SCIENTIFIC-LINUX-USERS Archives

January 2013

SCIENTIFIC-LINUX-USERS@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Florian Philipp <[log in to unmask]>
Reply To:
Florian Philipp <[log in to unmask]>
Date:
Sat, 19 Jan 2013 12:06:12 +0100
Content-Type:
multipart/signed
Parts/Attachments:
text/plain (962 bytes) , signature.asc (268 bytes)
Am 19.01.2013 02:26, schrieb Todd And Margo Chester:
> Hi All,
> 
> With all the security problems in Java right now, does
> anyone know if HTML5 will eventually sub for Java?
> 
> And, will HTML5 have its own list of prodigious security
> problems?
> 
> Many thanks,
> -T

HTML + javascript had its own share of broken sandboxes just like java.
Not to forget cross site scripting, cross site request forgery, session
ID theft and so on. With HTML5, WebGL was introduced as another major
feature that comes with its own boatload of security issues.

We've also seen security issues in pdfs, jpegs, pngs and so on. It's not
that the java exploits are extraordinary. It's just that

a) Because oracle is just about the only distributor of java runtime
environments these days, if there is an exploit, everyone is affected
while other web exploits are often limited to a single browser.

b) Oracle's handling of these issues seems ... sub-par, to say the least.

Regards,
Florian Philipp



ATOM RSS1 RSS2