X-Received: by 10.224.18.132 with SMTP id w4mr3557039qaa.1.1366165531326; Tue, 16 Apr 2013 19:25:31 -0700 (PDT) X-Received: by 10.50.128.105 with SMTP id nn9mr88678igb.17.1366165531290; Tue, 16 Apr 2013 19:25:31 -0700 (PDT) Path: csiph.com!v102.xanadu-bbs.net!xanadu-bbs.net!news.glorb.com!cj1no2582577qab.0!news-out.google.com!ef9ni42441qab.0!nntp.google.com!ca1no48217597qab.0!postnews.google.com!glegroupsg2000goo.googlegroups.com!not-for-mail Newsgroups: comp.lang.java.programmer Date: Tue, 16 Apr 2013 19:25:31 -0700 (PDT) In-Reply-To: <516e04f5$0$32117$14726298@news.sunsite.dk> Complaints-To: groups-abuse@google.com Injection-Info: glegroupsg2000goo.googlegroups.com; posting-host=69.28.149.29; posting-account=CP-lKQoAAAAGtB5diOuGlDQk0jIwmH0T NNTP-Posting-Host: 69.28.149.29 References: <516e04f5$0$32117$14726298@news.sunsite.dk> User-Agent: G2/1.0 MIME-Version: 1.0 Message-ID: Subject: Re: > Sandboxed power == More secure??? From: Lew Injection-Date: Wed, 17 Apr 2013 02:25:31 +0000 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable Xref: csiph.com comp.lang.java.programmer:23480 Arne Vajh=F8j wrote: > Richard Maher wrote: >> Perhaps the most significant change will be that, in the default >> setting, sites will not be able to force the small programs known as >> Java applets to run in the browser unless they have been digitally >> signed. Users can override that only if they click to acknowledge the >> risk, Rizvi said. >> Read more: >> http://www.smh.com.au/it-pro/security-it/oracle-fixes-42-holes-in-java-t= o-revive-confidence-20130417-2hz6n.html#ixzz2QfmbSO5B >=20 >> Disbelief! Really? Rather overblown, that reaction. =20 > They want users to confirm that they want to run an applet. > It somewhat protects against users being infected without noticing if > a malicious site uses a zero day vulnerability. >=20 > And there has been a few of those. >=20 > Chrome already prompts every time. >=20 > A bit frustrating for user experience, Really? > but Oracle has deemed it necessary. But only for unsigned applets. Tempest in a teapot. --=20 Lew