Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Java
From: Justin Mason <jmason @ iona . ie>
Date: Tue, 31 Oct 1995 12:37:21 +0000
To: Mike Shaver <shaver @ neon . ingenia . com>
Cc: Firewalls @ greatcircle . com
In-reply-to: <199510310710 . CAA30694 @ neon . ingenia . com>

Mike Shaver <shaver @
 neon .
 ingenia .
 com>:

[HotJava security modes:]
>- No Access: [...]
>- Originating host access: the applet can open connections back to the
>host from which it was loaded (although there is a bug that sometimes
>forbids the applet from opening connections to the original host), but
>nowhere else.
>- "Firewall" access: applets can open connections to anywhere outside of
>a user-defined firewall (most likely the netblock(s) of the local
>network, but it's flexible), but not inside.  Sun was thinking, it
>seems.  (Yes, you depend on the user to not do anything stupid.  Yet
>again...)
>- Anything Goes: applets can open any damned connection they please.
>Caveat everyone.

By the way, there's problems with these security modes and a web proxy
(in the 1.0b3 version on Solaris). When an applet tries to access a
URL, it actually opens a connection to the web proxy; this is spotted
by the security mode, and a security exception is raised.

You can see the problems this raises: The only way to get a URL-opening
applet working is to open up security and allow conns to the proxy,
which means that anything the proxy can access, the java applet can
access too. Hey presto, no security mode.

It'd be easy enough to fix this, and I'm sure they will. Just FWIW...

--j.


Follow-Ups:
  • Re: Java
    From: Mike Shaver <shaver @ neon . ingenia . com>

References:
  • Re: Java
    From: Mike Shaver <shaver @ neon . ingenia . com>
Indexed By Date Previous: ncsa/firewalls/viruses
From: a000 @ gate . net
Next: Re: Java
From: Mike Shaver <shaver @ neon . ingenia . com>
Indexed By Thread Previous: Re: Java
From: Mike Shaver <shaver @ neon . ingenia . com>
Next: Re: Java
From: Mike Shaver <shaver @ neon . ingenia . com>

Google
 
Search Internet Search www.greatcircle.com