Press "Enter" to skip to content

Posts published in “Internet”

Five, Count ‘Em, Five New Security Holes In Java

Those who thought it was safe to re-up Java on their browsers will need to go back and turn it off again.

If you listen to us, after you do you’ll never turn it back on. Browser side Java has been made pretty much obsolete by newer technologies, which means you don’t need it, especially since it’s proving to be about as easy to keep secure as ActiveX, sandbox or no. Here at FOSS Force, we haven’t had it enabled on our browsers for years, with no noticeable problems when we surf the web.

You may remember that back on January 10th it was announced that Java had a security vulnerability that was already being exploited in the wild. This security hole was serious enough to prompt the U.S. Department of Homeland Security to suggest that browser side Java be turned-off on all computers.

Java: Where Oracle, Twitter and Black Hats Meet


Back on January 24th, Oracle was sitting on their hands after issuing incomplete patches to not handle security issues in Java, issues bad enough to evoke dire warnings from the U.S. Department of Homeland Security. I opined on that day that Ellison’s hired help needed to get off their duffs and come up with a good fix quick, even if Java has turned-out to be a puppy Larry Ellison no longer wants to keep. Evidently, somebody in Deadwood City felt the same way, as Oracle pushed a patch this past Friday addressing 50 security holes in the beleaguered programming language.

Wait a minutes, did I just write that the patch addressed 50 security holes? I’ve got a five pound block of Swiss cheese in the fridge that has fewer holes than that. I think if I was Larry Ellison I would be ashamed to admit I’d allowed that many security vulnerabilities to accrue unfixed while any project was under my care. I think I’d fix ten a day or something in five separate patches and try to make it look like I had my security eagles working overtime finding new holes ahead of the bad guys.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

QtWeb: Not Quite Ready For Full Time Browsing

I thought my motherboard was dying.

I have an old Lenovo built, IBM branded desktop with 512 megs of memory and a 3 GHz processor. It runs Windows XP Pro, because the bank requires I run a piece of crap software that only speaks Windows. I’ve learned to live with it.

It’s got a Pentium 4, which had heat dissipation problems, which is why I figure the folks at Lenovo installed a gee-whiz thermostat controlled fan that’ll rev-up way high when needed. Normally that hasn’t been necessary, except when I get carried away watching high def movies or spend too much time strolling down memory lane on YouTube.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Java Still Isn’t Safe – Possible New Vulnerability

I was just guessing on Monday when I said that the Java security patch pushed by Oracle on Sunday was “too little too late.” This appears to have been a lucky good guess on my part, as word is out now that the Java browser plugin still isn’t safe.

At least that’s what Brian Krebs is reporting on his blog Krebs On Security. Evidently there’s a black hat on a hacker forum who’s offering-up info to two buyers on a new vulnerability in the latest and greatest version of Java (that would be version 7, update 11) for the sum of $5,000 each.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Java Security Vulnerability – How To Disable Java In Linux Browsers

When the Homeland Security folks get into the mix and urge all computer users to disable Java in their browsers, you know it’s serious. Indeed, the exploit announced yesterday seems to affect all operating systems, including Linux, and it’s already being exploited. According to Trend Micro the flaw is already being used by blackhat toolkits mainly to distribute ransomware. In a blog posted yesterday, the company advises all users to disable or uninstall Java:

To prevent this exploit, and subsequently the related payload, we recommend users to consider if they need Java in their systems. If it is needed, users must use the security feature to disable Java content via the Java Control Panel, that shipped in the latest version of Java 7. The said feature disables Java content in webpages. If Java content is not needed, users may opt to uninstall Java as it can pose certain security risk.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Assange on the Run: Going Nowhere for Now

Assange now has help, but seemingly not enough.

He’s surrounded by hostile Brits and a government threatening to storm the Ecuadoran embassy where he’s holed up. Ecuador’s government has granted him political asylum and is calling the Brits’ bluff, pointedly reminding them they’re not a colony and haven’t been for quite a long time.

If he does manage to escape and get his feet safely planted on Ecuadoran soil, he has a good chance of being able to eventually return home to Australia, where he has a strong support base.

For now, the Brits are unlikely to follow through on their threatened raid; that would set a dangerous precident. Ernest A. Canning, writing as a guest on The Brad Blog, explained the danger the threat exposes:

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

LendInks, Mob Mentality and the DMCA

The streets of the Internet can be dangerous.

Every day, people are gunned down when they leave the relatively safe main streets of Reddit, Facebook or Twitter to wander into bad neighborhood forums where they’re not known. The usual weapons are words and the common advice is to grow thick skin for protection. Consequences are usually low; feelings are about all that ever get hurt.

Sometimes, however, mobs form. Posses meet up outside a hated website and hit the owners with barrages of venomous email. If a site has a forum or a Facebook page, they try to take over. If it’s supported by ad money, they might launch a campaign against the advertisers, as happened in 2010 with Cooks Source Magazine–a New England site brought down by web users for cavalierly stealing content.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Megauploads, WikiLeaks and Independence Day

Wednesday is the Fourth of July, the day when we in the U.S. celebrate whatever we perceive to be the vision of our founding families. This would seem to be a good time to wonder what the framers of our constitution would think about the way we’ve been applying, or not applying, due process to the Internet.

There are two cases in the news these days that are quite disturbing. For starters, there’s Megaupload.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

The Information Superhighway Is Now The Advertising Superhighway

I have absolutely no problem with people who want to spend their lives amassing wads and wads of money. I personally find it a silly way to live a life, since wealth can’t follow one into the otherworld, but if that’s what trips a person’s trigger, he or she should go ahead and become as rich as possible.

The trouble is, in the last few decades, the wannabe rich folks have decided the whole planet should be nothing but a platform for making money, and they’ve somehow convinced a majority of us that this is sensible. So now we have baseball and football stadiums, once named named after teams or the cities where theses teams played, named after respected corporate entities such as Enron and Bear Stearns. Heck, I expect that soon the Metropolitan Opera House will be known as Sony Music Theater and Lincoln Center will be renamed Lincoln Financial Group Center.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Now It’s Time to Push Congress – Repeal, Repeal, Repeal

While we’ve been busy celebrating our little victory on SOPA and PIPA, the Justice Department has been busy showing us this legislation isn’t necessary, they can take down sites without proving a thing whenever they damn well please. They seized and took offline Megaupload, a popular file-sharing site, indicted it’s owners and froze millions of dollars of assets, claiming the site deliberately aids copyright infringement.

Sweet. Cool. If true, they maybe need to be taken down. It’s a good thing we have the Constitution, which guarantees due process, so we can assume that these claims were proved in a court of law, eh? It’s a good thing we blocked PIPA and SOPA, keeping Justice from taking down sites willy-nilly whenever their suspicions are lit.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Hold Your Horses – We’ve Only Won a Reprieve

I just received an email from Demand Progress, a progressive web site, proclaiming, “Wow. We just won.” The reference, of course, was to Wednesday’s Internet blackout to protest SOPA and PIPA. Indeed, it does appear we’ve won a battle, as both bills appear to be dead – for the time being.

Winning a battle is not the same thing as winning a war. The losing side in any war always wins at least a battle or two. A war isn’t won until the other side raises a white flag and agrees to terms of surrender. So far, all we’ve won is one battle.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Latest Articles