Java Security Evolution - Out with the Old, In with the New

Security is a dynamic science. Over time, cryptographic protocols and algorithms inevitably weaken, and new ones are created to replace them. Security risks also change as new threats emerge while old ones may decrease in severity or relevance.

In this session, we will describe how we embrace these changes by continuously evolving the security of the Java Platform. We will explain why we permanently disabled the Security Manager in JDK 24 and the impact it may have on your applications or libraries. We will show you how we are enhancing the security of your applications by adding support for quantum-resistant algorithms in JDK 24. Finally, we will describe several enhancements planned for the near future.

Make sure to check the JavaOne 2025 playlist.