hß Security update check shut down because of a security hole
Summary
In August 2012 heise Security shut down its online update check because it required Java, and Java 7 had just been found to have a highly critical hole that was already being exploited. The hole affected all browsers with the Java 7 plugin; modules for the Blackhole exploit kit were already circulating, and no patch from Oracle had been announced yet. As an alternative, heise recommended the locally installed Personal Software Inspector.
Ideas
- A security service that needs Java endangers its users when Java is vulnerable.
- Exploit kits make new holes exploitable without programming skills.
- The only thing that helped against the zero-day hole was disabling Java.
- A local checking tool replaced the web-based check.
Insights
- Consistently switching off your own service can be the most responsible security decision.
- For years, browser plugins were one of the biggest points of entry for malware.
Facts
- F-Secure had already spotted modules for the Blackhole exploit kit.
- The current Java version 7 was affected on all operating systems.
References
Critique
- The report gives no identifier for the hole, which makes it harder to match against later updates.
Remarks
- Oracle closed the hole a few days later in an unscheduled update; Java applets in the browser have since been abolished entirely.
Recommendations
- Remove runtime environments and plugins that you do not actively need.
- With security tools, check which dependencies they bring with them.
Links to the original source and the Web Archive open in a new tab.