New Post has been published on http://suporteninja.com/oracle-esta-sendo-acusada-de-enganar-clientes-atualizacoes-de-seguranca-do-java/
Oracle esta sendo acusada de enganar clientes "atualizações de segurança" do java
Oracle esta sendo acusada de enganar clientes “atualizações de segurança” do java, as versões desatualizadas continuam instaladas nos computadores, que podem ser facilmente exploradas para possíveis Cyber-ataques.
Oracle é acusada de enganar clientes nas atualizações de segurança java
A comissão federal do comércio dos EUA levantou uma questão sobre a Oracle e transmitiu um enunciado. Segundo a FTC a Oracle falhou em informar os clientes sobre suas atualizações do java. Pois as atualizações não removem as versões anteriores dos computadores, que podem ser facilmente exploradas para possíveis ataques.
“Quando o software de uma empresa está em centenas de milhões de computadores, é vital que as suas afirmações sejam verdadeiras e suas atualizações de segurança forneça segurança para o software”, disse Jessica rico, diretora do Bureau de Proteção ao Consumidor da FTC.
(adsbygoogle = window.adsbygoogle || []).push();
Se gostou da nossa iniciativa comente, curta ou compartilhe! Esse estímulo é muito importante para a nossa equipe e reflete diretamente na possibilidade de trazermos mais conteúdos que você venha a gostar!
Se encontrar algo errado com o site não esqueça que o Site é nosso... <br> Se você quiser perguntar ou sugerir algo para nossa equipe use este link! ou Clique aqui para enviar sua postagem:
A plataforma Standard Edition software (Java SE) está instalada em mais de 850 milhões de computadores pessoais e é essencial que suas atualizações transmitam segurança para seus clientes. Logo após a pronunciação da FTC a Oracle terá que dar a possibilidade de seus clientes desinstalarem versões anteriores do software com mais facilidade.
A Comissão emite uma reclamação administrativa quando tem “razões para acreditar” que a lei foi ou está a ser violado, e parece à Comissão que um processo é de interesse público. Quando a Comissão emite uma ordem de consentimento em uma base final, ele carrega a força da lei no que diz respeito às ações futuras. Cada violação de tal ordem pode resultar em uma penalidade civil de até USD $16.000.00
Oracle has agreed to settle Federal Trade Commission charges that it deceived consumers about the security provided by updates to its Java Platform, Standard Edition software (Java SE), which is installed on more than 850 million personal computers. Under the terms of a proposed consent order, Oracle will be required to give consumers the ability to easily uninstall insecure, older versions of Java SE.
“When a company’s software is on hundreds of millions of computers, it is vital that its statements are true and its security updates actually provide security for the software,” said Jessica Rich, director of the FTC’s Bureau of Consumer Protection. “The FTC’s settlement requires Oracle to give Java users the tools and information they need to protect their computers.”
Oracle’s Java SE provides support for a vast array of features consumers use when browsing the web, including browser-based calculators, online gaming, chatrooms, and 3D image viewing.
According to the FTC’s complaint, since acquiring Java in 2010, Oracle was aware of significant security issuesaffecting older versions of Java SE. The security issues allowed hackers’ to craft malware that could allow access to consumers’ usernames and passwords for financial accounts, and allow hackers to acquire other sensitive personal information through phishing attacks.
In its complaint, the FTC alleges that Oracle promised consumers that by installing its updates to Java SE both the updates and the consumer’s system would be “safe and secure” with the “latest… security updates.” During the update process, however, Oracle failed to inform consumers that the Java SE update automatically removed only the most recent prior version of the software, and did not remove any other earlier versions of Java SE that might be installed on their computer, and did not uninstall any versions released prior to Java SE version 6 update 10. As a result, after updating Java SE, consumers could still have additional older, insecure versions of the software on their computers that were vulnerable to being hacked.
In 2011, according to the FTC’s complaint, Oracle was aware of the insufficiency of its update process. Internal documents stated that the “Java update mechanism is not aggressive enough or simply not working,” and that a large number of hacking incidents were targeting prior versions of Java SE’s software still installed on consumers’ computers.
While Oracle did have notices on their website relating to the need to remove older versions because of the security risk they posed, the information did not explain that the update process did not automatically remove all older versions of Java SE. The updates continued to remove only the most recent version of Java SE installed until August 2014.
The complaint charges that this failure to disclose the limitations of the updates in light of the statements made about the security benefits of the updates was deceptive and in violation of Section 5 of the FTC Act.
Under the terms of the proposed consent order, Oracle will be required to notify consumers during the Java SE update process if they have outdated versions of the software on their computer, notify them of the risk of having the older software, and give them the option to uninstall it. In addition, the company will be required to provide broad notice to consumers via social media and their website about the settlement and how consumers can remove older versions of the software.
The consent order also will prohibit the company from making any further deceptive statements to consumers about the privacy or security of its software and the ability to uninstall older versions of any software Oracle provides.
The FTC has published a blog post for consumers with more information about Java SE’s update issues.
The Commission vote to issue a complaint and accept the proposed consent order was 4-0. The FTC will publish a description of the consent agreement package in the Federal Register shortly. The agreement will be subject to public comment for 30 days, beginning today and continuing through Jan. 20, 2016, after which the Commission will decide whether to make the proposed consent order final. Interested parties can submit comments electronically and following the instructions on the web-based form.
Fonte: FTC
Enviado por: Julio Cezar