// COMPLETE THREAD

Re: Why I dislike Java. (was Re: "Scruffies" vs. "Neats")

2 expanded posts ยท every known parent and child

NODE 0937e7d7Re: Why I dislike Java. (was Re: "Scruffies" vs. "Neats")
At  9:03 AM 5/3/96 -0400, Perry E. Metzger wrote:
>... The problem I have is
>that I expect that increasingly pages will arise for which information
>can only be extracted with the use of Java. Some flunky from some desk
>will will come up and scream "what do you mean I can't get a copy of
>Foo Corporation's merger press release because we won't run some
>program! Thats bullshit! Do you know how much money the risk arb desk
>pulls in, you twit! This must never happen again! Fix it immediately!"

Unfortunately the market decided that function and price were more
important than security.  (I know, I spent 10 years developing and trying
to sell an OS with strong security features.)  The only thing I can suggest
to you is, spend the bucks, desk real estate, confusion etc. and have two
machines; a secure/reliable one and an insecure/unreliable one.  Make sure
OS manufacturers like Apple and Microsoft know that you want to be able to
disable the build in Java they have announced.

You may be able to develop a way of transferring the clipboard between the
machines so the dancing Java displayed economic numbers can be easily and
safely transferred to the secure machine's analysis program.

Regards - Bill


------------------------------------------------------------------------
Bill Frantz       | The CDA means  | Periwinkle  --  Computer Consulting
(408)356-8506     | lost jobs and  | 16345 Englewood Ave.
frantz@netcom.com | dead teenagers | Los Gatos, CA 95032, USA
NODE 086624bfRe: Why I dislike Java. (was Re: "Scruffies" vs. "Neats")
On Fri, 3 May 1996, Bill Frantz wrote:

> At  9:03 AM 5/3/96 -0400, Perry E. Metzger wrote:
> >... The problem I have is
> >that I expect that increasingly pages will arise for which information
> >can only be extracted with the use of Java. Some flunky from some desk
> >will will come up and scream "what do you mean I can't get a copy of
> >Foo Corporation's merger press release because we won't run some
> >program! Thats bullshit! Do you know how much money the risk arb desk
> >pulls in, you twit! This must never happen again! Fix it immediately!"
> 
> to sell an OS with strong security features.)  The only thing I can suggest
> to you is, spend the bucks, desk real estate, confusion etc. and have two
> machines; a secure/reliable one and an insecure/unreliable one.  Make sure

As far as I can tell, Perry's requirements are that *no* uncertified "code" 
should be running anywhere inside the firewall, whether it be a java 
applet or a game disk brought in by a temp in settlements.

One application of Solid Oak could be used to help out here; many applets 
are not custom written for a single page, but are instead just instances 
of fairly standard code. If this code is signed for by the software house 
that produced the applet, then the code can be accepted or rejected based 
on a approved vendors list.  This works for most medium security applications

There are situations where this is not enough; normally these 
organisations will have there own security divisions capable of doing 
there own evaluations. In these cases, the local security division could 
sign the code, and the application on the desk be configured to only run 
applets authenticated by the local security team.

Simon
   
---
       We are a bunch of hackers, networked through the soil
       Fighting for the TCP we gained by honest toil
       And when our bytes were threatened, then the cry rose near and far
      "Hurrah for the Buggy GNU Hack that comes in lots of tars"