|
|
|
|
|
by Silhouette
4623 days ago
|
|
The plugin is quite dangerous, an "aggressive" stance sounds reasonable to me. But what would persisting with claims that Java plug-ins are always dangerous have achieved? By a similar argument, the Firefox team fixes several security vulnerabilities they themselves describe as "critical" in each new six-weekly release, so they ought to have advised users not to run Firefox either. Software has bugs, and security flaws need to be fixed, but something about glass houses and stones kept coming to mind with the previous stance. The new one seems a reasonable balance and a constructive policy, and I welcome it as such. |
|
Oracle has been issuing ~50 per quarter recently, an incredibly long time to wait for critical fixes. In security, less is more. Now that Windows has become safer, the big targets are Java and Flash. It continues to be good practice to avoid standing behind big targets.