Risk
4/18/2013
10:16 AM
50%
50%

Java 7 Malicious App Warning System Draws Criticism

Java runtime environment fails to verify that digital certificates used to sign "trusted" applications haven't been revoked.

This week's release of Java 7 update 21 adds a system meant to warn users away from allowing Java apps that haven't been signed with a digital certificate -- from a certificate authority -- to be allowed to execute. But the new Java 7 runtime environment warning system has been criticized on both usability and information security grounds.

On the user interface front, according to Oracle, the Java Control Panel now presents "additional information and [requires] confirmation before being allowed to run" any Java content or apps. That information includes warnings against executing suspect Java apps, although users will still be able to do so. Some warnings come in the form of a yellow triangle, indicating that an application "cannot be identified because the certificate is untrusted or expired," while a yellow shield and alert will caution when an app "is unsigned and/or the certificate is not valid" and thus should not be trusted.

Cue usability concerns. "Logo and shield. Triangle and shield. Shield alone. Triangle alone. Confused yet?" said Paul Ducklin, head of technology for Sophos in the Asia Pacific region, in a blog post. "You're forgiven if you are, because these dialogs end up asking the very questions that you might reasonably expect Java to answer."

That's because Java 7 doesn't know whether the digital certificates it's relying on are still valid, owing to it failing to use the Online Certificate Status Protocol (OCSP) to check the revocation status of a digital certificate, or at least reference some other type of certificate revocation list (CRL).

"Even the latest #Java [release] still does not check for CRL/OCSP. [It] does have some blacklist or something though ... #blah," said Jindrich Kubec, director of threat intelligence at antivirus vendor Avast, via Twitter.

[ Massive interest in current events + Java vulnerabilities = Good news for cyber scammers. See Malware Attackers Exploit Boston Marathon Bombing. ]

Oracle didn't immediately respond to an emailed request for detailed information about how the Java run-time environment assesses certificate validity, and how often this information gets updated.

But according to David Barroso, head of cybersecurity intelligence at London-based Telefonica Digital, the Java runtime environment relies on a blacklist for known-bad Java archive (.jar) files, which contain Java applets. "The blacklist is pretty useless and it only blocks some already known signed vulnerable .jars," he said via Twitter.

According to veteran Java bug-hunter Adam Gowdiak, CEO and founder of Poland-based Security Explorations, the updated Java 7 runtime environment's Java Control Panel changes also put users at risk by allowing them to execute untrusted code. "The only good thing is that users neglecting to update their Java software will be better protected -- unsigned and self-signed Java will not run on their systems," he said. "Users of [the] current Java version will be able to run unsigned and self-signed Java code."

Despite Oracle's Java Control Panel changes, many security experts continue to recommend that people avoid using Java, if possible, or else take suitable precautions. "Disable Java in the browser unless you have a specific business need to run it," said Ross Barrett, senior manager of security engineering at Rapid7, via email. "Ideally, only enable it in an alternate browser and restrict use of that browser to the sites where you need Java."

For anyone who continues to use the browser plug-in, meanwhile, beware exploits that target zero-day Java vulnerabilities. "With a browser plug-in ... as complex as Java -- such as Flash, for instance -- you should always assume that some attacker, somewhere, has at least one zero-day waiting for the right opportunity," said Barrett.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2004-2771
Published: 2014-12-24
The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

CVE-2014-3569
Published: 2014-12-24
The ssl23_get_client_hello function in s23_srvr.c in OpenSSL 1.0.1j does not properly handle attempts to use unsupported protocols, which allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an unexpected handshake, as demonstrated by an SSLv3 handshak...

CVE-2014-4322
Published: 2014-12-24
drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl call, which allows attackers to gain privileges or c...

CVE-2014-6132
Published: 2014-12-24
Cross-site scripting (XSS) vulnerability in the Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3 through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 allows remote authenticated users to inject arbitrary web script or HTML vi...

CVE-2014-6153
Published: 2014-12-24
The Web UI in IBM WebSphere Service Registry and Repository (WSRR) 6.3.x through 6.3.0.5, 7.0.x through 7.0.0.5, 7.5.x through 7.5.0.4, 8.0.x before 8.0.0.3, and 8.5.x before 8.5.0.1 does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture ...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.