FTC Settles with Oracle over Charges of Software Security Misrepresentations
Time 3 Minute Read

On December 21, 2015, the Federal Trade Commission announced software company Oracle Corporation (“Oracle”) has agreed to settle FTC charges that accused the company of misrepresenting the security of its software updates. The proposed Agreement Containing Consent Order (“Consent Order”) stems from an FTC complaint that alleged the company had deceived consumers about the security provided by updates to the Java Platform, Standard Edition software (“Java SE”).

Java SE is a version of the Java computing platform commonly installed on personal computers to enable consumers to run various types of Java-compatible applications on their computers. In its complaint, the FTC alleged that the process for updating Java SE made it likely that consumers unknowingly would have older, insecure versions of Java SE remaining on their computers, despite the company’s representations to consumers that installing the update would be “safe and secure” and provide “the latest…security improvements.” In light of this representation, the FTC believed that Oracle misrepresented the security of its update process by failing to adequately disclose that older and less secure versions of the software could remain on the consumer’s computer. As a result, the FTC charged Oracle with engaging in a deceptive act or practice in violation of Section 5 of the FTC Act. According to Jessica Rich, Director of the FTC’s Bureau of Consumer Protection, “[w]hen a company’s software is on hundreds of millions of computers, it is vital that its statements are true and its security updates actually provide security for the software.”

The proposed Consent Order will prohibit Oracle from misrepresenting the privacy and security of its consumer-facing software, and require Oracle to inform consumers how to uninstall older iterations of such software. In addition, the Consent Order will require Oracle to clearly and conspicuously disclose to consumers during the Java SE update process if they have outdated versions of the software on their computer, notify them of the risk of keeping the older software on the device and provide instructions on how to uninstall it. The Consent Order also will require that Oracle provide consumers with several forms of notice about the settlement and how consumers can remove older versions of the software. Under the Consent Order, Oracle must post the notice on its website and via social media (i.e., on Twitter and Facebook), and also must request that third party software developers publish the notice in their security bulletins.

You May Also Be Interested In

Time 3 Minute Read

The Connecticut Attorney General recently issued a legal memorandum regarding the application of existing Connecticut laws, such as the Connecticut Data Privacy Act, to the use of artificial intelligence.

Time 3 Minute Read

On March 20, 2026, Oklahoma Governor Kevin Stitt signed SB 546 into law, enacting the Oklahoma Consumer Data Privacy Act, which will take effect on January 1, 2027.

Time 2 Minute Read

On February 5, 2026, Alabama Governor Kay Ivey signed Alabama House Bill 161, the App Store Accountability Act, establishing age categorization, age verification and parental consent requirements for mobile application marketplace providers operating in Alabama, effective January 2027.

Time 2 Minute Read

On March 5, 2026, the California Privacy Protection Agency announced that the agency had reached a settlement with Ford Motor Company resolving an enforcement action against the company that alleged noncompliance with the California Consumer Privacy Act’s opt-out of sale/sharing rights.

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page