A Java geek
  • Me
  • Books
  • Speaking
  • Mentions
  • Focus
  • Newsletters

jgdms

A collection of 2 posts
Security Baked Into the JVM
Technical

Security Baked Into the JVM

The more distributed a system, the harder it is to secure. Code crosses JVM boundaries. Objects are serialized across trust boundaries. Third-party proxies run inside your process. The usual answer is a network firewall. It helps, but it operates at the wrong level. Java 17 deprecated the SecurityManager, Java 24 put the final nail in its coffin. Most developers didn’t notice.

Jun 28, 2026
Security Baked Into the JVM: why fork Apache River and OpenJDK?
Technical

Security Baked Into the JVM: why fork Apache River and OpenJDK?

The more distributed a system, the harder it is to secure. Code crosses JVM boundaries. Objects are serialized across trust boundaries. Third-party proxies run inside your process. The usual answer is a network firewall. It helps, but it operates at the wrong level. Java 17 deprecated the SecurityManager, Java 24 put the final nail in its coffin. Most developers didn’t notice.

Jun 28, 2026
A Java geek © 2008-2026
v. 24738e15725f7adb794b9a956773d791fdbc9c2b/15071185139
Latest Posts