From: (Bill Frantz)
To: Andrew Loewenstern <
Message Hash: 23fb6349a048bc3e4084925b70b69a2913e342b486934487b007eca18fdb0f36
Message ID: <>
Reply To: N/A
UTC Datetime: 1995-12-19 20:22:25 UTC
Raw Date: Tue, 19 Dec 95 12:22:25 PST
From: (Bill Frantz)
Date: Tue, 19 Dec 95 12:22:25 PST
To: Andrew Loewenstern <
Subject: Re: Java and timing info - second attempt
Message-ID: <>
MIME-Version: 1.0
Content-Type: text/plain
>Jim Miller ( writes:
>Of course it would be a lot easier for the applet to just try to read the
>secret key file, encrypt it with an embedded public key, and post it to
If I understand Java security correctly, the applet can just send data back
to the server it was loaded from, but can't read random files on the
machine it runs on (even if the user running it can read them). Java is
beginning to become cluefull about the idea that a program is not the same
as the person running it, and should not have the same privileges. In this
area, most OSs (inluding Unix) are totally clueless, which is why the
Orange Book has mandatory security requirements at the "B" and above
Bill Frantz Periwinkle -- Computer Consulting
(408)356-8506 16345 Englewood Ave. Los Gatos, CA 95032, USA
Return to December 1995
Return to “ (Bill Frantz)”
1995-12-19 (Tue, 19 Dec 95 12:22:25 PST) - Re: Java and timing info - second attempt - (Bill Frantz)