Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

This site will have limited functionality while we undergo maintenance to improve your experience. If an article doesn't solve your issue and you want to ask a question, we have our support community waiting to help you at @FirefoxSupport on Twitter and/r/firefox on Reddit.

Search Support

Avoid support scams. We will never ask you to call or text a phone number or share personal information. Please report suspicious activity using the “Report Abuse” option.

Learn More

Why is java constantly considered as unsafe?

  • 8 replies
  • 17 have this problem
  • 3 views
  • Last reply by Ed

more options

Each time there is an update to Java, when I install it or some time shortly thereafter, it is marked as unsafe in Firefox.

Are the Java developers working with the Firefox team to correct issues or are they purposely ignoring suggestions?

Each time there is an update to Java, when I install it or some time shortly thereafter, it is marked as unsafe in Firefox. Are the Java developers working with the Firefox team to correct issues or are they purposely ignoring suggestions?

All Replies (8)

more options

Hello,

I believe all versions of Java are now considered unsafe simply because in the past they have proved to be unsafe.

I think the rationale is: given the number of security vulnerabilities in previous versions of Java it is safer to assume that new versions will be vulnerable even if those vulnerabilities are not yet widely known.

See here for more information:

You can see the complete list of blocked add-ons here:

https://addons.mozilla.org/en-US/firefox/blocked/

I hope this helps.

Modified by Ed

more options

Do we ask the Oracle Corporation to fix Java's issues? Or do we ask developers to stop using it?

more options

I think Mozilla are hoping that developers will start to use HTML5 instead of Java (and indeed all browser plugins) because plugins are potentially vulnerable and also often cause crashes / other problems in the browser.

more options

Here's an interesting article on the matter

http://threatpost.com/javas-losing-security-legacy

more options

Thanks. It actually sounds even worse than I'd imagined.

more options

Google Java security issues. There's a lot of concern about Java.

I do believe that Oracle is hammering its own nails into the Java coffin.

EG Apple has banned Java on it's Macs.

more options

I have an interesting situation. All of my PCs are with FF24 and Java 7u45 installed WinXp sp3. Three PCs have Java set to "always ask" with the warning about safety.

One PC has Java plugin and Java Deployment Tookkit are set to "always activate" in the add-ons manager settings. The only options for both are "always activate" and "never activate".

How do I set this to the proper setting of "always ask"?

I've dug around in about:config but cannot see anything obvious.

more options

I'm not too sure about that I'm afraid.

Since this is a slightly different question to the original would you mind starting a new thread and another support person will be along to answer.

Thanks.