• Critical cryptography issue in Java 15 and higher

    Home » Forums » Cyber Security Information and Advisories » Cyber Security for Business users » Critical cryptography issue in Java 15 and higher

    Author
    Topic
    #2440874

    Just came across this article. Sounds like a big one if you have Java 15 or higher running on your server. An April patch is available from Oracle. Doesn’t apply to me but seem like it could be a significant issue for some.

    https://arstechnica.com/information-technology/2022/04/major-crypto-blunder-in-java-enables-psychic-paper-forgeries/?comments=1

    Win10 Pro x64 22H2, Win10 Home 22H2, Linux Mint + a cat with 'tortitude'.

    1 user thanked author for this post.
    Viewing 0 reply threads
    Author
    Replies
    • #2440912

      It seems the issue doesn’t allow bad actors easy access via forgery, it fails a check for a forgery.
      You won’t suddenly see compromised systems because creating the forgery in the first place is extremely difficult. (At least that is how I read the article and comments.)

      cheers, Paul

    Viewing 0 reply threads
    Reply To: Critical cryptography issue in Java 15 and higher

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: