Progress on the OCA: Oracle Certified Associate Java SE 8 Programmer I Study Guide

book-pdf

In September, Scott and I announced we were writing a book for the OCA (Java 8) exam. Just over a month later, the book cover is up on Amazon along with the estimated publish date of December 31, 2014. I assume this means early January as I find it hard to believe anything happens at a large company during Christmas/New Year’s Week.

It’s great to see progress though. The book is now starting the technical proofreading stage. Yesterday, our tech proofer showed us what the PDF or some of the chapters looks like. it was really cool seeing the jump from a (heavily edited and iterative) Word document to a sharp looking PDF. It’s also exciting seeing something we wrote in near final form.

browser plugins

A friend asked me what browser plugins I use. Rather than write an email back, I thought “well that makes a good blog post.” Aside from the plugins practically everyone has (like Java, Acrobat, etc), this page lists what I use.

Safari plugins

My main browser is Safari. I have:

Plugin What is is for
Live CSS Editor  Testing CSS changes without loading the page
Firebug Lite for Safari JavaScript debugging
Unicorn CSS validator equivalent to this page
W3C Validator XHTML, CSS and RSS validator equivalent to this page (not sure where I downloaded it from)
No Follow Shows which links have no follow
Ghostery This is the most recent plugin that I’ve added. It shows you which third party sites have content on the page and makes it easy to customize what you allow.

I used to use plugins for Delicious and Feedly, but replaced them with the bookmarkets

Safari plugins

I also have some Firefox plugins:

Plugin What is is for
Alexa Toolbar  The Alexa toolbar shows you the “popularity” of a site. This plugin “phones home” with your business so I don’t want it in my main browser. It is useful when looking at SEO though. For example, my friend owns NYC Doula Service and asked me a question about her ranking. It was convenient to have tools installed.
PageRank  Shows Google page rank value. I don’t know if this one phones home, but I keep it in Firefox because Alexa is there.
Heartbleed  Earlier this year when the Heartbleed vulnerability was new, someone wrote a plugin to check sites. This plugin was only available in Firefox. That’s why this one is in Firefox, it isn’t a plugin that I think is spying on me.

OWASP A9 – Using Insight/CLM for CodeRanch

This week at CodeRanch we have a promotion for Iron Clad Java. Before the promo, I wanted to make sure we didn’t have anything embarrassing going on. We had already dealt with XSS, CSRF, Clickjacking and brute force logins. As I looked through the OWASP Top 10, I realized that I had no idea how we were doing on A9 “Using Components with Known Vulnerabilities”.

I saw that Sonatype provides a free Insight scan. I did that and got a nice summary:

clmHigh level summary

The high points of the summary are that:

  1. We use 58 libraries
  2. No high known security vulnerabilities in the libraries we use!
  3. Need to look into the details for the license “issues” since we are non-commerical.

Details

I then clicked on the other tabs and got a sample report. That’s the line where free lives. Since CodeRanch doesn’t have a budget, I asked the vendor for a free credit to see the report and they graciously agreed.

I then learned:

  1. All four of our security “issues” were in commons-httpclient. This library isn’t used anywhere in the codebase or in unit tests. I checked the description of the issue and we don’t  use that part of the library. So clean! I’m impressed that a completely volunteer run site came out clean. Good job to all the mods who update the jars!
  2. The license part showed a variety of licenses. For example dom4j and hibernate-core came up. The licenses would be more useful if we were a company and owned the product/could configure it ourselves.
  3. It was cool seeing the ages of the components we use. And which ones are exact matches vs similar. (I’m sure we didn’t edit hibernate-core!)

This report would be clearly be more useful for a large company. More applications and more people who work on them makes it harder to know what is going on. Still, I’m glad I didn’t have to check 50+ libraries by hand.

Disclaimer: I received free access to the detailed report in exchange for writing this review.