Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers |
|---|---|
| Date: | Fri, 07 Oct 2005 20:26:10 +0200 |
Having worked closely with the security teams of most large commercial vendors (IBM, Oracle, Microsoft, Apple, HP, Adobe, Real) I can quite honestly say that, of all of them, Oracle is the only company to still treat security in this way. Most other organizations "got it" years ago and while there could be improvements made in various areas the most improvement could be made at Oracle.
Not many of them "got it". Some are simply worse.
Firstly, it's due to the facts that I posted as I did. It is fact that the patch for Alert 68 fails to properly fix a large number of holes it was touted to fix. It is fact that a large number of companies that spent a great deal of money installing the patch have wasted their time. It is fact that Oracle database servers are still vulnerable to security holes that were reported to Oracle years ago.
Amazing statistics. Where are statistics on others?
Oh, this wasn't out of the blue; and there have been a great number of public statements about Oracle's failings. Not just from myself, I'll add, but others as well.
I'll Google. Thanks.
I sympathize with your concerns and I am known to be FAR from a person who doesn't voice his opinions - and loudly, but it only makes me wonder why now,
Because enough is enough.
why them
Because they seem to be the only ones that don't get it.
This is the place where you lost me, I am sorry. The only ones?
Yes. Based upon the facts the Oracle security response has been a failure. How else can you describe it?
If you gave me a patch and said it fixed a security flaw and it turns out it didn't I'd call that a failure. Multiply that by a factor of tens and you've got yourself a complete failure. If I did this to my customers I'd sack myself for neglect. Really, I would.
Good luck,
Gadi. /not advocating for Oracle but against public *personal* flogging
-- My blog: http://blogs.securiteam.com/?author=6
| Previous by Date: | Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers, David Litchfield |
|---|---|
| Next by Date: | Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers, David Litchfield |
| Previous by Thread: | Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers, David Litchfield |
| Next by Thread: | Re: Opinion: Complete failure of Oracle security response and utter neglect of their responsibility to their customers, David Litchfield |
| Indexes: | [Date] [Thread] [Top] [All Lists] |