I told you to remove java and flash from your macs!

Discussion in 'Apple' started by Sam Posten, Apr 6, 2012.

  1. Sam Posten

    Sam Posten Moderator
    Moderator

    Joined:
    Oct 30, 1997
    Messages:
    20,709
    Likes Received:
    1,824
    Location:
    Aberdeen, MD & Navesink, NJ
    Real Name:
    Sam Posten
    Do it today if you haven't already!
    http://allthingsd.com/20120406/whats-this-a-mac-virus-no-actually-its-a-weakness-in-java/
     
  2. mattCR

    mattCR Executive Producer
    Reviewer

    Joined:
    Oct 5, 2005
    Messages:
    10,512
    Likes Received:
    385
    Location:
    Overland Park, KS
    Real Name:
    Matt
    Java has traditionally been the root of the majority of windows virus as well. This is just the first one that tried to target Mac using java as the way in.
     
  3. Sam Posten

    Sam Posten Moderator
    Moderator

    Joined:
    Oct 30, 1997
    Messages:
    20,709
    Likes Received:
    1,824
    Location:
    Aberdeen, MD & Navesink, NJ
    Real Name:
    Sam Posten
    Either way,no time like the present to give it the boot. I haven't missed it once.
     
  4. RickER

    RickER Producer

    Joined:
    Jan 4, 2003
    Messages:
    5,130
    Likes Received:
    2
    Location:
    Tulsa, Oklahoma
    Real Name:
    Rick
    Oh , good. I do not even have it installed on my Mac. Thanks for the heads up, and the link!
     
  5. DaveF

    DaveF Moderator
    Moderator

    Joined:
    Mar 4, 2001
    Messages:
    17,248
    Likes Received:
    1,299
    Location:
    One Loudoun, Ashburn, VA
    Real Name:
    David Fischer
    I tried for six months and had to reinstall it. The web isn't usable without Flash.

    And Java was needed for something I use online. I don't recall what, maybe OWA, but I had to keep it installed.

    I guess I need to install an A/V app now. (sigh) (Which, allegedly, didn't catch this malware until well after it was in the wild.)
     
  6. mattCR

    mattCR Executive Producer
    Reviewer

    Joined:
    Oct 5, 2005
    Messages:
    10,512
    Likes Received:
    385
    Location:
    Overland Park, KS
    Real Name:
    Matt
    OWA doesn't use java. But your right, there are tons of sites that rely on it still
     
  7. Sam Posten

    Sam Posten Moderator
    Moderator

    Joined:
    Oct 30, 1997
    Messages:
    20,709
    Likes Received:
    1,824
    Location:
    Aberdeen, MD & Navesink, NJ
    Real Name:
    Sam Posten
    Chrome and you are done. No machine wide flash.
    Please do not bother to install an a/v program. Worse than useless.
     
  8. DaveF

    DaveF Moderator
    Moderator

    Joined:
    Mar 4, 2001
    Messages:
    17,248
    Likes Received:
    1,299
    Location:
    One Loudoun, Ashburn, VA
    Real Name:
    David Fischer
    I tried switching to Chrome.
    Chrome doesn't sync by iCloud with .iOS Safari
    Chrome's Flash also goes bonkers and crushes my CPU.

    Chrome is a good desktop browser, its UI was just a bit weirder and less integrated into the Apple whole.
     
  9. Sam Posten

    Sam Posten Moderator
    Moderator

    Joined:
    Oct 30, 1997
    Messages:
    20,709
    Likes Received:
    1,824
    Location:
    Aberdeen, MD & Navesink, NJ
    Real Name:
    Sam Posten
    Detailed info on the issue.
    http://www.macworld.com/article/1166254/what_you_need_to_know_about_the_flashback_trojan.html
     
  10. Craig S

    Craig S Producer
    Supporter

    Joined:
    Mar 4, 2000
    Messages:
    5,710
    Likes Received:
    184
    Location:
    League City, Texas
    Real Name:
    Craig Seanor
    Dave. if you want to continue to use Safari & Flash at least go install the Safari extension ClickToFlash. It will block all Flash content unless you specifically enable it. You can easily whitelist all trusted sites you use that require Flash.
     
  11. DaveF

    DaveF Moderator
    Moderator

    Joined:
    Mar 4, 2001
    Messages:
    17,248
    Likes Received:
    1,299
    Location:
    One Loudoun, Ashburn, VA
    Real Name:
    David Fischer
    I checked, and realized I had turned off Java in Safari after the first go 'round of this malware.

    I should put ClickToFlash back on. I used it for a while, but it become so annoying have to click things twice to play videos, that I gave up and removed it. Then I tried removing Flash completely. But that turned out to be even more annoying. There's no trivial way to switch to Chrome to open a website to play a video.

    And even if I do switch, my wife isn't going to switch from Safari without a real hard sell on my part. And then she'll be annoyed at me for making her switch from her preferred tool for the next year. It would be like switching her from Excel to Numbers, and that's not happening either.


    (And look, as I type, having just played a Flash video in Safari and closed the tab, "Safari Web Content" is going nuts and at 85% of CPU.)

    Ultimately, Apple has to deal with this. If they get painted with malware worries like Windows, their brand will suffer.
     
  12. DaveF

    DaveF Moderator
    Moderator

    Joined:
    Mar 4, 2001
    Messages:
    17,248
    Likes Received:
    1,299
    Location:
    One Loudoun, Ashburn, VA
    Real Name:
    David Fischer
    It's an Epidemic
    http://daringfireball.net/2012/04/flashback_eword





     
  13. Sam Posten

    Sam Posten Moderator
    Moderator

    Joined:
    Oct 30, 1997
    Messages:
    20,709
    Likes Received:
    1,824
    Location:
    Aberdeen, MD & Navesink, NJ
    Real Name:
    Sam Posten
    You chose to install Java. It does not ship with the OS.
     
  14. mattCR

    mattCR Executive Producer
    Reviewer

    Joined:
    Oct 5, 2005
    Messages:
    10,512
    Likes Received:
    385
    Location:
    Overland Park, KS
    Real Name:
    Matt
    Apple has it with 10.6. And it auto-installs when it detects it needs it. Apple was notified of the flaw which Oracle addressed 2 weeks ago. They didn't release the patch via update when it did. *shrug* Apple shipped it with all of their OS's until last year; so yes, for people who constantly update to the newest/latest/greatest OS, they got it.. but odds are, if you have 10.6 or before, you have Java.

    Because Apple handles the update system for it, which is nice, they should update it.

    *shrug* My gut tells me, though, that Mac has for a long time been not a target of those who wanted to send virus because it wasn't a big enough % of the desktop space, and thus it wasn't as hip.. yes, more secure also, but less attempts also factors in. We'll have to see how 2012 factors the whole thing in.. as a %, Daring Fireball has it right.. at no point in raw % did Windows have a virus this widespread (period). Though in sheer numbers, of course more. It all depends on how you look at it
     
  15. DavidJ

    DavidJ Producer
    Supporter

    Joined:
    Jul 23, 2001
    Messages:
    3,076
    Likes Received:
    224
    Real Name:
    David
    What do I need to do to disable Java?
     
  16. mattCR

    mattCR Executive Producer
    Reviewer

    Joined:
    Oct 5, 2005
    Messages:
    10,512
    Likes Received:
    385
    Location:
    Overland Park, KS
    Real Name:
    Matt
    David-

    Apple's response and info, including Java disable/etc.

    https://discussions.apple.com/thread/3858557?start=0&tstart=0
     
  17. dmiller68

    dmiller68 Supporting Actor

    Joined:
    Sep 29, 2009
    Messages:
    667
    Likes Received:
    3
    Real Name:
    David Miller
    Well I checked my machines and I'm not infected. As has been pointed out you have to a site that has the malware to get the infection. So as long as you go to known sites your pretty safe. I was using chrome for a while but I have had too many issues so I'm back to Safari.

    Thanks for the Link mattCR
     
  18. DaveF

    DaveF Moderator
    Moderator

    Joined:
    Mar 4, 2001
    Messages:
    17,248
    Likes Received:
    1,299
    Location:
    One Loudoun, Ashburn, VA
    Real Name:
    David Fischer
    You do not understand how brand perception works... :)
     
  19. DavidJ

    DavidJ Producer
    Supporter

    Joined:
    Jul 23, 2001
    Messages:
    3,076
    Likes Received:
    224
    Real Name:
    David
    Thanks Matt.
    Do I need to disable both Java and JavaScipt?
     
  20. mattCR

    mattCR Executive Producer
    Reviewer

    Joined:
    Oct 5, 2005
    Messages:
    10,512
    Likes Received:
    385
    Location:
    Overland Park, KS
    Real Name:
    Matt
    The last thing Apple will say is "You chose to install Java" when they provided it through 10.6, and it auto-downloads on detection. It ranks up there with "you're holding it wrong"
     

Share This Page