02 Runtimes
Java applets
Code that ran inside the page in its own sandbox, with a security model that outlived its usefulness.

The manuals outlasted the plugin. Documentation is often the last part of a runtime still legible.
oujouer.com collection
A runtime that promised too much and delivered too long
Java arrived in 1995 with a proposition that seemed, at the time, almost unreasonably ambitious: write code once, run it anywhere — including inside a web page. Sun Microsystems shipped the Java plugin alongside the language itself, and within a year Netscape Navigator supported it. A small block of bytecode, declared with an <applet> tag, would load into a sandboxed virtual machine inside the browser and execute there, isolated from the host operating system. The security model was the selling point. The sandbox was also, eventually, the problem.
Through the late 1990s the applet had genuine momentum. Games appeared: simple puzzles, card games, the kind of turn-based strategy that worked comfortably in a runtime that was not especially fast. Multiplayer text-based environments had already shown that a browser could be a social space — MUD1 at Essex predated the web entirely — but applets gave developers a graphical layer without requiring the player to install anything beyond a browser and the plugin. Chat clients, interactive maps and simple arcade ports all used the same mechanism.

Director shipped on disc first and on the web second, which is why it never reached Flash’s install base.
oujouer.com collection
The difficulty was performance. The Java Virtual Machine was interpreting bytecode at a time when processors were not fast enough to make that invisible. Just-in-time compilation — where the JVM compiles hot bytecode paths to native machine code at runtime — improved matters considerably after HotSpot arrived with Java 1.3 in 2000, but by then Flash had already established itself as the more fluid experience for animation and games. Flash's rendering was purpose-built for the browser; the JVM was a general runtime that happened to live there. The difference was visible.

The preloader was the only moment the platform showed itself to the player.
oujouer.com collection
What kept applets alive was not games but institutional software — educational tools, scientific visualisations, banking interfaces — and the promise of the security sandbox. A well-configured applet was supposed to be unable to touch the filesystem or the network beyond its origin server. In practice, the sandbox became the site of a sustained and damaging series of vulnerabilities. Between roughly 2012 and 2014, Java's browser plugin was repeatedly identified by security researchers as one of the most exploited surfaces on the consumer web. The US Department of Homeland Security advised users to disable it on more than one occasion. Oracle, which had acquired Sun and with it Java in 2010, issued patches in rapid succession; the reputation damage was cumulative rather than recoverable.
Sun Microsystems shipped the Java plugin alongside the language itself, and within a year Netscape Navigator supported it.
The browser vendors began the withdrawal. Mozilla deprecated NPAPI plugin support incrementally, and the Java plugin — which relied on NPAPI, the same interface that carried Flash and Shockwave — lost its foothold in Firefox. Chrome dropped NPAPI entirely in 2015. The Java plugin was formally deprecated by Oracle in Java 9, released in 2017, and removed in Java 11 the following year. Unlike Flash, the end came without a fixed public deadline and without much ceremony; the plugin simply stopped being part of the platform.
Preservation here is structurally harder than for Flash. The Internet Archive runs the Emularity framework to serve browser software through emulation, and some applets are accessible through it, but the catalogue is thin. Java applets were never collected at the scale that Flash content was, partly because the game output was smaller and partly because no project equivalent to BlueMaxima's Flashpoint organised around the runtime. The .class and .jar files that constitute an applet are often recoverable from archived pages; running them requires a compatible JVM and, depending on the applet's signing and permission requirements, a security configuration that modern Java explicitly refuses to provide. The sandbox that was once the feature is now the barrier.

Distributed, installed, withdrawn — the disc outlived the software’s reach.
oujouer.com collection
What remains is a runtime that bridged a genuine gap — the years between static HTML and the mature plugin ecosystem — and whose institutional use cases outlasted its cultural ones by a decade. The games it carried were modest; the infrastructure question it raised, of how to run untrusted code safely inside a page, has never been fully resolved.