Meet Oracle: the new Microsoft - Silicon Valley Sleuth

Silicon Valley Sleuth, an insider's view from Silicon Valley
A blog from V3.co.uk





Other blogs
Download Junkie
Your daily dose of download discussion

IT Sneak
V3.co.uk's under cover reporter offers odds and ends from the odd end of the technology

Mac Inspector
Drills to the core of the latest Mac rumours and news

Security Watchdog
Sniffing out IT security issues

The Frontline
Insight into the latest tech news from V3.co.uk's team of reporters

V3.co.uk Labs
The latest UK business technology: quick reviews and first impressions




« Podcasts: growing pains or the end of a hype? | Main | OLPC does Doom »

Meet Oracle: the new Microsoft

Pouring some salt into Oracle's security wounds, security researcher David Litchfield has published details of a new class of attack against the database. The vulnerability could allow an attacker to steal confidential information or insert coding time bombs in the database that will get executed at a later time.

0072133252 Oracle can't do much about this one. Instead, application developers have to make sure that they follow best practices.

Although Oracle is trying to meet the challenges of today's security landscape, the company so far has failed to step up to the challenge. It isn't just that Oracle is unable to fight off the onslaught of new SQL injection vulnerabilities, as the unpatched vulnerabilities meter currently surpasses 200.

The database vendor also seems unable to handle a world in which information travels at the speed of light, and in which it needs to respond instantaneously.

The company has a "global product security blog" which published a paltry four postings last October, and none so far in November. Security related questions to Oracle's PR department as a rule remain unanswered.

Security seems an afterthought with Oracle. The company should consider looking at Microsoft for some inspiration.

Technorati technorati tags: , , , ,

Comments

Post a comment







Useful links: About | Privacy policy | Terms & conditions | Top of the page
© Incisive Media Investments Limited 2010, Published by Incisive Financial Publishing Limited, Haymarket House, 28-29 Haymarket, London SW1Y 4RX, are companies registered in England and Wales with company registration numbers 04252091 & 04252093