It is currently Thu Mar 28, 2024 3:52 pm

All times are UTC - 8 hours [ DST ]




Post new topic Reply to topic  [ 44 posts ]  Go to page 1, 2, 3  Next
Author Message
Offline
 Post subject: Cgoban being blocked in a future Java security update?
Post #1 Posted: Wed Oct 16, 2013 5:44 am 
Beginner

Posts: 3
Liked others: 0
Was liked: 0
Rank: 1-3k
KGS: 2k
Hello,

I always update Java because of security reasons, and for a time now I always got a warning about running it because of security reasons, of course I ignored it because I trust KGS, but now after a recent Java update it states that in a future Java security update that Cgoban will be blocked?

I really like KGS, so am I misunderstanding something? I added three screenshots for further information, because I think since the sound issues not everyone is updating Java anymore. Should I just avoid updating Java from now on, or will Cgoban be updated?

Image

Image

Image

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #2 Posted: Wed Oct 16, 2013 6:13 am 
Lives in gote
User avatar

Posts: 314
Location: Germany
Liked others: 10
Was liked: 128
Rank: KGS 4k
Have you even tried googling this? Just the first part of the error msg together with java yielded this, which links to
this.

So it's really just a convention thing and according to the Oracle page you could avoid it by running the cgoban jar-file directly (without webstart).

As for the KGS security model, the official website basically recommends downgrading your java-version severely to circumvent an easy to fix sound bug, which is frankly insane.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #3 Posted: Thu Oct 17, 2013 6:17 am 
Beginner

Posts: 3
Liked others: 0
Was liked: 0
Rank: 1-3k
KGS: 2k
Thanks for your help.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #4 Posted: Thu Jan 16, 2014 2:15 pm 
Dies in gote

Posts: 21
Liked others: 0
Was liked: 0
Rank: AGA 1 dan
KGS: drgoplayer
I am only able to enter gokgs thru web browsers after another java update. I had to add these exceptions to javaws to do that:
http://files.gokgs.com
http://files.gokgs.com/javaBin/cgoban.jar
using ubuntu add the exceptions under the security tab. in linux open javaws from the terminal as root (sudo javaws)
in windows probably just use Start, Run, cmd and type javaws

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #5 Posted: Thu Jan 16, 2014 3:54 pm 
Dies with sente
User avatar

Posts: 124
Location: still above sea level: http://bit.ly/eQYULx
Liked others: 1
Was liked: 8
Rank: 3d EGF
GD Posts: 1700
Dear all,

I just upgraded JAVA and now 'my security settings' in JAVA
wouldn't allow me to run cgoban.
(despite that I clicked somewhere on 'trust')


How do I get cgoban running?

Above explanations where not yet helpful, I do not get to the stage where I could assign 'exceptions'.
Who has undergone & solved the same problem?

[Windows 7, Firefox]

(I can watch 1 KGS game at a time on my mobile, but it's too cumbersome to play)

Many thanks in advance,
Tommie

_________________
Greetings,
Tommie

3dan EGF (AGA no 13477) || Tommie on KGS: 'June'|| DGS: 'Zhi Laohu' 纸老虎 = 'paper tiger' || Senseis : http://senseis.xmp.net/?tderz ||
ENFP (MBTI) - 'Find your own style within the Fundamentals of Go! '

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #6 Posted: Thu Jan 16, 2014 5:03 pm 
Lives in gote
User avatar

Posts: 314
Location: Germany
Liked others: 10
Was liked: 128
Rank: KGS 4k
Have you tried running the jar-file directly?

In a command line that should be
Code:
java.exe -jar cgoban.jar


assuming "java.exe" is in your PATH and cgoban.jar is in the current directory.


Alternatively, in the java control panel under security you can change the security level. Maybe just lowering this from "Very high" to "High" might do the trick.
The java control panel should be found in your windows control panel under "java" or "java control panel".

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #7 Posted: Thu Jan 16, 2014 6:20 pm 
Lives with ko

Posts: 289
Liked others: 7
Was liked: 42
Rank: 100
GD Posts: 100
I also can no longer run cGoban3 after Java 7.51.

I guess this is the end for KGS.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #8 Posted: Thu Jan 16, 2014 10:50 pm 
Lives in sente

Posts: 923
Location: UK
Liked others: 72
Was liked: 479
Rank: 5 dan
KGS: macelee
It took me 20 minutes and several reboots to change the settings properly in order to run a Java applet (that I wrote to be used by my self only). Oracle is changing the way it presents the security warnings for every new Java updates. This is just crazy.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #9 Posted: Thu Jan 16, 2014 11:27 pm 
Gosei
User avatar

Posts: 1581
Location: Hong Kong
Liked others: 54
Was liked: 544
GD Posts: 1292
I had that problem with the webstart version, then I downloaded the jar version and dragged the icon to the start button and pinned it there. Now it works well just from the jar version.

_________________
http://tchan001.wordpress.com
A blog on Asian go books, go sightings, and interesting tidbits
Go is such a beautiful game.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #10 Posted: Fri Jan 17, 2014 12:24 am 
Judan

Posts: 6087
Liked others: 0
Was liked: 786
You can try offline installation:
http://senseis.xmp.net/?CGoban3OfflineInstallation

Under Windows, if the JRE sandbox does not work for CGoban, you can alternatively use Integrity Levels to let it run in the LOW sandbox for all your internet applications configured that way:

viewtopic.php?f=24&t=2133&hilit=running+cgoban+low
http://home.snafu.de/jasiek/windows_sec ... ncept.html

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #11 Posted: Fri Jan 17, 2014 10:58 am 
Lives in gote
User avatar

Posts: 314
Location: Germany
Liked others: 10
Was liked: 128
Rank: KGS 4k
So I just got the update, and my very first suggestion (running cgoban.jar directly) worked.

A more clean solution to let you continue webstart would be in the java control panel in the security tab to add the exception sites
http://files.gokgs.com/
http://pandanet-igs.com/

The pandanet site is for gopanda (if you happen to use that). This is the solution drgoplayer posted and works just fine here.

RobertJasiek wrote:
Under Windows, if the JRE sandbox does not work for CGoban, you can alternatively use Integrity Levels to let it run in the LOW sandbox for all your internet applications configured that way:

[...]

Your windows security concepts seem rather misplaced in this thread, as they have nothing to do with the problem at hand.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #12 Posted: Fri Jan 17, 2014 1:07 pm 
Lives in sente

Posts: 706
Liked others: 252
Was liked: 251
GD Posts: 846
So, from an Oracle blog, some background. I'd like to emphasize that although user workarounds are possible, it is the application author's responsibility to address this sort of thing and ample warning was provided.

That being said, I prefer the Java Control panel workaround. That way, if WMS gets around to updating CGoban, I'll get the latest version quicker.

So first, find the Java control panel. In Windows, you can launch the control panel and search for it:

Attachment:
findjavacontrol.png
findjavacontrol.png [ 10.42 KiB | Viewed 31920 times ]


Click that thing that looks like a coffee cup drawn by an artist on psychedelics. (Don't get me wrong, I still like Duke.)

This will bring up a dialog with a bunch of tabs. Select the security tab.

Attachment:
javacontrol.png
javacontrol.png [ 24.07 KiB | Viewed 31920 times ]


Then, click the "Edit Site List" button and you should get this:

Attachment:
javacontrol2.png
javacontrol2.png [ 13.96 KiB | Viewed 31920 times ]


Add http://files.gokgs.com, click Add, OK, and OK, and try again by going to http://www.gokgs.com and following the link again to "Download Client and SGF Editor", then either "CGoban for Java Web Start" or "CGoban3 with no file association" as appropriate. (The latter is better if you already have another SGF editor installed that you prefer to use.)

If this does not help, I'd be curious to know so feel free to PM me.


This post by snorri was liked by 3 people: daal, PeterHB, wineandgolover
Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #13 Posted: Fri Jan 17, 2014 1:32 pm 
Judan

Posts: 6087
Liked others: 0
Was liked: 786
leichtloeslich wrote:
Your windows security concepts seem rather misplaced in this thread, as they have nothing to do with the problem at hand.


The OP shows a message box saying "[...] allows the application to run with unrestricted access to your personal files and other ressources on your computer [...]". Using Integrity Level LOW as described in the related section of my windows security concept page and the CGoban settings for that prohibit the application to access personal files or (quite some) other ressources on the computer. Therefore, Integrity Levels can well contribute to solving an important part of the security problem, even if java and CGoban should be buggy and malware should attack them and circumvent JRE's own sandbox. It will then be restricted by the integrity level.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #14 Posted: Sat Jan 18, 2014 4:08 am 
Lives in sente
User avatar

Posts: 866
Liked others: 318
Was liked: 345
This deserves a new topic. Seems urgent to me.

Great job on the windows solution, snorri. Can somebody post a similar, step-by-step guide for osX?

Sadly, not all of us are tech wizards who already know about flags, exceptions, etc., so the solution needs to be written for computer DDK.

I hope my mac doesn't auto-upgrade java, though I wouldn't feel safe supressing updates for long.

Come to the rescue, WMS!

_________________
- Brady
Want to see videos of low-dan mistakes and what to learn from them? Brady's Blunders


This post by wineandgolover was liked by: LuckyJim
Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #15 Posted: Sat Jan 18, 2014 12:20 pm 
Dies in gote

Posts: 21
Liked others: 0
Was liked: 0
Rank: AGA 1 dan
KGS: drgoplayer
I have the client running in ubuntu 10.04 now. Probably will work in all debian versions or all linuxes.
From terminal
sudo javaws (opens console as root user and will require your password)
ensure that
http://files.gokgs.com
http://files.gokgs.com/javaBin/cgoban.jar
are added to the exception list under the security tab.
Now from terminal you should be able to run the client with
sudo javaws http://files.gokgs.com/javaBin/cgoban.jnlp
It may ask for you root user password and the first time it will download the client file. It will also give the security warnings that are shown in earlier posts.

Hopefully wms will get settled into his new job and then take a look at updating the client to be compatible with future java security updates.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #16 Posted: Sat Jan 18, 2014 12:49 pm 
Gosei
User avatar

Posts: 1585
Location: Barcelona, Spain (GMT+1)
Liked others: 577
Was liked: 298
Rank: KGS 5k
KGS: RBerenguel
Tygem: rberenguel
Wbaduk: JohnKeats
Kaya handle: RBerenguel
Online playing schedule: KGS on Saturday I use to be online, but I can be if needed from 20-23 GMT+1
wineandgolover wrote:
This deserves a new topic. Seems urgent to me.

Great job on the windows solution, snorri. Can somebody post a similar, step-by-step guide for osX?

Sadly, not all of us are tech wizards who already know about flags, exceptions, etc., so the solution needs to be written for computer DDK.

I hope my mac doesn't auto-upgrade java, though I wouldn't feel safe supressing updates for long.

Come to the rescue, WMS!


Open preferences (Apple menu on top left, for instance) select the Java icon, go to the security settings and follow add files.gokgs.com and/or goserver.gokgs.com (first one if you use Java Web Start and the second if you use the browser version) to the exception list. Save options, and you are ready to go.

_________________
Geek of all trades, master of none: the motto for my blog mostlymaths.net


This post by RBerenguel was liked by: wineandgolover
Top
 Profile  
 
Offline
 Post subject: CGoban and Security in Java 7
Post #17 Posted: Mon Jan 20, 2014 12:04 am 
Dies in gote
User avatar

Posts: 55
Liked others: 6
Was liked: 12
KGS: UnclMartin
  • WMS repackaged the client for Java Web Start, so this fix should no longer be necessary for users of that client. However, at the time I post this, the applet has not yet been repackaged. This fix is still needed for users of the applet.
  • Following the instructions earlier in this thread, in order to run the applet, I entered the following two exceptions:
    • http://www.gokgs.com
    • http://goserver.gokgs.com
  • Users who found they could run the web start client or the applet by lowering Java security should undo that change. Applet users should enter exceptions, as described in this thread.

The admins would like to know if there is a set of exceptions that works for everybody. If you find a set of exceptions mentioned in this thread does not work for you, but another does, please post that information if no one else has. Thank you.

Edit: I had not noticed that earlier messages in this thread did say that http://files.gokgs.com was needed for the Web Start client, while http://goserver.gokgs.com was needed for the applet. I edited this message. But, I still had to enter two exceptions just to run the applet.


Last edited by UnclMartin on Mon Jan 20, 2014 1:40 pm, edited 4 times in total.
Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #18 Posted: Mon Jan 20, 2014 6:13 am 
Lives in sente
User avatar

Posts: 866
Liked others: 318
Was liked: 345
RBerenguel wrote:
Open preferences (Apple menu on top left, for instance) select the Java icon, go to the security settings and follow add files.gokgs.com and/or goserver.gokgs.com (first one if you use Java Web Start and the second if you use the browser version) to the exception list. Save options, and you are ready to go.


Sigh, this is what I mean when I say instructions need to be idiot proof. In this case, I am the idiot. I followed the instructions and have the security tab open, but it isn't showing me a place to enter exceptions, at least not that my DDK computer skills can see. It is different than snorri's example. See the hidden pic below. How do I add the exceptions discussed? I am on the most recent OS X (10.9.1) and the java 7 update 45. Thanks.

Attachment:
Screen Shot 2014-01-20 at 1.07.42 PM.png
Screen Shot 2014-01-20 at 1.07.42 PM.png [ 101.54 KiB | Viewed 31611 times ]

_________________
- Brady
Want to see videos of low-dan mistakes and what to learn from them? Brady's Blunders

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #19 Posted: Mon Jan 20, 2014 10:37 am 
Dies in gote
User avatar

Posts: 55
Liked others: 6
Was liked: 12
KGS: UnclMartin
The most recent version of Java 7 is update 51. As far as I know, the ability to add exceptions is not available with older versions.

Top
 Profile  
 
Offline
 Post subject: Re: Cgoban being blocked in a future Java security update?
Post #20 Posted: Mon Jan 20, 2014 10:45 am 
Tengen

Posts: 4380
Location: North Carolina
Liked others: 499
Was liked: 733
Rank: AGA 3k
GD Posts: 65
OGS: Hyperpape 4k
Wms may have fixed the problem: https://plus.google.com/108736506961432085848. He also says he hopes to return to working on the HTML client soon.

_________________
Occupy Babel!


This post by hyperpape was liked by: Bonobo
Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 44 posts ]  Go to page 1, 2, 3  Next

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group