...
| Wiki Markup |
|---|
\[[JLS 05|AA. Java References#JLS 05]\] [Section 6.6, Access Control|http://java.sun.com/docs/books/jls/third_edition/html/names.html#6.6] \[[SCG 07|AA. Java References#SCG 07]\] Guideline 1-1 Limit the accessibility of classes, interfaces, methods, and fields \[[Campione 96|AA. Java References#Campione 96]\] [Access Control|http://www.telecom.ntua.gr/HTML.Tutorials/java/javaOO/accesscontrol.html] \[[McGraw 00|AA. Java References#McGraw 00]\] Chapter 3, Java Language Security Constructs \[[Bloch 08|AA. Java References#Bloch 08]\] Item 13: Minimize the accessibility of classes and members |
...
SEC19SEC00-J. Do not rely on the default automatic signature verification provided by URLClassLoader and java.util.jarFollow the principle of least privilege 02. Platform Security (SEC) SEC16SEC02-J. Sign and seal sensitive objects before transitGuard doPrivileged blocks against untrusted invocations