Great Circle Associates Firewalls
(June 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Java and HotJava security issues (fwd)
From: Jeff Welty <jwelty @ wdni . com>
Date: Fri, 9 Jun 1995 09:08:25 -0700 (PDT)
To: Christian Wettergren <cwe @ it . kth . se>
Cc: Peter da Silva <peter @ nmti . com>, Brian Rogers <brogers @ integctr . com>, ken @ bridge . com, firewalls @ greatcircle . com, fwesterv @ hub . eng . wayne . edu
In-reply-to: <199506090712 . JAA20466 @ tmpwww . electrum . kth . se>

On Fri, 9 Jun 1995, Christian Wettergren wrote:

[stuff deleted]

> Another issue is that although Java cannot change .rhosts et al,
> it can change the information within it's reach. This information
> will in due time be very valuable, probably more so than the rest
> of the information on the account. :-)

Best point made so far on Hot Java.  If the language does nothing but
play point&click games of no real consequence, there's no value to
it other than entertainment or maybe education.  If the information
the language manages, however, is important to an organization then
you've got something *really* worthwhile, but you've also got the
security issue again.

The security vulnerability can never go away in a networked-firewalled
system of data-applications, but it can certainly be minimized!

*---------------------------------------------------*
| Jeff Welty <weltyj @
 wdni .
 com>   -=- (206)924-6390  |
|                       *                ---->|     |
| WTC-1A3               * Recycling     / \   |     |
| Weyerhaeuser Company  * Works!         |   \ /    |
| Tacoma, WA  98422     *                |<----     |
*---------------------------------------------------*




References:
Indexed By Date Previous: Re: Hot Java Denial of Services Attack
From: Tim Keanini <blast @ crl . com>
Next: PORTUS v.2 announcement
From: ted @ gw . lsli . com
Indexed By Thread Previous: Re: Java and HotJava security issues (fwd)
From: peter @ nmti . com (Peter da Silva)
Next: Re: Java and HotJava security issues (fwd)
From: Christopher Samuel <chris @ rivers . dra . hmg . gb>

Google
 
Search Internet Search www.greatcircle.com