Hacker News new | ask | show | jobs
by meowface 4504 days ago
Java's sandbox is no more secure than it was before, but because of Firefox and Chrome adding in a ton of mitigating features like requiring "click to play" by default, disabling it as soon as it goes out of date, and Oracle adding the same features internally, it's definitely way less of a threat right now.

Drive bys are still of course possible via Adobe Flash and Reader exploits, the occasional IE exploit, and the rare Firefox exploit.