PING: RFR: JDK-4347142: Need method to set Password protection to Zip entries

KUBOTA Yuji kubota.yuji at gmail.com
Mon Apr 25 08:49:57 UTC 2016


2016-04-20 7:57 GMT+09:00  <mark.reinhold at oracle.com>:
> I have to agree.  I don't think it makes sense to add a known-vulnerable
> encryption algorithm to the JDK.  It might work perfectly well for one
> use case but it will eventually be used by someone who doesn't take the
> time to understand it, assumes that it provides strong encryption when
> it doesn't, gets burned, and then blames Java.

Yes, Mark. We never hope to make OpenJDK be blamed with our proposal.

Mark, I am glad if you are interested in this proposal if using any strong
encryption algorithm like Sherman's implementation (AES encryption).
If so, we hope to continue discussion the better way to fill our needs
and given comments for improving OpenJDK.

Thanks,
Yuji



More information about the core-libs-dev mailing list