Warning this article may contain opinions of the author that you and iTWire don't necessarily agree with. Don't let them get away with it - have your say with a comment!

No. 1 Story

ACCC clears Optus to scrap HFC network and use NBN instead

The ACCC has cleared, provisionally, the proposed deal between Optus and NBN Co under which Optus is to be paid around $800m to shut down its HFC network and transfer customers onto the NBN. read more

No Java fix in Mac OS X 10.5.7

Opinion and Analysis

Furthermore, Tinnes advised users of other operating systems to do the same, even if they have updated Java recently: Java has "a huge attack surface and it suffers from many other security vulnerabilities," he asserted.

The lack of a fix in Mac OS X 10.5.7 was also noted by Landon Fuller, one of the developers of SoyLatte (a port of Java 6 to Mac OS X, now part of the OpenJDK BSD-Port project) and the co-ordinator of the community project that provided temporary patches for the flaws revealed by the Month of Apple Bugs until Apple delivered official fixes.

"[T]hese vulnerabilities remain in Apple's shipping JVMs," he observed.

"Unfortunately, it seems that many Mac OS X security issues are ignored if the severity of the issue is not adequately demonstrated.

"Due to the fact that an exploit for this issue is available in the wild, and the vulnerability has been public knowledge for six months, I have decided to release a my own proof of concept to demonstrate the issue," he added.

If you're curious (and trusting) enough to try Fuller's proof of concept, you'll find a link to it here.

I've already disabled Java in my browsers. It'll be interesting to see how long it will be before I really do need to turn it back on. I recently tested an MFD that uses a Java applet to enable scanning to a computer without installing any software, but apart from that I can't remember the last time I noticed an Java applet loading.

Better safe than sorry.