NODE 0937e7d7Re: Why I dislike Java. (was Re: "Scruffies" vs. "Neats")
frantz@netcom.com (Bill Frantz)Sat, 4 May 1996 14:39:39 +0800
At 9:03 AM 5/3/96 -0400, Perry E. Metzger wrote:
>... The problem I have is
>that I expect that increasingly pages will arise for which information
>can only be extracted with the use of Java. Some flunky from some desk
>will will come up and scream "what do you mean I can't get a copy of
>Foo Corporation's merger press release because we won't run some
>program! Thats bullshit! Do you know how much money the risk arb desk
>pulls in, you twit! This must never happen again! Fix it immediately!"
Unfortunately the market decided that function and price were more
important than security. (I know, I spent 10 years developing and trying
to sell an OS with strong security features.) The only thing I can suggest
to you is, spend the bucks, desk real estate, confusion etc. and have two
machines; a secure/reliable one and an insecure/unreliable one. Make sure
OS manufacturers like Apple and Microsoft know that you want to be able to
disable the build in Java they have announced.
You may be able to develop a way of transferring the clipboard between the
machines so the dancing Java displayed economic numbers can be easily and
safely transferred to the secure machine's analysis program.
Regards - Bill
------------------------------------------------------------------------
Bill Frantz | The CDA means | Periwinkle -- Computer Consulting
(408)356-8506 | lost jobs and | 16345 Englewood Ave.
frantz@netcom.com | dead teenagers | Los Gatos, CA 95032, USA
NODE 086624bfRe: Why I dislike Java. (was Re: "Scruffies" vs. "Neats")
Simon Spero <ses@tipper.oit.unc.edu>Sat, 4 May 1996 15:03:50 +0800
On Fri, 3 May 1996, Bill Frantz wrote:
> At 9:03 AM 5/3/96 -0400, Perry E. Metzger wrote:
> >... The problem I have is
> >that I expect that increasingly pages will arise for which information
> >can only be extracted with the use of Java. Some flunky from some desk
> >will will come up and scream "what do you mean I can't get a copy of
> >Foo Corporation's merger press release because we won't run some
> >program! Thats bullshit! Do you know how much money the risk arb desk
> >pulls in, you twit! This must never happen again! Fix it immediately!"
>
> to sell an OS with strong security features.) The only thing I can suggest
> to you is, spend the bucks, desk real estate, confusion etc. and have two
> machines; a secure/reliable one and an insecure/unreliable one. Make sure
As far as I can tell, Perry's requirements are that *no* uncertified "code"
should be running anywhere inside the firewall, whether it be a java
applet or a game disk brought in by a temp in settlements.
One application of Solid Oak could be used to help out here; many applets
are not custom written for a single page, but are instead just instances
of fairly standard code. If this code is signed for by the software house
that produced the applet, then the code can be accepted or rejected based
on a approved vendors list. This works for most medium security applications
There are situations where this is not enough; normally these
organisations will have there own security divisions capable of doing
there own evaluations. In these cases, the local security division could
sign the code, and the application on the desk be configured to only run
applets authenticated by the local security team.
Simon
---
We are a bunch of hackers, networked through the soil
Fighting for the TCP we gained by honest toil
And when our bytes were threatened, then the cry rose near and far
"Hurrah for the Buggy GNU Hack that comes in lots of tars"