 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: What to do about Java in Windows (and elsewhere)?</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/what-to-do-about-java-in-windows-and-elsewhere/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/what-to-do-about-java-in-windows-and-elsewhere/</link>
	<description></description>
	<lastBuildDate>Mon, 13 May 2013 06:09:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: Ed Tittel</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/what-to-do-about-java-in-windows-and-elsewhere/#comment-201</link>
		<dc:creator>Ed Tittel</dc:creator>
		<pubDate>Sun, 20 Jan 2013 23:38:13 +0000</pubDate>
		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=2989#comment-201</guid>
		<description><![CDATA[Dear Tom:Again some good questions and concerns. The reason DHS weighed in so heavily speaks to the pervasiveness of use of Java in government installations, some whose attack and compromise could have serious results. The nature of the vulnerability -- remote code execution -- is such that it could result in complete system takeover if and when the right exploit should be foisted, followed by execution of just the right elements of malware. No, it&#039;s not that this is a bad exception following generally &quot;good behavior&quot; where Java is concerned (it&#039;s been the focus of an increasing number of exploits over the past 18 months or so, but even before then its history was not unblemished). There&#039;s a BIG RISK here which is why it&#039;s receiving a lot of attention, though some of it may be more for sensationalism&#039;s sake.HTH,--Ed--]]></description>
		<content:encoded><![CDATA[<p>Dear Tom:Again some good questions and concerns. The reason DHS weighed in so heavily speaks to the pervasiveness of use of Java in government installations, some whose attack and compromise could have serious results. The nature of the vulnerability &#8212; remote code execution &#8212; is such that it could result in complete system takeover if and when the right exploit should be foisted, followed by execution of just the right elements of malware. No, it&#8217;s not that this is a bad exception following generally &#8220;good behavior&#8221; where Java is concerned (it&#8217;s been the focus of an increasing number of exploits over the past 18 months or so, but even before then its history was not unblemished). There&#8217;s a BIG RISK here which is why it&#8217;s receiving a lot of attention, though some of it may be more for sensationalism&#8217;s sake.HTH,&#8211;Ed&#8211;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TomLiotta</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/what-to-do-about-java-in-windows-and-elsewhere/#comment-200</link>
		<dc:creator>TomLiotta</dc:creator>
		<pubDate>Sun, 20 Jan 2013 17:50:52 +0000</pubDate>
		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=2989#comment-200</guid>
		<description><![CDATA[And to clarify, I&#039;m not asking about you. I&#039;m curious about the general treatment. It&#039;s even been on TV newscasts. -- Tom]]></description>
		<content:encoded><![CDATA[<p>And to clarify, I&#8217;m not asking about you. I&#8217;m curious about the general treatment. It&#8217;s even been on TV newscasts. &#8212; Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TomLiotta</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/what-to-do-about-java-in-windows-and-elsewhere/#comment-199</link>
		<dc:creator>TomLiotta</dc:creator>
		<pubDate>Sun, 20 Jan 2013 17:44:40 +0000</pubDate>
		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=2989#comment-199</guid>
		<description><![CDATA[I understand most of it. It&#039;s just that particular item seems to have caused more of a stir than others in the past have. Is it because DHS is referenced in association? Is it because Java has had a fairly good history (not perfect) and this is therefore out of the ordinary? I didn&#039;t notice any attention to &lt;a href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4792&quot; rel=&quot;nofollow&quot;&gt;CVE-2012-4792&lt;/a&gt;. Is it just because it&#039;s &quot;Oh, well, same old thing&quot;? -- Tom]]></description>
		<content:encoded><![CDATA[<p>I understand most of it. It&#8217;s just that particular item seems to have caused more of a stir than others in the past have. Is it because DHS is referenced in association? Is it because Java has had a fairly good history (not perfect) and this is therefore out of the ordinary? I didn&#8217;t notice any attention to <a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4792" rel="nofollow">CVE-2012-4792</a>. Is it just because it&#8217;s &#8220;Oh, well, same old thing&#8221;? &#8212; Tom</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ed Tittel</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/what-to-do-about-java-in-windows-and-elsewhere/#comment-198</link>
		<dc:creator>Ed Tittel</dc:creator>
		<pubDate>Sat, 19 Jan 2013 16:52:48 +0000</pubDate>
		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=2989#comment-198</guid>
		<description><![CDATA[You make a good point, Tom, but the recommendations come from CERT/DHS and are primarily aimed at US government employees (or rather, the IT admins who cater to their computing and Internet access needs). While it&#039;s true that I laid out a potential strategy for avoiding trouble based on those recommendations, they originate from elsewhere.That said you raise the very interesting question of why we use software subject to zero-day attacks in general. The real answer is &quot;because it&#039;s what we&#039;ve got&quot; which could then even translate into &quot;because we have no choice.&quot; In such a situation, adding extra layers of protection -- as I attempted to do with an insulated VM inside its own separate runtime environment -- makes even more sense, if you ask me.But thanks for asking an important question: Windows itself is surely subject to the same sort of flaws that Java is, and we continue to use it by the billions of copies daily as well.Best wishes,--Ed--]]></description>
		<content:encoded><![CDATA[<p>You make a good point, Tom, but the recommendations come from CERT/DHS and are primarily aimed at US government employees (or rather, the IT admins who cater to their computing and Internet access needs). While it&#8217;s true that I laid out a potential strategy for avoiding trouble based on those recommendations, they originate from elsewhere.That said you raise the very interesting question of why we use software subject to zero-day attacks in general. The real answer is &#8220;because it&#8217;s what we&#8217;ve got&#8221; which could then even translate into &#8220;because we have no choice.&#8221; In such a situation, adding extra layers of protection &#8212; as I attempted to do with an insulated VM inside its own separate runtime environment &#8212; makes even more sense, if you ask me.But thanks for asking an important question: Windows itself is surely subject to the same sort of flaws that Java is, and we continue to use it by the billions of copies daily as well.Best wishes,&#8211;Ed&#8211;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: TomLiotta</title>
		<link>http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/what-to-do-about-java-in-windows-and-elsewhere/#comment-197</link>
		<dc:creator>TomLiotta</dc:creator>
		<pubDate>Sat, 19 Jan 2013 09:52:56 +0000</pubDate>
		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/vista-enterprise-desktop/?p=2989#comment-197</guid>
		<description><![CDATA[Would you use any other software tools or products that are subject to critical zero-day attacks? It&#039;s not clear why this particular issue is raising such awareness when so many previous vulnerabilities outside of Java have mostly passed notice. -- Tom]]></description>
		<content:encoded><![CDATA[<p>Would you use any other software tools or products that are subject to critical zero-day attacks? It&#8217;s not clear why this particular issue is raising such awareness when so many previous vulnerabilities outside of Java have mostly passed notice. &#8212; Tom</p>
]]></content:encoded>
	</item>
</channel>
</rss>
