Java-Gaming.org
Play Revenge of the Titans! The situation is critical. We need fancy commanders to defend Earth, the moon, Mars!
Featured games (78)
games approved by the League of Dukes
Games in Showcase (407)
games submitted by our members
Games in WIP (293)
games currently in development
News: Read the Java Gaming Resources, or peek at the official Java tutorials
 
    Home     Help   Search   Login   Register   
Pages: [1]
  ignore  |  Print  
  Browser security nags (or lack of them!)  (Read 1789 times)
0 Members and 1 Guest are viewing this topic.
Offline Abuse

JGO Coder


Medals: 2


falling into the abyss of reality


« Posted 2008-11-16 00:31:50 »

Attempt to launch an exe -> browser nags you.
Launch a jnlp -> Java plugin nags you if necessary & you havn't accepted the certificate.
unsigned Applet -> obviously sandboxed.
signed Applet -> Java nags you if you havn't accepted the certificate.
signed Jar file -> Java nags you if you havn't accepted the certificate.
unsigned Jar file -> no browser nag, no Java nag, not sandboxed?

Given that even moderately security literate people won't realize a .jar file is a security threat that should not be clicked on willy-nilly, this seems to me to be a little bit of a security hole? (obviously in the browser, not Java per-se)
Or have I simply managed to turn off the nag message somehow?

Make Elite IV:Dangerous happen! Pledge your backing at KICKSTARTER here!
Offline princec
« League of Dukes »

JGO Kernel


Medals: 196
Projects: 3


Eh? Who? What? ... Me?


« Reply #1 - Posted 2008-11-16 03:13:24 »

Looks like a proper hole to me. Strange that no-one's noticed it before,.

Cas Smiley

Offline zammbi

JGO Coder


Medals: 4



« Reply #2 - Posted 2008-11-16 03:54:37 »

I had notice this also a while back and thinking the same thing. But I guess you rarely hear of any harmful jar files.

Current project - Rename and Sort
Games published by our own members! Check 'em out!
Try the Free Demo of Revenge of the Titans
Offline Abuse

JGO Coder


Medals: 2


falling into the abyss of reality


« Reply #3 - Posted 2008-11-16 06:10:13 »

I had notice this also a while back and thinking the same thing. But I guess you rarely hear of any harmful jar files.

If that is indeed the case, it seems to beg the question as to what purpose the scary security warnings are serving in webstart =/ (except the obvious ill effect of scaring off some users)

Make Elite IV:Dangerous happen! Pledge your backing at KICKSTARTER here!
Offline princec
« League of Dukes »

JGO Kernel


Medals: 196
Projects: 3


Eh? Who? What? ... Me?


« Reply #4 - Posted 2008-11-16 14:01:26 »

To be honest they serve no useful purpose at all. Any dodgy crim can get their code signed anyway.

Cas Smiley

Offline zammbi

JGO Coder


Medals: 4



« Reply #5 - Posted 2008-11-22 10:21:45 »

Seems chrome shows a message that that jar files can be harmful.

Current project - Rename and Sort
Offline hishadow

Senior Newbie





« Reply #6 - Posted 2008-11-23 06:42:45 »

In Firefox, the browser will ask if executing a jar. Maybe you have turned this on auto-accept at a previous time?
Pages: [1]
  ignore  |  Print  
 
 
You cannot reply to this message, because it is very, very old.

Play Revenge of the Titans! The situation is critical. We need fancy commanders to defend Earth, the moon, Mars!
 
Browse for soundtracks for your game!

Add your game by posting it in the WIP section,
or publish it in Showcase.

The first screenshot will be displayed as a thumbnail.

The invasion has landed! On Mars! And you're there to beat 'em!
cubemaster21 (97 views)
2013-05-17 21:29:12

alaslipknot (105 views)
2013-05-16 21:24:48

gouessej (135 views)
2013-05-16 00:53:38

gouessej (130 views)
2013-05-16 00:17:58

theagentd (142 views)
2013-05-15 15:01:13

theagentd (128 views)
2013-05-15 15:00:54

StreetDoggy (171 views)
2013-05-14 15:56:26

kutucuk (192 views)
2013-05-12 17:10:36

kutucuk (195 views)
2013-05-12 15:36:09

UnluckyDevil (201 views)
2013-05-12 05:09:57
Complex number cookbook
by Roquen
2013-04-24 12:47:31

2D Dynamic Lighting
by Oskuro
2013-04-17 16:46:12

2D Dynamic Lighting
by Oskuro
2013-04-17 16:45:57

2D Dynamic Lighting
by Oskuro
2013-04-17 16:23:20

Noise (bandpassed white)
by Roquen
2013-04-05 17:36:01

Noise (bandpassed white)
by Roquen
2013-04-03 16:17:38

Java Data structures
by Roquen
2013-03-29 13:21:12

Topic Request
by kutucuk
2013-03-22 21:42:01
Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines | Managed by Enhanced Four Valid XHTML 1.0! Valid CSS!
Page created in 0.101 seconds with 21 queries.