iTnews
  • Home
  • News
  • Technology
  • Security

Oracle hits back at security critics

By Tom Sanders
Nov 30 2006 12:50PM
Follow google news

Database vendor's claim that it is "leading the industry" greeted with
chuckles.

Oracle hits back at security critics
Oracle has lashed out against security experts who criticized the company's security record.

The database vendor is "leading the software industry in terms of responsible development and security," charged Eric Maurice, manager for security in Oracle's global technology business unit in a posting on a company blog.

Security researchers in the past weeks have targeted Oracle with multiple studies and blog postings. Both security vendor NGS Software and analyst firm Enterprise Strategy Group (ESG) have published studies comparing the number of software updates in Oracle and Microsoft databases. Both studies found that Microsoft outshone its competitor.

Argentinean security vendor Argeniss last week said that it was planning to organise a 'Week of Oracle Database Bugs'. The company said it would release details of one unpatched security vulnerability every day for one week to demonstrate the poor level of Oracle's database security. The company has since suspended the event.

Oracle's Maurice wrote his blog posting in response to "articles and blog entries", but didn't specifically mention the ESG, NGS Software or Argeniss cases.

However he appeared to address the NGS Software and ESG studies by claiming that others were "trying to play the number game" and countered that the database vendor won't let "external perception drive our security policies".

He touted the company's support for the Common Vulnerability Scoring System, a relatively new standard that provides an independent way of rating the severity of security flaws. The programme is headed up by Cisco, while Microsoft is famously absent from its supporter list.

Indirectly lashing out at Argeniss, Maurice described researchers who published zero day exploits as irresponsible.

Rich Mogull, a research vice president with Gartner who heads up the firm's Information Security and Risk practice, said that the blog posting was mostly a public relations move.

While he agreed with the database vendor that disclosing zero day vulnerabilities is irresponsible, he told vnunet.com that the vendor's claim that it is "leading the industry in terms of responsible development and security" is overblown.

"I would not say that Oracle is an industry leader yet. They need to mature as an organisation in how they manage these vulnerabilities," Mogull told vnunet.com.

"Oracle is putting practices in place, but they definitely aren’t as far along as some of the others."

He also pointed out that there hasn't yet been a large scale attack targeting Oracle databases. If such a worm would surface however, it could cause major damage to corporate data or erase it altogether.

Customers are telling Oracle that they are dissatisfied with the firm's security record and the large number of patches it releases, but they aren't yet switching to competing products, Mogull added.

"If customers start buying other products, that would cause Oracle to change very quickly."

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:
atbackcriticshitsoraclesecurity

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Intelligence × Trust: the equation that will decide Australia's AI winners
Promoted Content Intelligence × Trust: the equation that will decide Australia's AI winners
AI is delivering business value today
Partner Content AI is delivering business value today

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.