Comment Re:The problem is not Java (Score 1) 309
No matter what we do to the browser's TLS implementation, this attack would still be possible via Java, because Java has its own TLS implementation.
We are already working on proactively mitigating any improvements on the BEAST attack that could be made to work using native browser features that would be affected by changes to our TLS implementation. But, right now, there are no known ways to implement the attack using built-in browser features.