Daniel J. Munoz//August 9, 2005//
Date: April 17, 1996
location: New Jersey
Title: Internet/ Burnt by Hot Java?
Author: Daniel Grech
A wave of excitement swept through the Internet community in January with the release of Java 1.0, Sun Microsystem”s programming language for the World Wide Web. Since then, demonstrations of Java”s power–flashy motion video and animation effects–have livened formerly static home pages, transforming the Web into an interactive environment.
“Java is a programming language that will allow people to write applications, called applets, that can be packaged and delivered on the Web,” says Ralph Rivera, senior Multi-Media Producer at In Jersey, an Internet provider. He explains that every time users visit a Web page, the applet is automatically downloaded to their RAM. “The possibilities of Java are only limited by the extent of the imagination of the author,” Rivera adds.
The excitement came to an abrupt halt in March, however, when a team of three Princeton University researchers discovered the most serious security flaw in Java to date. “This flaw would enable a hacker to booby trap a page on the Web, so anyone on the page could have their private data deleted or read,” says Edward Felten, Assistant Professor of Computer Science at Princeton and one of the flaw”s discoverers. “The potential consequences of this bug are more severe than the previous flaws discovered.”
According to an official statement by Sun, “Through a sophisticated attack, a malicious applet can exploit this bug to delete a file or do other damage.” To do this damage, the applet would have to bypass Java”s built-in security system, which certifies that all downloaded information adheres to language safety rules. In addition, the attacker would have to have intimate knowledge of the network he was targeting.
Sun has tried to downplay this risk by stressing that this danger is purely speculative, and no incidents of malignant applets have been reported. Serge Goldstein, Manager of the Information Access Group at Computing and Information Technology at Princeton University, explains, “I suspect there are very few people out there who know how to exploit this bug. Practically speaking, the chances that anyone has been damaged by this are slim to none.”
The relatively limited range of users potentially affected by this exposure further limits its repercussions. Regardless of the platform, be it Macintosh or Windows, from which the browser is run, only Java-enabled Web browsers, such as Netscape Navigator versions 2.0 and above or Sun”s HotJava, are at risk. Netscape versions less than 2.0 are not affected, nor is Netscape 2.0 on Windows 3.1.
Within a week of the bug”s discovery, Netscape and Sun researchers patched the hole, releasing fixes that can be downloaded from the Web. But this discovery has sparked a great deal of concern as net surfers have come to grips with the security issues created by Web innovations. Suddenly, new technology, like Java, seems less appealing.
“For every fix, someone will find a way to break it,” Rivera says. Diane Burley, Director of In Jersey, adds, “If someone wants to be malicious, the person will be malicious, so users must be very careful to protect themselves.”
Rivera emphasizes that all users should make backups of their hard drive and use virus protection programs. He also recommends using the latest versions of software available, since more bugs and problems will have been eliminated, and advises users to avoid the beta versions since they are largely untested.
In addition, Rivera believes that a good rule for net surfers is to visit only Web pages from sources the user can trust. “I am very careful when I visit non-commercial sites, especially when I am downloading onto my hard drive,” he says.
Goldstein encourages all users endangered by the flaw to either disable Java or download the fix. To disable Java, a user should click the “Options” menu item, then “Security Preferences,” then “General,” then check the “Disable Java” box.