[ / / / / / / / / / / / / / ] [ dir / arepa / general / komica / lewd / mde / nofap / vg / vichan ][Options][ watchlist ]

/tech/ - Technology

You can now write text to your AI-generated image at https://aiproto.com It is currently free to use for Proto members.
Email
Comment *
File
Select/drop/paste files here
Password (Randomized for file and post deletion; you may also set your own.)
* = required field[▶ Show post options & limits]
Confused? See the FAQ.
Expand all images

File (hide): b7ebde42957440d⋯.png (558.01 KB, 644x651, 92:93, java.png) (h) (u)

[–]

 No.993077>>993085 [Watch Thread][Show All Posts]

The claim that Java is insecure is just a meme right? I know that sandbox is shit but that's that really needed for standalone applications.

 No.993080>>993103

Java in what sense?

Java web applets? Horribly insecure, that's why it's been abandoned for browser-based stuff.

Java as a language, used for client-side stuff? I don't see what's wrong with it.

Every now and then, I hear people talking about issues relating to Java serialization and deserialization. But that's about it. It has a ton of users and a lot of money behind it, and it still gets frequent updates. That's more than you can say for toy languages that are only used by people in academia. The built-in Oracle stuff is pretty good.

The only real issue is with bad code, like copying and pasting bad shit from Stack Overflow, or using 3rd party libraries which may or may not be secure and might not have a bug ticketing system or auditing/fixes.

And of course, nothing can fix a bad programmer. Off-by-one errors, misconfigurations, hardcoded passwords, insufficient randomness for RNG, unvalidated user input, etc.


 No.993081

I memed my mom once


 No.993082>>993084 >>993292

It's a lot safer than C.


 No.993084>>993235

>>993082

Definitely. C doesn't care if something is initialized or not. Pointers and memory management might give you e-cred with boomer programmers, but at the end of the day, when you leave memory safety up to the programmer, that's not good. It should have built-in security to make things easier. Rust, for example, is slightly better.

But just like how we don't code directly in assembly anymore, it doesn't make sense to use C or C++ anymore unless you REALLY need that extra performance, which many things don't.


 No.993085>>993247

>>993077 (OP)

Best part of Java is the JVM, not the language itself.


 No.993086>>993103

The JVM has its exploits, and so does the Java STL. That said, /tech/ really is retarded about this stuff; some people here swear they won't install Java because it's insecure, but they don't realize that as long as you only run the programs you trust, there is absolutely nothing to fear. More or less like any program you run in your computer.


 No.993088

The picture in the OP is even funnier when you realise he was caught for using Freenet (a java application)


 No.993103>>993113

>>993086

>JVM has its exploits

The previous version (JRE 10) had 12 minor DoS exploits known. Compare that to the number of severity of exploits known for any version of Chrome or Firefox.

Security is a function of when those exploits become known, how good the company is about patching them quickly, and how good users are about keeping their software up to date. You can get owned pretty hard running any piece of software from 15 years ago.

>Java STL

There is no STL in Java. There is a built-in Collections API, and there are 3rd party replacement APIs which have had serialization exploits per >>993080


 No.993113>>993143 >>993292

>>993103

<You can get owned pretty hard running any piece of software from 15 years ago.

>what is openbsd


 No.993143>>993156

File (hide): c361fbe97213265⋯.png (44.65 KB, 1036x707, 148:101, ouch.PNG) (h) (u)

>>993113

>>993113

>>what is openbsd

A false sense of security for skids, LARPers, and freetards.


 No.993156>>993170 >>993261

>>993143

That's a pretty great track record they have.


 No.993170

>>993156

Sure, but the point stands. Even OpenBSD versions from 1 year ago can get you owned. There's also the uncounted zero-days that BSD's suffer from due to less eyes on the code in general.


 No.993193

vm != sandbox


 No.993197>>993239 >>993243

only literal street shitters who cannot find another job in their home country of pajeetistan program in Java.


 No.993235>>993292

>>993084

>But just like how we don't code directly in assembly anymore, it doesn't make sense to use C or C++ anymore unless you REALLY need that extra performance, which many things don't.

>You can't be trusted not to write shit code goy

>Buy the latest jewtel if you want extra performance don't write your software to be fast and efficient goy!

>Rust, for example, is slightly better

>it doesn't make sense to use C or C++ anymore

>Use this latest memelang goy!

kill yourself


 No.993239

>>993197

Are you retarded anon? If could get a job, you would know that you are more likely to work with existing code than to create something from scratch.


 No.993243

>>993197

t. only proficient in a meme language


 No.993247>>993279

>>993085

Because it was written in C.


 No.993261

>>993156

very few CVEs doesn't mean it's really secure

it just means no researchers are FINDING the vulnerabilities

more eyes = more exploits

for all you know, there could be something like shellshock for BSD in the sense that it's been there forever but nobody noticed it for years and years

more people auditing linux = more people finding bugs


 No.993279

>>993247

JVM developers wrote in C so that I don't have to. They are heroes.


 No.993292

>>993082

that's a very low bar, to be fair.

>>993113

>what is openbsd

an insecure meme

>>993235

way to miss the point


 No.993321

C code can have zero bugs (very hard, obviously; you need something like compcert or a good enough compiler, too).

Java code, on the other hand, will always rely on a shitty bloated JVM full of bugs developped by Oracle streetshitters.




[Return][Go to top][Catalog][Screencap][Nerve Center][Cancer][Update] ( Scroll to new posts) ( Auto) 5
22 replies | 1 images | Page ?
[Post a Reply]
[ / / / / / / / / / / / / / ] [ dir / arepa / general / komica / lewd / mde / nofap / vg / vichan ][ watchlist ]