Yahoo 5 Years Behind on Java Security

Catch up with NBC News Clone on today's hot topic: Wbna50785975 - Breaking News | NBC News Clone. Our editorial team reformatted this story for clarity and speed.

Keeping software up-to-date is one of the easiest and most effective ways to prevent computer infections from wreaking havoc on your system.

Keeping software up-to-date is one of the easiest and most effective ways to prevent computer infections from wreaking havoc on your system.

But for some reason, Yahoo is telling its small-business customers to use a version of Java that, by Internet standards, is pretty ancient.

Yahoo's misstep affects those who use SiteBuilder, a free tool for creating Web pages in Yahoo's hosting environment, reported independent security blogger Brian Krebs.

SiteBuilder requires the use of the Java software platform. But instead of serving up the latest, most secure version, users are asked to use Java 6 Update 7, which hasn't been current since 2008.

Yahoo's own page promoting SiteBuilder copyrights all material in 2007, and the SiteBuilder download page recommends Windows XP as the optimal operating system. (SiteBuilder will also run on Windows 2000.)

Whether Java 6.7 actually is required to run SiteBuilder is still unclear. A commenter on Krebs' site said SiteBuilder would work with newer versions of Java 6, but not with Java 7, introduced in mid-2011.

We tried installing SiteBuilder, but were advised that "Yahoo! SiteBuilder requires a different version of the Java Runtime Environment than the one found on your computer."

What is certain is that users operating older versions of Java are at risk to hundreds of exploits that could lead to computer damage, data theft, identity theft and even stolen funds.

As Krebs notes, outdated versions of Java are the largest point of entry for malware attacks.

The latest versions of Java had numerous security problems just last month, and many security experts recommend disabling Java entirely in Web browsers.

[ Why and How to Disable Java on Your Computer ]

Combined with an endorsement from Internet behemoth Yahoo, the use of outdated Java code creates a cocktail of confusion and compromised security that disproportionately affects small businesses, many of whom are ill-prepared to handle a malware or hacker attack.

Earlier this month, Yahoo was found to have failed to patch its implementation of WordPress on a developer page, allowing spammers to hijack Yahoo Mail accounts.

Last summer, hackers broke into Yahoo's servers and made off with 450,000 usernames, email addresses and unencrypted passwords corresponding to Yahoo! Voices accounts.

An email seeking comment from Yahoo was not immediately returned.

×
AdBlock Detected!
Please disable it to support our content.

Related Articles

Donald Trump Presidency Updates - Politics and Government | NBC News Clone | Inflation Rates 2025 Analysis - Business and Economy | NBC News Clone | Latest Vaccine Developments - Health and Medicine | NBC News Clone | Ukraine Russia Conflict Updates - World News | NBC News Clone | Openai Chatgpt News - Technology and Innovation | NBC News Clone | 2024 Paris Games Highlights - Sports and Recreation | NBC News Clone | Extreme Weather Events - Weather and Climate | NBC News Clone | Hollywood Updates - Entertainment and Celebrity | NBC News Clone | Government Transparency - Investigations and Analysis | NBC News Clone | Community Stories - Local News and Communities | NBC News Clone