Java-Gaming.org
Play Revenge of the Titans! The situation is critical. We need fancy commanders to defend Earth, the moon, Mars!
Featured games (78)
games approved by the League of Dukes
Games in Showcase (406)
games submitted by our members
Games in WIP (293)
games currently in development
News: Read the Java Gaming Resources, or peek at the official Java tutorials
 
    Home     Help   Search   Login   Register   
Pages: [1]
  ignore  |  Print  
  Browser security nags (or lack of them!)  (Read 1787 times)
0 Members and 1 Guest are viewing this topic.
Offline Abuse

JGO Coder


Medals: 2


falling into the abyss of reality


« Posted 2008-11-16 00:31:50 »

Attempt to launch an exe -> browser nags you.
Launch a jnlp -> Java plugin nags you if necessary & you havn't accepted the certificate.
unsigned Applet -> obviously sandboxed.
signed Applet -> Java nags you if you havn't accepted the certificate.
signed Jar file -> Java nags you if you havn't accepted the certificate.
unsigned Jar file -> no browser nag, no Java nag, not sandboxed?

Given that even moderately security literate people won't realize a .jar file is a security threat that should not be clicked on willy-nilly, this seems to me to be a little bit of a security hole? (obviously in the browser, not Java per-se)
Or have I simply managed to turn off the nag message somehow?

Make Elite IV:Dangerous happen! Pledge your backing at KICKSTARTER here!
Offline princec
« League of Dukes »

JGO Kernel


Medals: 196
Projects: 3


Eh? Who? What? ... Me?


« Reply #1 - Posted 2008-11-16 03:13:24 »

Looks like a proper hole to me. Strange that no-one's noticed it before,.

Cas Smiley

Offline zammbi

JGO Coder


Medals: 4



« Reply #2 - Posted 2008-11-16 03:54:37 »

I had notice this also a while back and thinking the same thing. But I guess you rarely hear of any harmful jar files.

Current project - Rename and Sort
Games published by our own members! Check 'em out!
Legends of Yore - The Casual Retro Roguelike
Offline Abuse

JGO Coder


Medals: 2


falling into the abyss of reality


« Reply #3 - Posted 2008-11-16 06:10:13 »

I had notice this also a while back and thinking the same thing. But I guess you rarely hear of any harmful jar files.

If that is indeed the case, it seems to beg the question as to what purpose the scary security warnings are serving in webstart =/ (except the obvious ill effect of scaring off some users)

Make Elite IV:Dangerous happen! Pledge your backing at KICKSTARTER here!
Offline princec
« League of Dukes »

JGO Kernel


Medals: 196
Projects: 3


Eh? Who? What? ... Me?


« Reply #4 - Posted 2008-11-16 14:01:26 »

To be honest they serve no useful purpose at all. Any dodgy crim can get their code signed anyway.

Cas Smiley

Offline zammbi

JGO Coder


Medals: 4



« Reply #5 - Posted 2008-11-22 10:21:45 »

Seems chrome shows a message that that jar files can be harmful.

Current project - Rename and Sort
Offline hishadow

Senior Newbie





« Reply #6 - Posted 2008-11-23 06:42:45 »

In Firefox, the browser will ask if executing a jar. Maybe you have turned this on auto-accept at a previous time?
Pages: [1]
  ignore  |  Print  
 
 
You cannot reply to this message, because it is very, very old.

Play Revenge of the Titans! The situation is critical. We need fancy commanders to defend Earth, the moon, Mars!
 
Try the Free Demo of Revenge of the Titans

Add your game by posting it in the WIP section,
or publish it in Showcase.

The first screenshot will be displayed as a thumbnail.

The invasion has landed! On Mars! And you're there to beat 'em!
cubemaster21 (78 views)
2013-05-17 21:29:12

alaslipknot (89 views)
2013-05-16 21:24:48

gouessej (121 views)
2013-05-16 00:53:38

gouessej (113 views)
2013-05-16 00:17:58

theagentd (126 views)
2013-05-15 15:01:13

theagentd (113 views)
2013-05-15 15:00:54

StreetDoggy (156 views)
2013-05-14 15:56:26

kutucuk (179 views)
2013-05-12 17:10:36

kutucuk (179 views)
2013-05-12 15:36:09

UnluckyDevil (186 views)
2013-05-12 05:09:57
Complex number cookbook
by Roquen
2013-04-24 12:47:31

2D Dynamic Lighting
by Oskuro
2013-04-17 16:46:12

2D Dynamic Lighting
by Oskuro
2013-04-17 16:45:57

2D Dynamic Lighting
by Oskuro
2013-04-17 16:23:20

Noise (bandpassed white)
by Roquen
2013-04-05 17:36:01

Noise (bandpassed white)
by Roquen
2013-04-03 16:17:38

Java Data structures
by Roquen
2013-03-29 13:21:12

Topic Request
by kutucuk
2013-03-22 21:42:01
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines | Managed by Enhanced Four Valid XHTML 1.0! Valid CSS!
Page created in 0.16 seconds with 20 queries.