-
Notifications
You must be signed in to change notification settings - Fork 5
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Potential security issue with Pledge's reliance on Java 6 #17
Comments
Oracle's support roadmap for Java SE can be found here: Free, public support for Java 7 ends after April 2015. If that schedule is adhered to, public security updates (i.e. those available without a paid support plan) will only be available for Java 8 after that date, through March 2017. Neither Java 6 nor Java 7 will receive any public security updates, going forward. So if McAfee currently - or anytime within the next two years - provides a Pledge update based on a newer Java release, as of May 2015 that update would need to be based on Java 8, to conform to the campus's MSSND requirements. |
Thanks for making a note of this here, @aronr. It's good to at least know y'all are thinking about this... |
Thanks for noting this issue, @davclark. Two quick thoughts:
|
Would this be a good time to segue into using Yubikey OTP? |
If you'd like to suggest that the folks investigating a Pledge replacement look at Yubikey, you might try writing the general inquiry address here: https://security.berkeley.edu/about/contact-us Unfortunately, I don't recall hearing who's on that team; otherwise, this would be a more direct referral. |
At least under Mac OS X - I'm not sure whether this is the case on other OSes - the Pledge one time password app requires the installation of Java 6.
This might potentially be problematic from a security standpoint. That's because the campus's Minimum Security Standards for Networked Devices (MSSND) (https://security.berkeley.edu/mssnd#software-patch-updates) state that:
And Oracle will not be making such patches available for Java 6 (https://www.java.com/en/download/faq/java_6.xml):
The text was updated successfully, but these errors were encountered: