# Homeland Security warns to disable Java amid zero-day flaw

**URL:** https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893
**Category:** In My Humble Opinion
**Created:** [January 11, 2013, 7:32pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893 "2013-01-11T19:32:19Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![Fool\_in\_the\_Rain](https://avatars.discourse-cdn.com/v4/letter/f/8491ac/32.png) [@Fool\_in\_the\_Rain](https://boards.straightdope.com/u/Fool_in_the_Rain)
#### Post date: [January 11, 2013, 7:32pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/1 "2013-01-11T19:32:19Z")

</div>

[Homeland Security warns to disable Java amid zero-day flaw](http://www.zdnet.com/homeland-security-warns-to-disable-java-amid-zero-day-flaw-7000009713/)

> [@](#):
>
> The U.S. Department of Homeland Security has warned users to disable or uninstall Java software on their computers, amid continuing fears and an escalation in warnings from security experts that hundreds of millions of business and consumer users are vulnerable to a serious flaw.
> 
> Hackers have discovered a weakness in Java 7 security that could allow the installation of malicious software and malware on machines that could increase the chance of identity theft, or the unauthorized participation in a botnet that could bring down networks or be used to carry out denial-of-service attacks against Web sites.

I found this interesting. This is, I believe, the first time they have warned users to disable a program. I know java does have security issues, but is this level of warning warranted?

---

<div class="post-metadata">

### Author: ![Amblydoper](https://avatars.discourse-cdn.com/v4/letter/a/fbc32d/32.png) [@Amblydoper](https://boards.straightdope.com/u/Amblydoper)
#### Post date: [January 12, 2013, 2:45am UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/2 "2013-01-12T02:45:29Z")

</div>

This is a zero-day attack that can affect pretty much any computer, anywhere. Most zero-day explots get patched faster then any serious harm can be done, but this security hole is still wide open.

Apple has disabled Java 7, so if you have a Mac, you are already safe. OSX has a secret blacklist that can remotely kill security issues.

---

<div class="post-metadata">

### Author: ![SmartAleq](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/smartaleq/32/163_2.png) [@SmartAleq](https://boards.straightdope.com/u/SmartAleq)
#### Post date: [January 12, 2013, 5:38am UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/3 "2013-01-12T05:38:51Z")

</div>

If you’re running Firefox and recently updated to v.18 I think you’ll discover that Java and Silverlight are both blocked for vulnerability issues.

---

<div class="post-metadata">

### Author: ![kittenblue](https://avatars.discourse-cdn.com/v4/letter/k/ba8739/32.png) [@kittenblue](https://boards.straightdope.com/u/kittenblue)
#### Post date: [January 12, 2013, 2:30pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/4 "2013-01-12T14:30:38Z")

</div>

I disabled it on two of my computers yesterday morning after hearing about it on Good Morning America, much to the derision of my SO, who couldn’t find mention of it in the news until yesterday evening. For those of us who aren’t up on the lingo, what is meant by “zero-day”? They keep tossing around that term as if it is common knowledge, and it ain’t!

---

<div class="post-metadata">

### Author: ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)
#### Post date: [January 12, 2013, 2:36pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/5 "2013-01-12T14:36:37Z")

</div>

I think ‘zero-day’ means that the vulnerability is known to the world when the software is released.

---

<div class="post-metadata">

### Author: ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)
#### Post date: [January 12, 2013, 4:03pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/6 "2013-01-12T16:03:55Z")

</div>

> [@kittenblue](#):
>
> I disabled it on two of my computers yesterday morning after hearing about it on Good Morning America, much to the derision of my SO, who couldn’t find mention of it in the news until yesterday evening. For those of us who aren’t up on the lingo, what is meant by “zero-day”? They keep tossing around that term as if it is common knowledge, and it ain’t!

> **[Zero-day vulnerability](https://en.wikipedia.org/wiki/Zero-day_attack)**
>
> A zero-day (also known as a 0-day) is a vulnerability or security hole in a computer system unknown to its developers or anyone capable of mitigating it. Until the vulnerability is remedied, threat actors can exploit it in a zero-day exploit, or zero-day attack.
> The term "zero-day" originally referred to the number of days since a new piece of software was released to the public, so "zero-day software" was obtained by hacking into a developer's computer before release. Eventually the term was ap...

---

<div class="post-metadata">

### Author: ![Tom\_Tildrum](https://avatars.discourse-cdn.com/v4/letter/t/e95f7d/32.png) [@Tom\_Tildrum](https://boards.straightdope.com/u/Tom_Tildrum)
#### Post date: [January 12, 2013, 4:04pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/7 "2013-01-12T16:04:49Z")

</div>

I use OpenOffice on Win7. Am I correct that it somehow requires Java?

---

<div class="post-metadata">

### Author: ![OttoDaFe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ottodafe/32/356_2.png) [@OttoDaFe](https://boards.straightdope.com/u/OttoDaFe)
#### Post date: [January 12, 2013, 5:00pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/8 "2013-01-12T17:00:47Z")

</div>

So is this specific to Java 7? I seem to have missed the update boat, and I’m still using Java 6.

---

<div class="post-metadata">

### Author: ![DCnDC](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dcndc/32/2842_2.png) [@DCnDC](https://boards.straightdope.com/u/DCnDC)
#### Post date: [January 12, 2013, 5:09pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/9 "2013-01-12T17:09:25Z")

</div>

> [@Tom\_Tildrum](#):
>
> I use OpenOffice on Win7. Am I correct that it somehow requires Java?

“[Java is mainly required for the HSQLDB database engine.](http://www.openoffice.org/download/common/java.html)”

---

<div class="post-metadata">

### Author: ![DJ\_Motorbike](https://avatars.discourse-cdn.com/v4/letter/d/90ced4/32.png) [@DJ\_Motorbike](https://boards.straightdope.com/u/DJ_Motorbike)
#### Post date: [January 12, 2013, 6:37pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/10 "2013-01-12T18:37:06Z")

</div>

> [@Amblydoper](#):
>
> Apple has disabled Java 7, so if you have a Mac, you are already safe.

I think you forgot the [smug] [/smug] tags.

According to this [article](http://www.politico.com/story/2013/01/feds-issue-warning-on-java-security-86090.html?hp=r3) OSX is vulnerable.

> [@](#):
>
> Dormann said making matters worse is the fact that the vulnerability is true for most operating systems, including Windows, OS X and Linux, and browser-level protections will not work against it.

According to [Oracle](http://www.oracle.com/technetwork/java/javase/documentation/autoupdate-1667051.html) if I’m reading this correctly, they haven’t updated Java for 32bit Windows to v7 yet. It is not due for release until February.

If you’re using a 32bit version of Windows you’re safe because only v7 of Java is vulnerable according to DHS. I do happen to use Windows 7 32bit. I checked the version of Java installed. Yep, version 6 update 37 which is current for 32bit Windows.

[Smug]If you’re using 32bit Windows you should be safe, but if you’re using OS X you may not be.[/Smug] 😉

---

<div class="post-metadata">

### Author: ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)
#### Post date: [January 12, 2013, 6:45pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/11 "2013-01-12T18:45:10Z")

</div>

> [@DJ\_Motorbike](#):
>
> I think you forgot the [smug] [/smug] tags.
> 
> According to this [article](http://www.politico.com/story/2013/01/feds-issue-warning-on-java-security-86090.html?hp=r3) OSX is vulnerable.
> 
> According to [Oracle](http://www.oracle.com/technetwork/java/javase/documentation/autoupdate-1667051.html) if I’m reading this correctly, they haven’t updated Java for 32bit Windows to v7 yet. It is not due for release until February.
> 
> If you’re using a 32bit version of Windows you’re safe because only v7 of Java is vulnerable according to DHS. I do happen to use Windows 7 32bit. I checked the version of Java installed. Yep, version 6 update 37 which is current for 32bit Windows.
> 
> [Smug]If you’re using 32bit Windows you should be safe, but if you’re using OS X you may not be.[/Smug] 😉

If you’re on OS X, there’s a Java Preferences app in /Applications/Utilities. I ran it and it said I have Java SE 6, both 32- and 64-bit.

---

<div class="post-metadata">

### Author: ![DJ\_Motorbike](https://avatars.discourse-cdn.com/v4/letter/d/90ced4/32.png) [@DJ\_Motorbike](https://boards.straightdope.com/u/DJ_Motorbike)
#### Post date: [January 12, 2013, 7:30pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/12 "2013-01-12T19:30:38Z")

</div>

> [@Sunspace](#):
>
> If you’re on OS X, there’s a Java Preferences app in /Applications/Utilities. I ran it and it said I have Java SE 6, both 32- and 64-bit.

Yeah, I wonder on how many machines v7 is actually installed. Anyway I’m disabling Java in Firefox just to be safe until I’ve heard something from Oracle addressing this. In Firefox it can be disabled by going to Tools then Options and then the “Content” tab there is a checkbox disable it if not already.

ETA:Of course half the internet doesn’t work now.

---

<div class="post-metadata">

### Author: ![Procrustus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/procrustus/32/2994_2.png) [@Procrustus](https://boards.straightdope.com/u/Procrustus)
#### Post date: [January 12, 2013, 7:32pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/13 "2013-01-12T19:32:38Z")

</div>

I would have no idea how to “disable” java. I hope no one out there wants to pretend to be me today.

---

<div class="post-metadata">

### Author: ![chappachula](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@chappachula](https://boards.straightdope.com/u/chappachula)
#### Post date: [January 12, 2013, 7:32pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/14 "2013-01-12T19:32:48Z")

</div>

So …what’s Java, and how do I know if it’s installed on my computer?  
I have a home computer with windows XP and IE8.  
I have a work computer with Win7 and IE9.  
Yes, I’m a total techno-phobe. Please answer using words, not incomprehesible capitalized 3-letter abbreviations.)

I know Java is a type of coffee 🙂 .  
I’ve heard of it as a computer language, too. but I have no idea what it does. Or why, if it’s so important for web sites, it isn’t automatically included in the browser. Or , if it’s not automatically included in everyones’ computer, why do websites use it?

I don’t give a damn what’s inside my computer, just like I don’t care what’s under the hood of my car.  
I just turn 'em on, and use 'em.  
When they break, I call a mechanic, or a help-line guy in India…

---

<div class="post-metadata">

### Author: ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)
#### Post date: [January 12, 2013, 8:03pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/15 "2013-01-12T20:03:30Z")

</div>

> [@DJ\_Motorbike](#):
>
> Yeah, I wonder on how many machines v7 is actually installed. Anyway I’m disabling Java in Firefox just to be safe until I’ve heard something from Oracle addressing this. In Firefox it can be disabled by going to Tools then Options and then the “Content” tab there is a checkbox disable it if not already.
> 
> ETA:Of course half the internet doesn’t work now.

You do know that Javascript and Java are two **VERY** different things, don’t you? The security hole in question does not relate to Javascript.

---

<div class="post-metadata">

### Author: ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)
#### Post date: [January 12, 2013, 8:39pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/16 "2013-01-12T20:39:41Z")

</div>

[Apple disables Java 7 in OS X](http://appleinsider.com/articles/13/01/11/zero-day-flaw-prompts-apple-to-block-java-7-from-os-x).

---

<div class="post-metadata">

### Author: ![Sunspace](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/sunspace/32/1250_2.png) [@Sunspace](https://boards.straightdope.com/u/Sunspace)
#### Post date: [January 12, 2013, 8:50pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/17 "2013-01-12T20:50:56Z")

</div>

It turns out that my Mac is too old for the affected version to run on anyways… Java 7 on the Mac requires OS X 10.7.3 or above. I’m running OS X 10.6.8. [Link.](http://www.java.com/en/download/apple.jsp)

---

<div class="post-metadata">

### Author: ![DJ\_Motorbike](https://avatars.discourse-cdn.com/v4/letter/d/90ced4/32.png) [@DJ\_Motorbike](https://boards.straightdope.com/u/DJ_Motorbike)
#### Post date: [January 12, 2013, 9:22pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/18 "2013-01-12T21:22:14Z")

</div>

> [@Canadjun](#):
>
> You do know that Javascript and Java are two **VERY** different things, don’t you? The security hole in question does not relate to Javascript.

Ohhhh. :smack:

Thanks.

---

<div class="post-metadata">

### Author: ![ZenBeam](https://avatars.discourse-cdn.com/v4/letter/z/3ab097/32.png) [@ZenBeam](https://boards.straightdope.com/u/ZenBeam)
#### Post date: [January 12, 2013, 10:42pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/19 "2013-01-12T22:42:33Z")

</div>

> [@Procrustus](#):
>
> I would have no idea how to “disable” java. I hope no one out there wants to pretend to be me today.

[How to Disable Java in Firefox](http://antivirus.about.com/od/securitytips/ht/How-To-Disable-Java-In-Firefox.htm). For me (on Linux), it was something called IcedTea-Web plugin, listed under Tools -\> Add-ons -\> Plugins. YMMV

ETA: [for Chromium](http://superuser.com/questions/201613/disable-java-plugin-in-google-chrome), enter chrome://plugins/ as the URL, and look for the same IcedTea Web Plugin.

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [January 12, 2013, 10:54pm UTC](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893/20 "2013-01-12T22:54:24Z")

</div>

First of all, it [really isn’t a zero-day vulnerability](http://thenextweb.com/insider/2013/01/11/latest-java-vulnerability-possible-since-oracle-didnt-properly-fix-old-one-now-pushing-ransomware/).

Secondly, the term “zero-day” is so mis- and over-used that it really has no effective meaning anymore. Anytime I see an article that describes something as a “zero-day” flaw or whatever, I know immediately the article isn’t going to be technically useful.

The only things that really matters is if the flaw is being used in the wild and has it been patched yet?

The answers are not good for this one.

[Next page](https://boards.straightdope.com/t/homeland-security-warns-to-disable-java-amid-zero-day-flaw/646893.md?page=2)
