Changes welcomed, but one expert said he'd like to see sandbox technology in Java like that used in Adobe Reader and Google Chrome Oracle’s plans to bolster Java security were welcomed by security experts who nevertheless wanted to see more done to lockdown one of hackers’ favorite targets.The Java steward released on Thursday its priorities for the application platform. The changes on tap included automated checking of the validity of signed certificates, stopping unsigned applets from being executed by default and adding centralized management options. The latter included whitelisting of applets in enterprise environments.The upcoming changes, as well as other security efforts outlined in Oracle’s Software Security Assurance Blog, were categorized on Friday by security experts as necessary improvements that were far from definitive.“No one step Oracle is taking stands out as a silver bullet that will cure Java security issues,” said Paul Henry, a security and forensic analyst with Lumension. “That being said, each with one exception is a step in the right direction.” That exception was Oracle’s decision to release Java patches on a quarterly basis, although the company said it would make exceptions for highly critical zero-day vulnerabilities. Given the number of flaws Oracle is patching — 97 so far this year — a quarterly release is too much of a burden for corporate security pros, Henry said.“With the patch load we have seen historically, it may be better and faster to adopt a monthly cycle as Microsoft has done for years,” he said. HD Moore, chief research officer for Rapid7, said he believed the changes in the handling of applets was the most important piece of Oracle’s announcement. In the past, signed applets could run outside of the Java sandbox. Oracle plans to no longer make that possible.“Oracle is changing this model so that signing an applet no longer confers sandbox escape privileges,” Moore said. “This is a good thing for security.”However, Moore wanted to see more improvements related to the Java sandbox, such as adoption of the more secure technology used in Adobe Reader and Google Chrome.[Also see: Java security woes to stay with businesses for a long time]“A malicious applet with a valid signature can still abuse JRE (Java Runtime Environment) security flaws to escape the sandbox and compromise the system,” Moore said.Andrew Storms, director of IT and security operations for Tripwire, said a change he liked was splitting the Java distribution in two, one for the client computer and browser and the other for the server, where corporations run their Java-based business applications. “It’s a smart move to differentiate the two parts of Java, because that has always been pretty confusing for all end users,” Storms said.Oracle, which acquired Java with the purchase of Sun Microsystems in 2010, has been criticized for sometime by security pros for moving too slowly to stop Java exploits.The spotlight was turned on the problem in January when a previously unknown flaw actively exploited by cybercriminals prompted the Department of Homeland Security to advise consumers to disable Java on their PCs. The DHS warning was the same advocated by security experts for quite awhile.While the security problems mostly involved the Java browser plug-in, the extensive publicity raised concern among Oracle’s corporate customers. As a result, Oracle has started to show progress in handling Java security, experts say. Related content news UK government plans 2,500 new tech recruits by 2025 with focus on cybersecurity New apprenticeships and talent programmes will support recruitment for in-demand roles such as cybersecurity technologists and software developers By Michael Hill Sep 29, 2023 4 mins Education Industry Education Industry Education Industry news UK data regulator orders end to spreadsheet FOI requests after serious data breaches The Information Commissioner’s Office says alternative approaches should be used to publish freedom of information data to mitigate risks to personal information By Michael Hill Sep 29, 2023 3 mins Government Cybercrime Data and Information Security feature Cybersecurity startups to watch for in 2023 These startups are jumping in where most established security vendors have yet to go. By CSO Staff Sep 29, 2023 19 mins CSO and CISO Security news analysis Companies are already feeling the pressure from upcoming US SEC cyber rules New Securities and Exchange Commission cyber incident reporting rules don't kick in until December, but experts say they highlight the need for greater collaboration between CISOs and the C-suite By Cynthia Brumfield Sep 28, 2023 6 mins Regulation Data Breach Financial Services Industry Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe