latest version is safe now (until some hacker discovers a newer vulnerability). I uninstalled last night, and I don’t think I am going to bother to put it back unless and until I have a real need for it.

---

<div class="post-metadata">

### Author: ![njtt](https://avatars.discourse-cdn.com/v4/letter/n/ecd19e/32.png) [@njtt](https://boards.straightdope.com/u/njtt)
#### Post date: [August 30, 2012, 10:14pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/17 "2012-08-30T22:14:34Z")

</div>

> [@Der\_Trihs](#):
>
> The little formatting buttons in the Post Message screen don’t work if you disable JavaScript. You have to type everything by hand and hope you remember the proper syntax.

Yep, and Dope smilies, as I just discovered (see above). Probably the drop-down menus at the top of the page, too.

Unlike **Java** , **JavaScript** is ubiquitous, and necessary for a good web experience.

---

<div class="post-metadata">

### Author: ![voltaire](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/voltaire/32/313_2.png) [@voltaire](https://boards.straightdope.com/u/voltaire)
#### Post date: [August 30, 2012, 10:27pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/18 "2012-08-30T22:27:23Z")

</div>

Just in case there are people here who need Java and are going to update: You NEED to uninstall all of the older versions of Java before updating to the newest version. If you update to the newest version without uninstalling the previous versions, the older versions and their vulnerabilities will remain on your system.

---

<div class="post-metadata">

### Author: ![gardentraveler](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gardentraveler/32/3576_2.png) [@gardentraveler](https://boards.straightdope.com/u/gardentraveler)
#### Post date: [August 30, 2012, 10:47pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/19 "2012-08-30T22:47:09Z")

</div>

I just went to uninstall and saw that I have JavaFX as well as Java. Is that part of what needs to be uninstalled before the new install? (This is on my PC laptop running Windows 7, in case that’s relevant in any way.)

---

<div class="post-metadata">

### Author: ![MrSquishy](https://avatars.discourse-cdn.com/v4/letter/m/b9e5f3/32.png) [@MrSquishy](https://boards.straightdope.com/u/MrSquishy)
#### Post date: [August 31, 2012, 6:10pm UTC](https://boards.straightdope.com/t/disable-java-in-your-browser/633102/20 "2012-08-31T18:10:08Z")

</div>

> [@njtt](#):
>
> As things worked out, **JavaScript** became much the more important, and more widely used, web technology.

I will only agree with this if you insert “client-side” in there before “web technology”.

[Next page](https://boards.straightdope.com/t/disable-java-in-your-browser/633102.md?page=2)
