Review And Predictions For Security
Recently there was a big 0day exploit in the wild for the Java Runtime Environment. A lot of websites were hacked and they were distributing malware via the exploit. Oracle’s response was atypical, they got a patch out within a somewhat reasonable time and, beyond that, they’ve implemented a feature that allows Java to always prevent unsigned applets from running. That’s good news for users who need Java, and can’t just disable it.
On top of that Firefox has joined Chrome and now disables Java by default requiring user interaction to let any Java applets run, whether signed or not. Firefox and Chrome hold a combined number of users that dominates browser market share. Millions of users who have moved to Firefox’s latest version will now have to click multiple times just for an exploit kit to begin.
The combination of these two new features means that Java is less of a viable target than it was so recently. It will likely take months for the effects of these changes to propagate throughout the world but at some point the majority of users will have Java denied by default.
And then what? Attackers will have a number of options. They can start focusing on local exploits paired with remote exploits, to get out of sandboxes that are now used in Flash, Chrome, and Internet Explorer 9/10. They can continue targeting Java, with less reliability. Or they can find a new target, maybe mass-spamming IM clients, attacking antiviruses, torrent clients, etc.
I can’t predict what hackers will or won’t do. Trends can start spontaneously, but we can predict that as Java’s security slowly improves, and as browsers take more and more responsibility for the plugin, successful exploitation of the plugin will decrease. Whatever attackers wind up doing we’re probably going to find some changes in the threat landscape in 2013/2014.
blog comments powered by Disqus