Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Oracle's Java security head: We will 'fix Java,' communicate better

Oracle is planning to step up its community outreach efforts around the programming language

Oracle's head of Java security is promising the vendor will "fix" issues with the widely used programming language, as well as improve its outreach efforts to community members, following a spate of high-profile vulnerabilities.

"The plan for Java security is really simple," said Java security lead Milton Smith during a conference call this week with Java user group leaders. "It's to get Java fixed up, number one, and then number two, to communicate our efforts widely. We really can't have one without the other. No amount of talking or smoothing over is going to make anybody happy. We have to fix Java."

Oracle has been coming under fire recently from experts over what they say is an inability to properly patch vulnerabilities in Java.

Recently, the U.S. Department of Homeland Security even urged users to disable Java in their browsers. Most Java vulnerabilities of late have been at the browser level, according to Smith. "That's really the biggest target now."

Oracle, which gained control of Java through the acquisition of Sun Microsystems, has often been criticized for being tight-lipped in its public communications. But that label won't be fairly applied to the company's Java team moving forward, Smith said during the call, a recording of which was made publicly available through Oracle's website on Friday.

Smith and his peers "have a lot of things that we're looking at" with respect to communication, he said. One particular goal is to make sure Oracle is reaching all audiences, from consumer users to IT professionals running data centers to engineers, he said.

Exactly how this will be done hasn't been decided as of yet, but it could include more speeches at tech conferences as well as talking to the press, according to Smith.

Another possibility would be for Oracle to provide updates on security to Java user group leaders, who would then be able to share information with their members, he said.

Smith repeatedly underscored the importance of outreach to Oracle's Java security efforts.

For example, Oracle recently made "very significant" security improvements to Java, such as to prevent silent exploits, he said.

"But people don't understand those features yet," he said. "They're still pretty new."

Chris Kanaracus covers enterprise software and general technology breaking news for The IDG News Service. Chris' email address is Chris_Kanaracus@idg.com

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: CERT, IDG, Oracle, Sun Microsystems
Comments are now closed.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Languages and standards, application development, Sun Microsystems, security, software, Exploits / vulnerabilities, Oracle
Latest Blog Posts
Whitepapers
  • Why you should be re-thinking your approach to data protection
    Organisations of all shapes and sizes need a new approach to data protection that addresses the challenges of data growth, but IT budgets are not keeping pace with the escalating costs of supporting storage requirements. This whitepaper explores how securing and retrieving organisational data will need to be done more efficiently.
    Learn more »
  • Transform IT, Transform the Enterprise
    Existing IT operational models and an ageing infrastructure are CIOs back from their full potential. This paper reveals the three IT imperatives for a CIO-led transformation, and details how CIOs are adopting strategies to change IT and assert their organisations as business leaders and innovators.
    Learn more »
  • Top 20 Critical Security Controls - Compliance Guide
    Simply being compliant is not enough to mitigate attacks and protect critical information. Organizations can reduce chances of compromise by shifting away from a compliance-driven approach. This guide provides the Top 20 Critical Security Controls (CSCs) developed by the SANS Institute to address the need for a risk-based approach to security.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Salary Calculator

Supplied by

View the full Peoplebank ICT Salary & Employment Index

Recent comments