Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from vnunet.com



Other blogs
PCW Inter@ctive
Your views, your comments, your say

Security Watchdog
Sniffing out IT security
issues

The test bed
The hottest products, news and gossip from PCW's
Labs.

IT Sneak
IT Sneak Blog rummages in the dustbin of IT events.

Backbytes
An irreverent and offbeat look at the lighter side of technology

InterActive Home
Your complete guide to home entertainment technology

Taking Stock
Gags and Gossip from Accountancy Age.

Gizmodo
The gadgets weblog.



« Was Novell's Microsoft pact a mistake after all? | Main | PS1 + PS2 = PS3 »

Oracle's security record goes belly-up

Contrary to what Oracle likes to advertise in its marketing spin, the company's database is far from secure. The Central Intelligence Agency (CIA) might have been the application's first user, but these days the software is flooded with SQL injection flaws.

48589unbreakablelinux Contrary to Windows however, the flaws in Oracle remain largely invisible to the outside world. After all, few people have Oracle running on their desktop computers and we haven't seen any large scale worm attacks targeting Oracle databases. To the extent that attackers are targeting Oracle databases, they do so in targeted attacks to steal customer data or conduct industrial espionage.

So how do you make sure that the world finds out about Oracle's horrible security record?

By comparing the new devil with the old one, security researcher David Litchfield decided. Earlier today he published a whitepaper that drew a crystal clear picture. Around the same time that Microsoft succeeded to curb its security problems in SQL Server, Oracle completely lost control and saw the number of security vulnerability skyrocket.

Another researcher plans to have a "week of 0-day Oracle Database bugs" in an effort to draw the public's attention to the issue.

Larry Ellison in 2001 unwrapped a marketing programme that claimed that his database was "unbreakable", but reality has long since unveiled the hollowness behind the hype. Last month he dusted off the slogan once more, this time to market Oracle's support for Red Hat Linux.

If that's what Oracle's "unbreakable" respresents, Red Hat has nothing to worry about.

Technorati technorati tags: , , ,

November 22, 2006 at 03:01 AM | Permalink

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/t/trackback/24766/6906354

Listed below are links to weblogs that reference Oracle's security record goes belly-up:

Comments

Post a comment






 

Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Ltd. 2008
Incisive Media Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, is a company registered in the United Kingdom with company registration number 04038503