Why is java constantly considered as unsafe?
Each time there is an update to Java, when I install it or some time shortly thereafter, it is marked as unsafe in Firefox.
Are the Java developers working with the Firefox team to correct issues or are they purposely ignoring suggestions?
Additional System Details
- Shockwave Flash 11.9 r900
- Next Generation Java Plug-in 10.45.2 for Mozilla browsers
- NPRuntime Script Plug-in Library for Java(TM) Deploy
- Adobe PDF Plug-In For Firefox and Netscape 11.0.05
- VLC media player Web Plugin 2.1.0
- Qualys BrowserCheck Plugin 220.127.116.11
- Adobe Shockwave for Director Netscape plug-in, version 18.104.22.168
- Winamp Application Detector
- The QuickTime Plugin allows you to view a wide variety of multimedia content in Web pages. For more information, visit the QuickTime Web site.
- IE Tab 2 Plug-in for Mozilla/Firefox
- Foxit Reader Plug-In For Firefox and Netscape
- Npdsplay dll
- User Agent: Mozilla/5.0 (Windows NT 5.1; rv:24.0) Gecko/20100101 Firefox/24.0
I believe all versions of Java are now considered unsafe simply because in the past they have proved to be unsafe.
I think the rationale is: given the number of security vulnerabilities in previous versions of Java it is safer to assume that new versions will be vulnerable even if those vulnerabilities are not yet widely known.
See here for more information:
You can see the complete list of blocked add-ons here:
I hope this helps.
Modified by Ed
Do we ask the Oracle Corporation to fix Java's issues? Or do we ask developers to stop using it?
I think Mozilla are hoping that developers will start to use HTML5 instead of Java (and indeed all browser plugins) because plugins are potentially vulnerable and also often cause crashes / other problems in the browser.
Here's an interesting article on the matter
Thanks. It actually sounds even worse than I'd imagined.
Google Java security issues. There's a lot of concern about Java.
I do believe that Oracle is hammering its own nails into the Java coffin.
EG Apple has banned Java on it's Macs.
I have an interesting situation. All of my PCs are with FF24 and Java 7u45 installed WinXp sp3. Three PCs have Java set to "always ask" with the warning about safety.
One PC has Java plugin and Java Deployment Tookkit are set to "always activate" in the add-ons manager settings. The only options for both are "always activate" and "never activate".
How do I set this to the proper setting of "always ask"?
I've dug around in about:config but cannot see anything obvious.
I'm not too sure about that I'm afraid.
Since this is a slightly different question to the original would you mind starting a new thread and another support person will be along to answer.