Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Breakable
Kevin Poulsen, SecurityFocus 2002-01-16

A U.K. security expert is preparing to unveil a trove of serious vulnerabilities in Oracle's database products. Can the company redefine 'unbreakable' in time?

Comments Mode:
14 evaluations missed what 1 guy found... 2002-01-16
Anonymous (5 replies)
14 evaluations missed what 1 guy found... 2002-01-17
Brad C. Johnson, Vice President, SystemExperts Corp.
Not just some guy 2002-01-17
BLKMGK
PGU 2002-01-16
Anonymous (1 replies)
PGU 2002-01-17
Anonymous
Breakable 2002-01-17
Anonymous (2 replies)
Breakable 2002-01-17
KZ
Breakable 2002-01-17
Anonymous
Schneier is right 2002-01-17
Anonymous (1 replies)
Schneier is right 2002-01-17
Brad C. Johnson, Vice President, SystemExperts Corp.
Breakable 2002-01-17
drama at slakin d0t n3t (1 replies)
Breakable 2002-01-17
Anonymous
What Oracle means by UnBreakable 2002-01-17
Anonymous (3 replies)
UnBreakable <- Can't break in? 2002-01-18
Anonymous
What Oracle means by UnBreakable 2002-01-18
Anonymous
enron 2002-01-17
kkr
Breakable 2002-01-17
Grizzly
Breakable 2002-01-17
Anonymous
Breakable 2002-01-17
Anonymous (1 replies)
Breakable 2002-01-18
Anonymous
Oracle9i = 0 Evaluations 2002-01-17
Ross
Breakable 2002-01-18
An ex-Oracle security guy (1 replies)
[Moderator -- please replace the previous Anonymous posting with the following content, with this one, thanx]

Let's be real folks. All us security types know that security is a rich topic for 'truth or dare.' And everyone beats up Oracle's marketing department for their hype. So what? Mary Ann was recently given the highest ranking security position that Oracle has ever had. She is justifiably proud of Oracle's history of security work because she's seen all the 14 (Orange Book, etc.) evaluations of the database, and much, much more. She's really trying to make a difference and now she's in a position to make it so. Consider the following.

We all know few businesses buy software just for security reasons. Do huge numbers of security flaws stop anyone from buying M$ products??? How many people buy supposedly "secure" products that suck in functionality? Right, I thought so. Ignore Oracle's marketing hype for a moment. Oracle is seriously attempting to promote security as a product differentiator. Mary Ann really believes what she said to Mullen:

"We believe the market effect of the 'Unbreakable' campaign raises the security bar and therefore improves security overall, both in forcing us to live up to the statement, and forcing others in the industry to begin to do the same," wrote Davidson. "If our security today is imperfect but better than the competition, and if customers make a buying decision based on that criteria, than in the long term you will see all products in the market improve."

So what if Oracle's marketing hype isn't literally true? (Folks who take literally *any* marketing messages have bigger problems than this ;^) Oracle's marketing hype is just a reflection of Larry--take it for what it is. Now ask yourself: do you know of any other company (the size of Oracle) with the balls to put up such a challenge and is willing to deal with the consequences?

I can only wish Oracle 'good luck' and 'godspeed' in responding to the inevitable flow of security vulnerabilities yet to be found. White hat hackers be happy! Oracle is proof that you *can* make a difference!

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/309/9960#9960
Breakable 2002-01-18
Anonymous
Breakable 2002-01-18
Anonymous
Breakable 2002-01-18
An Interested Party
Playing with words 2002-01-20
Tired guy







 

Privacy Statement
Copyright 2009, SecurityFocus