Consumer Law LibrarySearchBy decadeBy respondentBy topicBy outcomeDataAbout

Oracle Corporation

Volume 161 · 161 F.T.C. 382

Citation
161 F.T.C. 382
Docket
C-4571
Complaint
2016-03-28
Decision
2016-03-28
Document type
consent order
Case type
consumer protection
Statutes
FTC Act (section 5)
Industry
software
Outcome
consent order entered
Relief
cease_and_desist; affirmative_disclosure; notice_to_customers; recordkeeping; compliance_reporting
Order term (years)
5
Commission counsel
The respondent, its attorney, and counsel
Source
Original volume PDF
Original PDF
This decision as a PDF

deceptive advertisingprivacy data securityonline internet

Cite this decision

Oracle Corporation, 161 F.T.C. 382 (2016). Consumer Law Library, https://consumerlawlibrary.org/decisions/v161-0008

Report an error in this record (decision id v161-0008)

Order status: active_until:2036-03-28. Sunset may be extended by the latest qualifying federal-court complaint alleging an order violation; complaints, dismissal/appeal outcomes, and respondent-specific extensions are not fully tracked.

Cited by 0 later FTC decisions

Cites

Text (OCR of the scan at left; may contain errors)

IN THE MATTER OF ORACLE CORPORATION CONSENT ORDER, ETC. IN REGARD TO ALLEGED VIOLATIONS OF SECTION 5 OF THE FEDERAL TRADE COMMISSION ACT Docket No. C-4571; File No. 132 3115 Complaint, March 28, 2016 – Decision, March 28, 2016 This consent order addresses Oracle Corporation’s failure to inform consumers that Java SE updates automatically removed only the most recent prior iteration of Java SE installed on the consumer’s computer, even if the consumer had multiple iterations of Java SE installed, and that the update would not remove any iteration released prior to Java SE iteration 6 update 10. The complaint alleges that Oracle violated Section 5(a) of the FTC Act by failing to make such disclosure and left some consumers vulnerable to a serious, well-known, and reasonably foreseeable security risk that attackers would target these computers through exploit kits, resulting in the theft of personal information. The consent order prohibits Oracle from misrepresenting (1) the privacy or security of the covered software on a consumer’s computer, including but not limited to the effect on privacy or security of any installation or update of the covered software; and (2) how to uninstall older iterations of the covered software.

Participants For the Commission: Andrea V. Arias and Jacqueline K. Connor.

For the Respondent: Jonathan Cedarbaum, D. Reed Freeman, Jr., Jamie Gorelick, Quentin Palfrey, and Benjamin Powell, Wilmer Cutler Pickering Hale and Dorr LLP. COMPLAINT The Federal Trade Commission, having reason to believe that Oracle Corporation has violated the provisions of the Federal Trade Commission Act, and it appearing to the Commission that this proceeding is in the public interest, alleges: 1. Respondent Oracle Corporation (“Oracle”) is a Delaware corporation with its principal office or place of business at 500 Oracle Parkway, Redwood City, California 94065. ORACLE CORPORATION 383 Complaint 2. The acts and practices of Oracle as alleged in this complaint have been in or affecting commerce, as “commerce” is defined in Section 4 of the Federal Trade Commission Act. ORACLE’S BUSINESS PRACTICES 3. Oracle is a software company that, among other things, develops the Java computing platform (“Java”), which is used to power many types of applications. Some of the more common Java applications allow consumers to play online games, chat with people online, calculate mortgage interest, and view images in 3D. Oracle acquired Java on January 27, 2010, as part of its purchase of Sun Microsystems, Inc.

4. Java comes in multiple editions for both enterprises and consumers. Consumers primarily use the Java Platform, Standard Edition (“Java SE”), which has been installed on more than 850 million personal computers.

5. Java SE includes various components that enable consumers to run Java applications on websites. Many computers today are sold with Java SE pre-installed. Alternatively, a consumer may go to the Java.com website and download Java SE. JAVA SE SECURITY 6. Since at least 2010, a principal security challenge facing Java SE users was that attackers closely monitored Oracle’s release of updates to its software to identify vulnerabilities in Java SE’s previous iterations. At the same time, attackers often developed malware designed to exploit vulnerabilities in previous iterations of Java SE installed on users’ computers (“exploit kits”).

7. In late 2010, Oracle acknowledged that exploit kits for at least 44 Java SE vulnerabilities were publicly available. For example, attackers have used known exploit kits targeting Java SE vulnerabilities to install key loggers that would capture consumers’ usernames and passwords, which could be used to log into a consumer’s Paypal, bank, and credit card accounts. VOLUME 161 Complaint 8. Other Java exploit kits could result in the unauthorized acquisition and transmission of sensitive personal information for the purpose of targeted spear-phishing campaigns. 9. Consumers with insecure iterations of Java SE on their computers were vulnerable to exploit kits targeting Java SE vulnerabilities while browsing infected websites or clicking on nefarious links.

THE JAVA SE UPDATE PROCESS 10. Oracle released Java SE version 6 update 19 in March 2010. Oracle released several subsequent updates for Java SE version 6 through April 16, 2013.

11. When an update was available, consumers would typically receive a prompt to update their Java SE. When the consumer proceeded to install the update, the consumer would encounter a series of installation screens, which stated that “Java provides safe and secure access to the world of amazing Java content,” and that Java SE updates and a consumer’s “system” (see, e.g., Exhibit B) would have “the latest . . . security improvements.” (See, e.g., Exhibits A–B).

12. In its Java SE “update” process, however, Oracle did not inform consumers that Java SE updates automatically removed only the most recent prior iteration of Java SE installed on the consumer’s computer, even if the consumer had multiple iterations of Java SE installed. Updates would also not remove any iteration released prior to Java SE version 6 update 10. Therefore, after the update process, consumers could still have additional older, insecure iterations of Java SE on their computers.

13. Beginning in October 2010, in a separate FAQ page of Oracle’s website, Oracle explained that because, in the past, consumers would install “each Java update . . . in separate directories on [their] system,” consumers “may have installed multiple versions of Java.” (See, e.g., Exhibits C–D). In addition, Oracle explained to consumers that additional “old and unsupported versions of Java on your system present[] a serious ORACLE CORPORATION 385 Complaint security risk” and that “[r]emoving older versions of Java from your system ensures that Java applications will run with the most up-to-date security.” (See, e.g., Exhibits C–D). However, for any consumers sophisticated enough to find this page on their own, it did not inform them that the Java SE update process did not automatically remove all older, insecure iterations of the software. In addition, Oracle failed to disclose this information or link to the relevant FAQ page during the Java SE update process. 14. Oracle was aware, no later than 2011, that its Java SE update process was not sufficient to ensure that consumers could always remove older, insecure iterations of Java SE and, therefore, that Java SE on their systems would have the latest security improvements. In internal documentation, Oracle admitted that “Java malware propagation [was] successful even though [attackers are] exploiting fixed bugs” and that the “Java update mechanism is not aggressive enough or simply not working.” Nevertheless, Oracle did not inform consumers during the update process that updating Java SE did not remove all older iterations of Java SE on their computers, and therefore, that their computers could remain susceptible to exploit kits targeting Java SE vulnerabilities.

15. In July 2011, Oracle released Java SE version 7. Oracle then began to periodically release updates for Java SE version 7. In December 2012, Oracle began to prompt certain users to update from Java SE version 6 to Java SE version 7. These updates continued to remove only the most recent prior iteration of Java SE.

16. In March 2014, Oracle released Java SE version 8. Oracle then began to periodically release updates for Java SE version 8. These updates continued to remove only the most recent prior iteration of Java SE until August 2014. IMPACT ON CONSUMERS 17. In numerous instances, Java SE’s update and uninstallation issues made it likely that consumers unknowingly would have older, insecure iterations of Java SE installed. VOLUME 161 Complaint 18. Attackers used exploit kits to specifically target vulnerabilities in older, insecure iterations of Java SE installed on consumers’ computers. As described in Paragraph 7, attackers used these exploit kits to obtain consumers’ personal information. 19. By failing to inform consumers that the Java SE update process did not remove all prior iterations of the software, Oracle left some consumers vulnerable to a serious, well-known, and reasonably foreseeable security risk that attackers would target these computers through exploit kits, resulting in the theft of personal information, as described above. VIOLATION OF THE FTC ACT Failure to Disclose 20. As described in Paragraph 11, Oracle represented, directly or indirectly, expressly or by implication, that by updating Java SE, Java users would ensure that Java SE on their computers had the latest security improvements. 21. Oracle failed to disclose, or failed to disclose adequately, that, in numerous instances, updating Java SE would not delete or replace all older iterations of Java SE on a consumer’s computer, and as a result, a consumer’s computer could still have iterations of Java SE installed that are vulnerable to security risks. This fact would be material to consumers’ decision whether to take further action after “updating” Java SE to protect their computers. 22. Oracle’s failure to disclose, or disclose adequately, the material information described in Paragraph 21, in light of the representation set forth in Paragraph 20, is a deceptive act or practice.

23. The acts and practices of Oracle as alleged in this complaint constitute unfair or deceptive acts or practices in or affecting commerce in violation of Section 5(a) of the Federal Trade Commission Act, 15 U.S.C. § 45(a). ORACLE CORPORATION 387 Complaint THEREFORE, the Federal Trade Commission this twentyeighth day of March, 2016, has issued this complaint against Oracle.

By the Commission.

Exhibit A VOLUME 161 Complaint Exhibit B Exhibit C ORACLE CORPORATION 389 Complaint Exhibit C Why should I remove older versions of Java jrom my system?, JAVA.COM (Oct. 31, 2010), http://web.archive.org/web/2012062608063 0/http:/www.java.conven/download/faq/temove olderversions.xml (accessed by searching for Java.com in the Internet Archive index). HELP RESOURCES e Installing Java a Remove Older Versions ail « EXO: General Questions.

a FAG Mobile Java @ cuppod Options.

Find expert =<) helpon Java “= installation Java" and setup Get Help Now! ae if Sole! Ln guage Why should | remove older versions of Java from my =istle Version system? This atticle applies to:

« Platfornish All Platiorne « Java vorsion(s): AILJRE Vorsions The lates! version of Jara s always the recormended version agit contains upcates and innprovernants to previous versions. You can confirm that vou have the lasted version ty visiting the Java Veddfication fade.

Over tire, you ray have installed rrultiple versione of Javato run available Java content. In the past, éach Java Lodate was installed in separate directories on your systern. However, Java updates ere riow® Installed fi @ single directary.

Should | remove older versions of Java? ‘We highly recommend users to remove all older versions of Java from your system. Keeping old and unsupported versions of Java on your system presents a serious security isk. Removing older versions of Java from your system enguires that Java apolcations will run with the most up-to-date security end performance improvements on your sv stem. How can i remove older versions af Java? ‘Tou Cen safely remove olcerversions of Java from your system by following the instructions on Java AUninstallstion instructions tor Windows page. Do | need older versions of Java? The lates! avaibbe version is always compatible with the oltarversione, However, some Java applications (or applets) Cen indicate that they are dependent on @ particular version, and may not run if WOU do not have that version inctalled. [fan application orweb paqe vou access requires an older version of Java, vou should report this to the providerfdeveloper and request that they undete the application to be compatible with all Java versions, Woy | Partner with Ws | Developers.

VOLUME 161 Complaint Exhibit D ORACLE CORPORATION 391 Decision and Order DECISION AND ORDER The Federal Trade Commission (“Commission” or “FTC”), having initiated an investigation of certain acts and practices of the respondent named in the caption hereof, and respondent having been furnished thereafter with a copy of a draft complaint that the Bureau of Consumer Protection proposed to present to the Commission for its consideration and which, if issued by the Commission, would charge respondent with a violation of the Federal Trade Commission Act (“FTC Act”), 15 U.S.C. § 45 et seq.;

The respondent, its attorney, and counsel for the Commission having thereafter executed an Agreement Containing Consent Order (“Consent Agreement”), which includes: a statement by respondent that it neither admits nor denies any of the allegations in the draft complaint, except as specifically stated in the Consent Agreement, and, only for purposes of this action, admits the facts necessary to establish jurisdiction; and waivers and other provisions as required by the Commission’s Rules; and The Commission having thereafter considered the matter and having determined that it had reason to believe that the respondent violated the FTC Act, and that a complaint should issue stating its charges in that respect, and having thereupon accepted the executed Consent Agreement and placed such agreement on the public record for a period of thirty (30) days for the receipt and consideration of public comments, and having duly considered the comments received from interested persons pursuant to Commission Rule 2.34, 16 C.F.R. § 2.34, now in further conformity with the procedure prescribed by Commission Rule 2.34, the Commission hereby issues its complaint, makes the following jurisdictional findings, and enters the following Order: 1. Respondent Oracle Corporation (“Oracle”) is a Delaware corporation with its principal office or place of business at 500 Oracle Parkway, Redwood City, California 94065.

VOLUME 161 Decision and Order 2. The Federal Trade Commission has jurisdiction of the subject matter of this proceeding and of the respondent, and the proceeding is in the public interest. ORDER DEFINITIONS For purposes of this order, the following definitions shall apply:

A. “Affected Consumers” shall mean persons who, prior to the date of issuance of this order, downloaded, installed, or updated Java SE.

B. “Clear(ly) and conspicuous(ly)” means that a required disclosure is difficult to miss (i.e., easily noticeable) and easily understandable by ordinary consumers, including in all of the following ways: 1. In any communication that is solely visual or solely audible, the disclosure must be made through the same means through which the communication is presented. In any communication made through both visual and audible means, such as a television advertisement, the disclosure must be presented simultaneously in both the visual and audible portions of the communication, even if the representation requiring the disclosure is made in only one means. 2. A visual disclosure, by its size, contrast, location, the length of time it appears, and other characteristics, must stand out from any accompanying text or other visual elements so that it is easily noticed, read, and understood. 3. An audible disclosure, including by telephone or streaming video, must be delivered in a volume, speed, and cadence sufficient for ordinary consumers to easily hear and understand it. ORACLE CORPORATION 393 Decision and Order 4. In any communication using an interactive electronic medium, such as the Internet or software, the disclosure must be unavoidable. 5. The disclosure must use diction and syntax understandable to ordinary consumers.

6. The disclosure must comply with these requirements in each medium through which it is received, including all electronic devices and faceto-face communications.

7. The disclosure must not be contradicted or mitigated by, or inconsistent with, anything else in the communication.

C. “Commerce” shall mean as defined in Section 4 of the Federal Trade Commission Act, 15 U.S.C. § 44. D. “Covered Software” shall mean Oracle’s Java SE, and any other software offered by Oracle directly to consumers to run programs on their computers or applications within a browser. Covered Software does not include software offered exclusively for developers or enterprises.

E. “Java SE” shall mean Oracle’s Java Platform, Standard Edition software, the Java Runtime Environment (“JRE”), or the Java plug-in offered by Oracle directly to consumers using Windows-based computers. Java SE does not include software offered exclusively for developers or enterprises.

F. “Iterations” shall mean all releases, other than test releases, that have ever been supported by Oracle. G. “Iteration(s) Released Within the Last Quarter” shall mean, at any given point in time, the iteration(s) of Java SE released within the preceding three months. VOLUME 161 Decision and Order H. Unless otherwise specified, “respondent” shall mean Oracle Corporation, and its successors and assigns. I.

IT IS ORDERED that respondent and its officers, agents, representatives, and employees, whether acting directly or indirectly, in or affecting commerce, must not misrepresent: (1) the privacy or security of the Covered Software on a consumer’s computer, including but not limited to the effect on privacy or security of any installation or update of the Covered Software; or (2) how to uninstall older Iterations of the Covered Software. II.

IT IS FURTHER ORDERED that respondent and its officers, agents, representatives, and employees, whether acting directly or indirectly, must ensure that during any installation or update to any Iteration of Java SE released after the date of service of this order, respondent:

A. Clearly and Conspicuously discloses to the consumer all Iterations of Java SE 1.4.2 or later, other than any Iteration(s) Released Within the Last Quarter, currently installed on the consumer’s computer; B. Clearly and Conspicuously explains that there may be risks to the security of the consumer’s computer if the consumer chooses not to remove any Iterations of Java SE older than the Iteration(s) Released Within The Last Quarter currently installed on the consumer’s computer; and C. Clearly and Conspicuously discloses which Iterations of Java SE 1.4.2 or later, other than any Iteration(s) Released Within the Last Quarter, that remain installed following installation or update of Java SE, and Clearly and Conspicuously provides instructions describing how consumers can effectively uninstall these Iterations.

ORACLE CORPORATION 395 Decision and Order III.

IT IS FURTHER ORDERED that respondent and its officers, agents, representatives, and employees, whether acting directly or indirectly, must notify Affected Consumers, Clearly and Conspicuously that in some instances, they may have older, insecure Iterations of Java SE on their computers. Such notification shall include effective, Clear and Conspicuous instructions on how to remove these older Iterations. Notification shall include, but not be limited to, each of the following means: A. Posting of a Clear and Conspicuous hyperlink on the home page of respondent’s primary, consumer-facing website for Java SE. Such hyperlink must read “IMPORTANT INFORMATION REGARDING THE SECURITY OF JAVA SE.” The hyperlink should connect to a sample of the letter shown in Attachment A. This hyperlink and sample letter must be posted no later than ten (10) days after the date of service of the order and for at least two years following posting; B. On or before ten (10) days after the date of service of this order, provide Clear and Conspicuous notice to Affected Consumers regarding the contents of Attachment A. Respondent shall inform Affected Consumers by:

1. Contacting Avast Software, AVG Technologies, ESET North America, Avira, Inc., McAfee, Inc., Symantec Corporation, Trend Micro, Inc., and Mozilla Corporation to request that these entities publish this notice in their security bulletins; 2. Sending a Twitter notification via respondent’s primary Twitter account for Java SE, the text of which shall read “IMPORTANT INFORMATION REGARDING THE SECURITY OF JAVA SE,”

and link to a sample of the letter shown in Attachment A; and VOLUME 161 Decision and Order 3. Sending a Facebook notification via respondent’s primary Facebook account for Java SE, the text of which shall read “IMPORTANT INFORMATION REGARDING THE SECURITY OF JAVA SE,”

and link to a sample of the letter shown in Attachment A; and C. On or before ten (10) days after the date of service of this order and for three (3) years thereafter, providing prompt and free help to Affected Consumers through: 1. An uninstall tool that allows Affected Consumers to uninstall Iterations of Java SE, 1.4.2 or later; 2. A page on respondent’s primary, consumer-facing website for Java SE that Clearly and Conspicuously explains how to uninstall Iterations of Java SE, and provides a link to the uninstall tool referenced in Part III.C.1; and 3. A Clear and Conspicuous electronic form, specific to update and uninstall issues, available on respondent’s primary, consumer-facing website for Java SE. Respondent shall answer within a reasonable time, by email, consumers who fill out such form.

IV.

IT IS FURTHER ORDERED that respondent shall maintain and, upon request, make available to the Federal Trade Commission for inspection and copying, for a period of five (5) years from the date of preparation or dissemination, whichever is later, a print or electronic copy of each document relating to compliance with this order, including but not limited to: A. All advertisements, promotional materials, installation and user guides, websites, and installation screens containing any representations covered by this order, as well as all materials used or relied upon in making or disseminating the representation;

ORACLE CORPORATION 397 Decision and Order B. All release notes for all Java SE Iterations, including the Iterations’ release dates; and C. Any documents, whether prepared by or on behalf of respondent, that contradict, qualify, or call into question respondent’s compliance with this order. V.

IT IS FURTHER ORDERED that respondent, and its successors and assigns, must deliver a copy of this order to all current and future subsidiaries, current and future principals, officers, directors, and managers, employees, agents, and representatives having managerial or supervisory responsibilities relating to Parts I - III of this order. Respondent must deliver this order to such current subsidiaries and personnel within thirty (30) days after service of this order, and to such future subsidiaries and personnel within thirty (30) days after the person assumes such position or responsibilities. For any business entity resulting from any change in structure set forth in Part VI, delivery must be at least ten (10) days prior to the change in structure. Respondent must secure a signed and dated statement acknowledging receipt of this order, within thirty (30) days of delivery, from all persons receiving a copy of the order pursuant to this section. VI.

IT IS FURTHER ORDERED that respondent, and its successors and assigns, shall notify the Commission at least thirty (30) days prior to any change in the corporation(s) that may affect compliance obligations arising under this order, including, but not limited to, dissolution, assignment, sale, merger, or other action that would result in the emergence of a successor company; the creation or dissolution of a subsidiary, parent, or affiliate that engages in any acts or practices subject to this order; the proposed filing of a bankruptcy petition; or a change in the corporate name or address. Provided, however, that, with respect to any proposed change in the corporation(s) about which respondent learns less than thirty (30) days prior to the date such action is to take place, respondent shall notify the Commission as soon as is practicable after obtaining such knowledge. Unless otherwise directed by a VOLUME 161 Decision and Order representative of the Commission, all notices required by this Part shall be sent by overnight courier (not the U.S. Postal Service) to the Associate Director of Enforcement, Bureau of Consumer Protection, Federal Trade Commission, 600 Pennsylvania Avenue NW, Washington, D.C. 20580, with the subject line In the Matter of Oracle Corporation, FTC File No. 132 3115. Provided, however, that in lieu of overnight courier, notices may be sent by first-class mail, but only if an electronic version of any such notice is contemporaneously sent to the Commission at [email protected].

VII.

IT IS FURTHER ORDERED that respondent, and its successors and assigns, within ninety (90) days after the date of service of this order, shall file with the Commission a true and accurate report, in writing, setting forth in detail the manner and form of its compliance with this order. Within ten (10) days of receipt of written notice from a representative of the Commission, it shall submit additional true and accurate written reports. VIII.

This order will terminate on March 28, 2036, or twenty (20) years from the most recent date that the United States or the Federal Trade Commission files a complaint (with or without an accompanying consent decree) in federal court alleging any violation of the order, whichever comes later; provided, however, that the filing of such a complaint will not affect the duration of: A. Any Part in this order that terminates in less than twenty (20) years;

B. This order’s application to any respondent that is not named as a defendant in such complaint; and C. This order if such complaint is filed after the order has terminated pursuant to this Part.

Provided, further, that if such complaint is dismissed or a federal court rules that respondent did not violate any provision of the ORACLE CORPORATION 399 Decision and Order order, and the dismissal or ruling is either not appealed or upheld on appeal, then the order will terminate according to this Part as though the complaint had never been filed, except that the order will not terminate between the date such complaint is filed and the later of the deadline for appealing such dismissal or ruling and the date such dismissal or ruling is upheld on appeal. By the Commission.

VOLUME 161 Decision and Order Attachment A ORACLE CORPORATION 401 Analysis to Aid Public Comment ANALYSIS OF CONSENT ORDER TO AID PUBLIC COMMENT The Federal Trade Commission has accepted, subject to final approval, an agreement containing a consent order applicable to Oracle Corporation (“Oracle”).

The proposed consent order has been placed on the public record for thirty (30) days for receipt of comments by interested persons. Comments received during this period will become part of the public record. After thirty (30) days, the Commission will again review the agreement and the comments received, and will decide whether it should withdraw from the agreement and take appropriate action or make final the agreement’s proposed order. Oracle is a Delaware corporation that, among other things, develops the Java computing platform, which is used to power applications that, for example, allow consumers to play online games, chat with people online, calculate mortgage interest, and view images in 3D. Consumers primarily use the Java Platform, Standard Edition (“Java SE”). When an update to Java SE was available, a consumer would typically receive a prompt to update the software. When the consumer proceeded to install the update, the consumer would encounter a series of installation screens, which stated that “Java provides safe and secure access to the world of amazing Java content,” and that Java SE updates and a consumer’s “system” would have “the latest . . . security improvements.” During the Java SE update process, however, Oracle did not inform consumers that Java SE updates automatically removed only the most recent prior iteration of Java SE installed on the consumer’s computer, even if the consumer had multiple iterations of Java SE installed, and that the update would not remove any iteration released prior to Java SE iteration 6 update 10. As such, after the update process, consumers could still have additional older, insecure iterations of Java SE installed on their computers, which attackers targeted to obtain consumers’ personal information through malware designed to exploit vulnerabilities (“exploit kits”).

The Commission’s complaint alleges that Oracle violated Section 5(a) of the FTC Act by failing to disclose that, in VOLUME 161 Analysis to Aid Public Comment numerous instances, updating Java SE would not delete or replace all older iterations of Java SE on a consumer’s computer, and as a result, a consumer’s computer could still have iterations of Java SE installed that are vulnerable to security risks. This fact would be material to consumers’ decisions whether to take further action after “updating” Java SE to protect their computers, in light of Oracle’s representations to consumers that by updating Java SE, users would ensure that Java SE on their computers had the latest security improvements.

The complaint further alleges that, by failing to inform consumers that the Java SE update process did not remove all prior iterations of the software, Oracle left some consumers vulnerable to a serious, well-known, and reasonably foreseeable security risk that attackers would target these computers through exploit kits, resulting in the theft of personal information. Consumers with insecure iterations of Java SE on their computers were vulnerable to exploit kits targeting Java SE vulnerabilities while browsing infected websites or clicking on nefarious links. Attackers used exploit kits targeting Java SE vulnerabilities to install key loggers that captured consumers’ usernames and passwords, which could be used to log into a consumer’s Paypal, bank, and credit card accounts. Other Java SE exploit kits may have resulted in the unauthorized acquisition and transmission of sensitive personal information for the purpose of targeted spearphishing campaigns.

The proposed order contains provisions designed to prevent Oracle from engaging in the future in practices similar to those alleged in the complaint.

Part I of the proposed order prohibits Oracle from misrepresenting (1) the privacy or security of the covered software on a consumer’s computer, including but not limited to the effect on privacy or security of any installation or update of the covered software; and (2) how to uninstall older iterations of the covered software.

Part II of the proposed order requires Oracle to ensure that during any installation or update of any iteration of Java SE released after the date of service of the order, Oracle: ORACLE CORPORATION 403 Analysis to Aid Public Comment (1) clearly and conspicuously discloses to the consumer all iterations of Java SE 1.4.2 or later, other than any iteration(s) released within the last quarter, currently installed on the consumer’s computer;

(2) clearly and conspicuously explains that there may be risks to the security of the consumer’s computer if the consumer chooses not to remove any iterations of Java SE older than the iteration(s) released within the last quarter currently installed on the consumer’s computer; and (3) clearly and conspicuously discloses which iterations of Java SE 1.4.2 or later, other than any iteration(s) released within the last quarter, that remain installed following installation or update of Java SE, and clearly and conspicuously provides instructions describing how consumers can effectively uninstall these iterations. Part III of the proposed order requires Oracle to notify consumers who downloaded, installed, or updated Java SE that, in some instances, they may have older, insecure iterations of Java SE on their computers; and provide instructions to such consumers on how to remove these older iterations. In addition, for three (3) years, Oracle must provide an uninstall tool that allows consumers to uninstall iterations of Java SE 1.4.2 or later; a page on their primary website that explains how to uninstall older, insecure iterations of Java SE; and free support through an electronic form to help consumers with their update and/or uninstall issues.

Parts IV through VIII of the proposed order are standard reporting and compliance provisions. Part IV requires Oracle to retain documents relating to its compliance with the order for a five-year period. Part V requires dissemination of the order now and in the future to all current and future principals, officers, directors, and managers, and to persons with managerial or supervisory responsibilities relating to Parts I – III of the order. Part VI ensures notification to the FTC of changes in corporate status. Part VII mandates that Oracle submit a compliance report to the FTC within 90 days, and periodically VOLUME 161 Analysis to Aid Public Comment thereafter as requested. Part VIII is a provision “sunsetting” the order after twenty (20) years, with certain exceptions. The purpose of this analysis is to facilitate public comment on the proposed order. It is not intended to constitute an official interpretation of the proposed complaint or order or to modify the order’s terms in any way.

HIKMA PHARMACEUTICALS PLC 405 Complaint

← 161 F.T.C. 337 · 161 F.T.C. 405 →