kgs and java security hole
- cyclops
- Lives in sente
- Posts: 801
- Joined: Mon May 10, 2010 3:38 pm
- Rank: KGS 7 kyu forever
- GD Posts: 460
- Location: Amsterdam (NL)
- Has thanked: 353 times
- Been thanked: 107 times
- Contact:
kgs and java security hole
From Bonobo's site I got this link descibing a security hole in the Java's browser plugin that the Java Client of KGS uses to let you play online. It seems quite risky but I cannot decide whether KGS players are affected as well.
-
tj86430
- Gosei
- Posts: 1348
- Joined: Wed Apr 28, 2010 12:42 am
- Rank: FGA 7k GoR 1297
- GD Posts: 0
- Location: Finland
- Has thanked: 49 times
- Been thanked: 129 times
Re: kgs and java security hole
Mef wrote:Java 7 just can't catch a break. This is the...third time(?) this has happened...
Does anyone see any correlation with the recent problems and Oracle acquiring Sun?
Offending ad removed
- Bonobo
- Oza
- Posts: 2224
- Joined: Fri Dec 23, 2011 6:39 pm
- Rank: OGS 13k
- GD Posts: 0
- OGS: trohde
- Universal go server handle: trohde
- Location: Lüneburg Heath, North Germany
- Has thanked: 8262 times
- Been thanked: 924 times
- Contact:
Re: kgs and java security hole
Uhm, forgive the vanity, but are you referring to me? Did you read me on FB or G+? Mind to identify yourself to me there?cyclops wrote:From Bonobo's site I got this link descibing a security hole in the Java's browser plugin that the Java Client of KGS uses to let you play online [..]
Groeten van Tom in Duitsland
“The only difference between me and a madman is that I’m not mad.” — Salvador Dali
-
Marcus
- Gosei
- Posts: 1387
- Joined: Tue Apr 20, 2010 8:51 am
- GD Posts: 209
- KGS: Marcus316
- Has thanked: 139 times
- Been thanked: 111 times
Re: kgs and java security hole
Bonobo wrote:Uhm, forgive the vanity, but are you referring to me? Did you read me on FB or G+? Mind to identify yourself to me there?cyclops wrote:From Bonobo's site I got this link descibing a security hole in the Java's browser plugin that the Java Client of KGS uses to let you play online [..]
Groeten van Tom in Duitsland
I just realized you had those links in your sig ... I just added you to my Go circle on G+.
Reading the security link now ...
-
xed_over
- Oza
- Posts: 2264
- Joined: Mon Apr 19, 2010 11:51 am
- Has thanked: 1179 times
- Been thanked: 553 times
Re: kgs and java security hole
cyclops wrote:From Bonobo's site I got this link descibing a security hole in the Java's browser plugin that the Java Client of KGS uses to let you play online. It seems quite risky but I cannot decide whether KGS players are affected as well.
In my opinion, this is mostly just fear, uncertainty and doubt.
Sure, if you go around visiting every random website then you might find some that have either written their java app to exploit this security hole and take advantage of you, or maybe their site was hacked and their otherwise save java app replaced with a hacked version.
KGS has been around for a long time and is actively used and maintained. I trust that site and their app.
-
hyperpape
- Tengen
- Posts: 4382
- Joined: Thu May 06, 2010 3:24 pm
- Rank: AGA 3k
- GD Posts: 65
- OGS: Hyperpape 4k
- Location: Caldas da Rainha, Portugal
- Has thanked: 499 times
- Been thanked: 727 times
Re: kgs and java security hole
The real issue is that browsers need better tools for managing plugins. I use java for KGS, and a handful of older go sites that have applets. If any other site I used had a java applet, I would be very suspicious (because modern web design and development is so strongly against it). I would love built in click to activate and/or whitelisting of plugins.
- cyclops
- Lives in sente
- Posts: 801
- Joined: Mon May 10, 2010 3:38 pm
- Rank: KGS 7 kyu forever
- GD Posts: 460
- Location: Amsterdam (NL)
- Has thanked: 353 times
- Been thanked: 107 times
- Contact:
Re: kgs and java security hole
@bonobo:
Because you have an even higher ratio of "likes" to "be liked" than me, I checked your profile. I guess I had nothing better to do that time. There I found a link to your website and there was the link I copied in my opening post.
I have no idea how to identify myself on your site without joining google. Otherwise I would happpily comply to your request without seeing the use.
schüss
Because you have an even higher ratio of "likes" to "be liked" than me, I checked your profile. I guess I had nothing better to do that time. There I found a link to your website and there was the link I copied in my opening post.
I have no idea how to identify myself on your site without joining google. Otherwise I would happpily comply to your request without seeing the use.
schüss
Last edited by cyclops on Fri Jan 11, 2013 12:46 pm, edited 2 times in total.
- cyclops
- Lives in sente
- Posts: 801
- Joined: Mon May 10, 2010 3:38 pm
- Rank: KGS 7 kyu forever
- GD Posts: 460
- Location: Amsterdam (NL)
- Has thanked: 353 times
- Been thanked: 107 times
- Contact:
Re: kgs and java security hole
So if you trust wms you can safely play on kgs without fearing the java hole. Nothing else but kgs creeps through the hole while playing your daily game.
- Bonobo
- Oza
- Posts: 2224
- Joined: Fri Dec 23, 2011 6:39 pm
- Rank: OGS 13k
- GD Posts: 0
- OGS: trohde
- Universal go server handle: trohde
- Location: Lüneburg Heath, North Germany
- Has thanked: 8262 times
- Been thanked: 924 times
- Contact:
Re: kgs and java security hole
Haha, OK, I like to be quite generous with my likes. OTOH sometimes it’s not so easy, e.g. when people write stuff I agree with together with stuff I don’t. Then I’d love to have some more fine-tuning for liking, like “I especially like your last sentence”cyclops wrote:@bonobo:
Because you have an even higher ratio of "likes" to "be liked" than me, I checked your profile.
Ah, I understand. That’s not my “site” but just a shortcut to my Google+ profile.I guess I had nothing better to do that time. There I found a link to your website
Yeah, that would only make sense if you were on Google+, too.and there was the link I copied in my opening post.
I have no idea how to identify myself on your site without joining google. Otherwise I would happpily comply to your request without seeing the use.
:-)schüss
Greetz, Tom
“The only difference between me and a madman is that I’m not mad.” — Salvador Dali
- cyclops
- Lives in sente
- Posts: 801
- Joined: Mon May 10, 2010 3:38 pm
- Rank: KGS 7 kyu forever
- GD Posts: 460
- Location: Amsterdam (NL)
- Has thanked: 353 times
- Been thanked: 107 times
- Contact:
Re: kgs and java security hole
Bonobo wrote:Haha, OK, I like to be quite generous with my likes.cyclops wrote:@bonobo:
Because you have an even higher ratio of "likes" to "be liked" than me, I checked your profile.
That is why you are a Bonobo!
- Bonobo
- Oza
- Posts: 2224
- Joined: Fri Dec 23, 2011 6:39 pm
- Rank: OGS 13k
- GD Posts: 0
- OGS: trohde
- Universal go server handle: trohde
- Location: Lüneburg Heath, North Germany
- Has thanked: 8262 times
- Been thanked: 924 times
- Contact:
[OT] Re: kgs and java security hole
:-D thxcyclops wrote:Bonobo wrote:Haha, OK, I like to be quite generous with my likes.cyclops wrote:@bonobo:
Because you have an even higher ratio of "likes" to "be liked" than me, I checked your profile.
That is why you are a Bonobo!
Actually I chose the Bonobo as my Avatar/domain/etc. exactly because I believe it’s better actively to spread the love than to wait that it rains down on one
“The only difference between me and a madman is that I’m not mad.” — Salvador Dali
-
speedchase
- Lives in sente
- Posts: 800
- Joined: Sun Dec 04, 2011 4:36 pm
- Rank: AGA 2kyu
- GD Posts: 0
- Universal go server handle: speedchase
- Has thanked: 139 times
- Been thanked: 122 times
Re: kgs and java security hole
People shouldn't hate on Java so much. C, C++ and C# are all much worse when it comes to security, there are literally millions of virus attacks in Windows executable files, and Microsoft's Activex framework is a joke. The only reason people publish articles like this is because they see it as a challenge to try to crack Java's security mechanisms, there is no interest in other frameworks because it is so easy. All security issues in Java are fixed quickly.
-
Ellyster
- Dies in gote
- Posts: 62
- Joined: Thu Jun 21, 2012 12:32 pm
- Rank: KGS 3 kyu
- GD Posts: 0
- KGS: Ellyster
- Location: Granada, Spain | Osaka, Japan | Turku, Finland | Tokyo, Japan
- Has thanked: 50 times
- Been thanked: 22 times
- Contact:
Re: kgs and java security hole
speedchase wrote:People shouldn't hate on Java so much. C, C++ and C# are all much worse when it comes to security, there are literally millions of virus attacks in Windows executable files, and Microsoft's Activex framework is a joke. The only reason people publish articles like this is because they see it as a challenge to try to crack Java's security mechanisms, there is no interest in other frameworks because it is so easy. All security issues in Java are fixed quickly.
Is not about the quantity of bugs in C, C++ C# vs quantity of bugs on Java or even the severity of the bug it self... is about the potential attackability.
Java is everywhere, and specially used in webs a lot... so a Java aplication (applet, servlet,...) have the "special privilege" of being executed instantaneously when the website is visited (meanwhile .exe need to be manually executed), so any significant bug sees its severity powered to the infinity.
It's the same of diseases... you don't mind a mortal disease if its very unlikely to get spread (agrirism) or a common disease that is not severe (flu)... but if you create the new spanish flu... men, that's major words.
- Dusk Eagle
- Gosei
- Posts: 1758
- Joined: Tue Apr 20, 2010 4:02 pm
- Rank: 4d
- GD Posts: 0
- Has thanked: 378 times
- Been thanked: 375 times
Re: kgs and java security hole
ActiveX being indescribably terrible does not excuse vulnerabilities in Java. Most people know that you shouldn't use ActiveX (and most browsers, and all Operating Systems other than Windows, don't have support for it). If zero-day Java vulnerabilities keep being found, then people are going to stop trusting Java applications on the web.
C and C++ aren't really relevant, as no browser grants a website the ability to run C or C++ code on the user's end. Since Java code can be run from a website on a user's machine (as long as they have the plugin installed), security is crucial.
My browser prompts me before running any Java code, so I should be safe (unless I allow it for a site I shouldn't). If your browser doesn't, then just visiting a malicious site could get you infected.
C and C++ aren't really relevant, as no browser grants a website the ability to run C or C++ code on the user's end. Since Java code can be run from a website on a user's machine (as long as they have the plugin installed), security is crucial.
My browser prompts me before running any Java code, so I should be safe (unless I allow it for a site I shouldn't). If your browser doesn't, then just visiting a malicious site could get you infected.
We don't know who we are; we don't know where we are.
Each of us woke up one moment and here we were in the darkness.
We're nameless things with no memory; no knowledge of what went before,
No understanding of what is now, no knowledge of what will be.
Each of us woke up one moment and here we were in the darkness.
We're nameless things with no memory; no knowledge of what went before,
No understanding of what is now, no knowledge of what will be.