Skip to main content [aditude-amp id="stickyleaderboard" targeting='{"env":"staging","page_type":"article","post_id":604366,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"entrepreneur,","session":"C"}']

Homeland Security: Sorry, Oracle, your fix isn’t good enough

Homeland Security: Sorry, Oracle, your fix isn’t good enough

The Department of Homeland Security says, despite Oracle's recent Java patch, that you should keep Java disabled to "mitigate other Java vulnerabilities that may be discovered in the future."

Homeland Security

The Department of Homeland Security warned today that you should still disable Java soon after Oracle released a patch for a hole in Java that enabled hackers to sneak into your computer to steal information or hook you up to a botnet.

[aditude-amp id="flyingcarpet" targeting='{"env":"staging","page_type":"article","post_id":604366,"post_type":"story","post_chan":"none","tags":null,"ai":false,"category":"none","all_categories":"entrepreneur,","session":"C"}']

“DHS is skeptical because it’s highly likely yet another Java vulnerability is found soon, starting this all over again,” said F-Secure chief research officer Mikko Hypponen in an email to VentureBeat. “The problem is the Java plugin in the browser. Remove the plugin from your daily browser. Then, if some site that you really need needs Java, use a secondary browser with the plugin enabled just for that site.”

The hole recently fixed in Java 7 enables an attacker to secretly install software on your computer by using an infected website to access Java and secretly slip into your system. Criminals may also create fake websites intended to trick a user into thinking that it is legitimate. From there, the hackers can grab your personal information or use your computer as part of a botnet string that could be used to attack other systems.

AI Weekly

The must-read newsletter for AI and Big Data industry written by Khari Johnson, Kyle Wiggers, and Seth Colaner.

Included with VentureBeat Insider and VentureBeat VIP memberships.

“Unless it is absolutely necessary to run Java in web browsers, disable it as described below, even after updating to 7u11,” the Department of Homeland Security warned in its advisory, “This will help mitigate other Java vulnerabilities that may be discovered in the future.”

The hole affects Windows computers, Macs, and Linux machines. DHS warns that other devices that use Java 7 may also be at risk.

Oracle provides detailed instructions on how to disable Java on a number of different systems on its website.

hat tip The New York Times; Homeland Security image via DonkeyHotey/Flickr

VentureBeat's mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Learn More