Security Alert: Disable Java immediately
Summary: There is a security vulnerability in Java. Right now the only way to avoid it (if you have Java installed) is to disable Java. In Safari, you can do that by going to Safari's Preferences, and uncheck the box next to "Enable Java" so that it looks like this:
Over on TUAW.com I wrote A reasonable response to Java security problems and explain how to disable Java on Safari, Firefox, and Google Chrome.
([Advanced Users]: In that article at TUAW I also discuss using Fluid.app for any sites you must use which require Java.)
This is not the first time Java has had a major security hole
It seems like it was only yesterday that I recommended to the NMUG folks that they disable Java.
Technically it was two days ago, before this latest security problem was discovered.
I recommended disabling Java because very few sites use it, and it has had security problems in the past. So why take the chance?
There is a report that Apple has actually taken a step which should automatically disable Java in your browser if you are using Mac OS X 10.6, 10.7, or 10.8 (Snow Leopard, Lion, or Mountain Lion), but I'd recommend just leaving it off.
"Should I disable all plugins?"
The screenshot above shows "Enable Plugins" is also disabled. I do that because I find that I don't miss it, but others might.
A more reasonable step would be to install the ClickToPlugin extension for Safari. It gives you much greater control over your plugins than disabling them altogether.
A few final notes of clarification
Don't confuse "Java" with "JavaScript"! They are two completely different things. Unfortunately they have very similar names. You can't uninstall JavaScript, only Java.
iOS (meaning iPads, iPhones, and iPod touch) does not include Java at all, so you don't need to worry about it there.
Originally posted 2013-01-11. If you are reading this in the distant future, the security problem mentioned above may be fixed, but my recommendation to leave Java disabled remains.









