Homeland Security warns to disable Java amid zero-day flaw

This is not correct. First of all, Java 7 for Windows is out. I uninstalled it from my computer yesterday after first reading about this alert. Secondly, if you are still running Java 6, that is an obsolete version that has vulnerabilities that were patched in Java 7. You are not safe with it; you are probably even more unsafe than with Java 7.

For most people, the best thing to do is simply to uninstall Java from your computer altogether (if it is there in the first place). Most people simply are making no use of it anyway. Although Java aplets used to be fairly common on web pages, that is no longer the case.

Windows users can do this simply by going to Programs under Control Panel and uninstalling Java.

I am on v18 and I just looked. Silverlight is not disabled. Is there any good reason it should be? (Java is not there because I uninstalled it.)

I use Firefox, and when I checked my plug-ins, I saw that Java is already disabled but Silverlight is not. Big computer know-nothing here (it’s embarrassing), so I have no idea if Silverlight is bad or not.

Silverlight might be disabled on mine because of NoScript–and it’s marked as “use with caution” but since I pretty much never need it I don’t bother enabling it.

I had v7 installed, but not any more.

To check Internet Explorer, all versions including IE 10:

Go to Tools on the taskbar.
Manage Add Ons.
On the left it will probably say under Show, ‘show current add ons’, change that to ‘show all add ons.’

Go through the list of add ons and disable anything from Oracle.

What about JavaFX? Is that exploitable as well?

Oracle has released a fix.

But note that they knew about this problem for some time and the patch in October didn’t completely fix it. So who knows if they’ve really fixed it this time.

I am such a computer weenie. I use Firefox and Windows.

Just so’s I understand this correctly, are y’all saying that in order to protect my computer, I need to disable anything with the word Java in it that’s shown as a plug-in in Firefox but can allow “enable JavaScript” under the Options tab? Is this correct or have I totally misunderstood this…

And if I’ve got it wrong, can someone please tell me what I need to do? Thanks so much!

At this point, if you have Java 7, update to Java 7.11.

JavaScript is completely different, not a problem.

There is no need for this, or any other fucking about with browser settings, if you do what I said: simply uninstall Java via the control panel Programs icon. Unless you know you need Java for some specific purpose, you almost certainly do not need it at all. Its ubiquity on most computers is a hangover from former times.

Agreed, most people can just uninstall Java. The only things I know that might use Java are browser-based games and certain applets like Internet speed tests.

I run the Chrome browser, inside a Sandboxie sandbox. Apparently I already had Java disabled for a year or more but only noticed it recently when I tried to run a speed test.

Thank you!