We'll fix Java and communicate better, Oracle's Java security head says

We'll fix Java and communicate better, Oracle's Java security head says

Oracle is planning to step up its community outreach efforts around the programming language

Article comments

Oracle's head of Java security is promising the vendor will "fix" issues with the programming language, as well as improve its outreach efforts to community members, following a spate of high-profile vulnerabilities.

"The plan for Java security is really simple," Java security lead Milton Smith told Java user group leaders. "It's to get Java fixed up, number one, and then number two, to communicate our efforts widely. We really can't have one without the other. No amount of talking or smoothing over is going to make anybody happy. We have to fix Java."

Oracle has been coming under fire recently from experts over what they say is an inability to properly patch vulnerabilities in Java.

Recently, the US Department of Homeland Security even urged users to disable Java in their browsers. Most Java vulnerabilities of late have been at the browser level, according to Smith. "That's really the biggest target now."

Oracle, which gained control of Java through the acquisition of Sun Microsystems, has often been criticised for being tight-lipped in its public communications. But that label won't be fairly applied to the company's Java team moving forward, Smith said during the call, a recording of which was made available through Oracle's website at the end of last week.

Smith and his peers "have a lot of things that we're looking at" with respect to communication, he said. One particular goal is to make sure Oracle is reaching all audiences, from consumer users to IT professionals running data centres to engineers, he said.

Exactly how this will be done hasn't been decided as of yet, but it could include more speeches at tech conferences as well as talking to the press, according to Smith.

Another possibility would be for Oracle to provide updates on security to Java user group leaders, who would then be able to share information with their members, he said.

Smith repeatedly underscored the importance of outreach to Oracle's Java security efforts.

For example, Oracle recently made "very significant" security improvements to Java, such as to prevent silent exploits, he said.

"But people don't understand those features yet," he said. "They're still pretty new."

Share:

Comments

Advertisement
Send to a friend

Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

ComputerworldUK Knowledge Vault

ComputerworldUK
Share
x
Open
* *