cancel
Showing results for 
Search instead for 
Did you mean: 

Why is java constantly considered as unsafe?

Highlighted
New Contributor

Why is java constantly considered as unsafe?

Each time there is an update to Java, when I install it or some time shortly thereafter, it is marked as unsafe in Firefox.

Are the Java developers working with the Firefox team to correct issues or are they purposely ignoring suggestions?

8 REPLIES
Senior Contributor

Re: Why is java constantly considered as unsafe?

Hello,

I believe all versions of Java are now considered unsafe simply because in the past they have proved to be unsafe.

I think the rationale is: given the number of security vulnerabilities in previous versions of Java it is safer to assume that new versions will be vulnerable even if those vulnerabilities are not yet widely known.

See here for more information:

You can see the complete list of blocked add-ons here:

https://addons.mozilla.org/en-US/firefox/blocked/

I hope this helps.

New Contributor

Re: Why is java constantly considered as unsafe?

Do we ask the Oracle Corporation to fix Java's issues? Or do we ask developers to stop using it?

Senior Contributor

Re: Why is java constantly considered as unsafe?

I think Mozilla are hoping that developers will start to use HTML5 instead of Java (and indeed all browser plugins) because plugins are potentially vulnerable and also often cause crashes / other problems in the browser.

New Contributor

Re: Why is java constantly considered as unsafe?

Here's an interesting article on the matter

http://threatpost.com/javas-losing-security-legacy

Senior Contributor

Re: Why is java constantly considered as unsafe?

Thanks. It actually sounds even worse than I'd imagined.

New Contributor

Re: Why is java constantly considered as unsafe?

Google Java security issues. There's a lot of concern about Java.

I do believe that Oracle is hammering its own nails into the Java coffin.

EG Apple has banned Java on it's Macs.

New Contributor

Re: Why is java constantly considered as unsafe?

I have an interesting situation. All of my PCs are with FF24 and Java 7u45 installed WinXp sp3. Three PCs have Java set to "always ask" with the warning about safety.

One PC has Java plugin and Java Deployment Tookkit are set to "always activate" in the add-ons manager settings. The only options for both are "always activate" and "never activate".

How do I set this to the proper setting of "always ask"?

I've dug around in about:config but cannot see anything obvious.

Senior Contributor

Re: Why is java constantly considered as unsafe?

I'm not too sure about that I'm afraid.

Since this is a slightly different question to the original would you mind starting a new thread and another support person will be along to answer.

Thanks.