Post-patch, US-CERT continues call to disable Java plug-in
It's justified, say security experts, who cite known but unpatched bugs
Computerworld - Even after Oracle patched critical Java vulnerabilities on Monday, the U.S. Computer Emergency Readiness Team (US-CERT) continued urging users to disable Java browser plug-ins.
"Due to the number and severity of this and prior Java vulnerabilities, it is recommended that Java be disabled temporarily in Web browsers," said US-CERT in a note Monday, a day after Oracle shipped an "out-of-band," or emergency update.
While calls to disable a plug-in -- or even to stop using a particular browser -- are not uncommon in the face of active exploits of an unpatched vulnerability, it's unusual that they continue after a patch is released.
But a pair of security professionals, including a researcher known for uncovering scores of Java bugs, said US-CERT's move was justified.
"Disabling Java seems to be a reasonable step to mitigate the risk associated with confirmed, not-yet-patched flaws," said Adam Gowdiak, founder and CEO of Security Explorations, in an email late Tuesday.
Gowdiak was referring to other Java vulnerabilities he has reported to Oracle, including two that he has been told will be patched in an upcoming Feb. 19 update.
Andy Chou, CTO of Coverity, a San Francisco-based developer whose products scan other software for potential security flaws, agreed with Gowdiak.
"Most users don't need to visit sites that use Java applets," said Chou in an email interview. "For them Java is just dead code. [So] it seems reasonable for many users to turn off a feature they don't need."
Recommendations from US-CERT, which is part of the U.S. Department of Homeland Security, carry special weight: The organization acts as a threat clearinghouse and security coordinator for both the public and private sectors.
Gowdiak noted that US-CERT could be basing its recommendation not only on publicly-available information, but also on confidential government sources.
Disabling the Java plug-in inside browsers may be the solution for many, as Chou argued, but some -- enterprise workers especially, but not exclusively -- rely on Java web applets.
So what's their move?
Gowdiak and Chou each recommended that users run Firefox or Chrome, both of which provide a feature dubbed "click-to-play" that requires the user to explicitly authorize a plug-in's execution.
In Chrome, the setting is under the advanced section of Settings (Windows) or Preferences (OS X), in the Privacy subsection. Users must click the "Content Settings" button, then scroll to view the "Plug-ins" listing.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts