14 ms·
“Stop reverse engineering our code”
- pkkp 11y agoIs it just me, or is the childish, mocking tone in the OP simultaneously baffling and totally befitting of the point they're trying to make? I understand that they're frustrated by the repeated submission of automated security vulnerability reports, but blanketing it entirely as "reverse engineering" and responding to it like this is... a strange approach. Did someone at Oracle actually think that this was the best way to make this point?
- dantiberian 11y agoThe previous post on the blog has a similar tone too https://blogs.oracle.com/maryanndavidson/entry/is_your_shellshocked_poodle_freaked https://blogs.oracle.com/maryanndavidson/entry/is_your_shell...
- syncsynchalt 11y agoThe formatting in that post is... interesting. I'd blame the CMS before the author on that point though.
- ncr100 11y agoIn my opinion she is being paid for propaganda in support of Oracle. By that I mean the message is not beneficial to the whole population of Oracle Users, but only to Oracle Corporate.
- kjs3 11y agoYeah, it's very poorly written. I always cringe when some exec thinks "oh, it's just a blog so I don't have to write with the same professionalism and attention to detail that I would in other corporate communications".
- vacri 11y agoWell, it's not even 'just a blog', it's a blog hosted by oracle.com about the author's employment at same. The standard of professionalism should be higher given the direct link, methinks. If it were a personal blog on a personal topic, it wouldn't matter as much.
- kjs3 11y agoI think if recent history is any guide, a C-level who claims "you can't hold me accountable for stupid shit I say on my personal blog" isn't going to be one much longer.
- denwer 11y agoIs that post for real? https://twitter.com/dinodaizovi/status/630972473945817088 https://twitter.com/dinodaizovi/status/630972473945817088
- hughstephens 11y agowho knows – in many ways it's even better if it's satire, because it's just believable enough.
- jacquesm 11y agoIf it didn't have a 'most likely' in it I'd think it was satire, but that's the kind of weasel wording that you'd expect in a real release. There was another post in much the same vein on that blog: https://blogs.oracle.com/maryanndavidson/entry/those_who_can_t_do https://blogs.oracle.com/maryanndavidson/entry/those_who_can...
- tobltobs 11y ago"Fixability. Only Oracle can fix vulnerabilities: SASO cannot. We have the code: they don’t." Just one of many nuggets in this other arrogant posting. If somebody needs input why FOSS is better than closed source have a look into this one also.
- brohee 11y agoWho's she attacking in that post (SASO)? Veracode?
- tptacek 11y agoYes. She doesn't get along with Veracode.
- idlewords 11y agoIf you read her previous posts you'll see it's the exact same tone and writing style. I think the claims of hacking are a way for people to express their incredulity and not meant seriously.
- macmac 11y agoThe arrogance is titanic. And her legal team apparently forgot to explain to her that certain jurisdictions permit reverse engineering and decompilation under certain circumstances irrespective of what Oracles license agreement says.
- idlewords 11y agoCan some infosec person speak to her strongest claim, that static analysis gives "basically 100% false positives" and wastes the team's time?
- kjs3 11y agoShe has a point here. Static analysis does generate a lot of false positives, and it requires a pretty in-depth understanding of the code to determine whether any given hit is a real issue. Unfortunately, that sort of understanding doesn't usually come from just running a static analysis tool (or fuzzer, OWASP scanner, etc., etc.). The problem comes (and I have personally been on the receiving end of this) when running the tool results in a couple of dozen to a couple of hundred trouble tickets you can't simply ignore that say things like "I found a bug and if you don't respond I'm going to dump Oracle", "I found a bug and if you don't fix it on my schedule I'm going to post to HackerSiteDuJour" or "I found a bug pay me a bounty or I'm gonna make a big stink". And so someone will have to go and look at the report and "prove" that just like 99.999% of the time, it's a false positive, and they will have to do that for every "security" person who cranks up a tool and finds the same "vulnerability". The problem here is: 1) She might be a writer but boy did she not convey the message I think she wanted to, which is kind of a shame. 2) She doesn't apparently much understand "reverse engineering" with more nuance than "my legal team says you can't do it so there", which is much more of a shame for someone who carries a CSO bag.
- HelloNurse 11y agoOracle cannot ignore annoying and low-expected-value static analysis tickets, but: 1) the answer should usually be either "fixed in this patch, install it" or "it's a false positive, try developing an actual exploit if you don't believe us". Not expensive, provided Oracle actually runs static analysis tools against their software and addresses the findings before releasing updates. 2) If Oracle actually runs static analysis tools against their software and addresses the findings before releasing updates, there should be very few tickets of this type to begin with, often from the debut of new tools or from naive user mistakes. Finding something, and worse finding something over and over again, means that Oracle QA is inadequate.
- quesera 11y agoWow. Someone's been hitting the Kool-Aid pretty hard. I've seen this institutional hubris first-hand. The unshakable belief (typically by nontechnical management) that all of the smartest people in the world are employed here, working for me. It always ends badly.
- antimagic 11y agoYup. It's not like those customers that are busy reverse engineering Oracle's code are doing it for the kicks. They have their own jobs to do. Much more likely, they are getting weird results out of Oracle's software that they don't understand, so they reverse engineer the code to see why the system is crashing / giving unexpected results so that they can find a workaround without having to wait for the vendor to fix their bug. Then, if it turns out that it's a security issue, of course they are going to notify Oracle of the fact, both as a moral duty, and because it makes it more likely that Oracle will get a patch out faster. Oracle whinging about people finding bugs in their code would be better off trying to improve their processes so that there are less bugs to find, rather than complaining that they've been found out for shipping buggy code.
- technion 11y agoI actually understand how it gets to be this way though. I literally can't touch a Government project without an Oracle license. When I talk to a salesman, the attitude is "I know you can't do this without me", contrary to salesmen for any other product in any other industry. When I talk to a project manager, they don't ask how it will be hosted, or what the platform will be, or anything else obvious. The first question, often before a project is fined, is "how many Oracle licenses can I buy?".
- oddthink 11y agoInteresting. In what industries is Oracle so dominant? You say government is one, but where else? In industry, all I've ever seen is Sybase, SQL Server, and MySQL (ok, technically Oracle). (My background is finance and technology.)
- trymas 11y agoNot sure if trolling/hacked or serious. If later, I guess, many tech savvy (read 'hackers') people, will accept this as a challenge.
- dang 11y agoThe submitted title ('Oracle CSO: ~“Only we can do security, trust us and do not reverse engineer”') breaks the HN guidelines: it's editorialized (whatever one thinks of the article), and it's a quote-looking-thing that isn't a quote, so misleading. Please don't do this. The HN guidelines ask you to use the original title. If that's really not suitable, a subtitle or some representative language from the article is ok. But putting your own spin on it is not ok. HN's goal is to let readers make up their own minds, and for that we need accurate, neutral titles. We've changed the title to a representative phrase from the article, and can change it again if someone suggests something better.
- hughstephens 11y agoapologies, my fault.
- deleted 11y ago[deleted]
- lawnchair_larry 11y agoThis explains so much about the sorry state of Oracle security. I hope Litchfield lets loose on them again.
- Ogre 11y agoJust today I was arguing for not moving something off of Oracle. No one's really happy the thing in question is on Oracle, but it is live in production and most of the time does what it needs to. It ain't broke. Changing to "something else" carries way too many unknowns for my comfort level. If I'd read this last night... I still would've argued the same thing, but I would've been really unhappy about it.
- azinman2 11y agoThere are too many points to discuss... it's really quite insane especially on the backs of Java exploit after Java exploit. But what I really don't get is this bug bounty hateathon. If it's only 3% of bugs (currently WITHOUT incentives like a bug bounty), then that's really not that much money... and in return you get more cred, something you might use for recruitment, and the off chance that you might increase that 3% versus something going on the black market. Even more so, how much could this really cost!? And Oracle has how much money?! If you can't spend that on a bug bounty when you're security is just so awesome as the post contends, then something is really in trouble.
- smoyer 11y agoThe repeated Java exploits You're referring to are exposed when using Applets in a browser ... This was conventionally recognized as a bed idea in about 2006. You simply shouldn't allow Applets to run - no matter what. I think you'll find the rest of the Java platform more secure than most, especially since the OpenJDK foundation was formed. I'm not here to defend Oracle in any other way but they've done a reasonable job of advancing the Java platform since it was acquired.
- lsd5you 11y agoThere is nothing wrong with signed java applets. There is no difference between that and downloading and running (a signed) application.
- mikeash 11y agoThat's only true if Java's signature validation isn't vulnerable (or at least is no more vulnerable than the signature verification for a normal OS). Searching around, it looks like there was at least one vulnerability like this, in which Java failed to check certificates for revocation, and at least one exploit was found in the wild signed with a stolen, revoked certificate that Java still accepted. This is especially fun because Java at least tries to sandbox unsigned applets, but signed applets get a lot more privileges.
- 11y ago
- duncan_bayne 11y agoSo, I disagree with the poster on a bunch of things here (no surprise, really). But: this is authentic. This is what we (i.e. hackers) are always claiming we want. Someone speaking her mind, shooting from the hip, etc. Not an anodyne blob of corporate-speak: this is an opinion, stated pretty clearly, and backed up with fighting words. You'd expect: "Our legal team has advised us to remind consultants that they are bound by any and all terms and conditions to which their clients have ... etc. etc. etc." You get: "Otherwise everyone would hire a consultant to say (legal terms follow) “Nanny, nanny boo boo, big bad consultant can do X even if the customer can’t!”" Here we have someone who clearly loves the company and the product with a passion, defending both against what she sees (very wrongly, in my opinion) as criminal misuse and waste of resources. I'll take one of these posts and argue its merits any day, over a block of mealy-mouthed corporate crap.
- platinum1 11y agoYou can be authentic and speak your mind without being arrogant, insulting, and condescending. In terms of tone, I wouldn't hold this up as a good example - it distracts from any legitimate argument the writer may or may not have.
- Udo 11y agoI think a lot of blog posts like these get triggered by some acute event which pushed the writer over the edge, and it's expected this will shine through in the text. The rest is probably due to living in an employer-typical bubble. If I was an Oracle customer (which I will never, ever be) I would appreciate the honesty. This honesty enables me to make purchase decisions as well, better than megabytes of legalese would have. In this case it's not a really surprising attitude given the company, but I really wish more vendors would be as open about the nature of their intended relationship with their customers.
- maze-le 11y ago> This honesty enables me to make purchase decisions as well. Fair point. And a hint to everyone still hanging on to oracle Databases. One of the best lines is this here: > Q. What does Oracle do if there is an actual security vulnerability? > (...) if there is an actual security vulnerability, we will fix it. Sure, the question is 'when', not so much 'if' customers have payed a hell of a lot money to get this straight.
- owenwil 11y agoI laughed at this line where she tries to prove her point by touting that Oracle already found a bug that a security researcher reported to them (but wasn't fixed yet): "(Small digression: I was busting my buttons today when I found out that a well-known security researcher in a particular area of technology reported a bunch of alleged security issues to us except – we had already found all of them and we were already working on or had fixes. Woo hoo!)"
- sqldba 11y agoIt sounds like they've confused a) users submitting results from static analysis that wastes time, b) users submitting demonstrable vulnerabilities, and c) license agreements. a) is bad, and the users should just be turned away. b) is good and far better than selling them on the black market. c) is... who cares it's a license agreement.
- madaxe_again 11y agoShe's mostly focussed on (a), it seems, and I can understand the frustration - all too often we get lengthy missives from client consultants along the lines of "Ran scanning tool. Suggests that the version of PHP.net you are using is vulnerable to LSASS and STUXNET vulnerabilities, our client is terrified, pay me off to make the pain go away." We get a genuine vulnerability reported once in a blue moon. (b) is good, but her point that them spending their time doing static analysis of oracle's software is a monumental waste of time is perfectly valid, if their root password is password and the firewall is just some sheetrock in the basement.
- reacweb 11y agoReverse engineering is legal in France for research and computer security (http://www.legifrance.gouv.fr/affichTexte.do?cidTexte=JORFTEXT000000266350&categorieLien=id http://www.legifrance.gouv.fr/affichTexte.do?cidTexte=JORFTE...).
- kitsune_ 11y agoAlso in Switzerland: > Art. 21 Decoding of computer programs > 1 Any person who has the right to use a computer program may obtain, either personally or through a third party, necessary information on the interfaces by decoding the program code using independently developed programs. > 2 The interface information obtained by decoding the program code may only be used for the development, maintenance and use of interoperable computer programs insofar as neither the normal exploitation of the program nor the legitimate interests of the owner of the rights are unreasonably prejudiced. https://www.admin.ch/opc/en/classified-compilation/19920251/index.html#a21 https://www.admin.ch/opc/en/classified-compilation/19920251/...
- Jare 11y agoI wonder to what extent "interoperability" (a common exemption for allowing Reverse Engineering in US and EU) might include "security validation" and thus make this generally legal regardless of EULAs.
- dagw 11y agoSure, but this is a contract matter between two private entities. Oracle can still revoke your license for doing it.
- kuschku 11y agoIn German law, clauses that forbid reverse engineering are invalid, the contract itself still stays valid, though. UhrG Paragraph 95 and 69
- pluma 11y agoDon't some types of contract require a CYA clause along the lines of "if any part of this contract is invalid, the contract only covers those parts that are valid", though? I'm not sure whether this is just voodoo or whether those contracts would otherwise be nullified as soon as you point out any single clause is actually invalid.
- kriro 11y agoThis is a marketing layup for any FLOSS ERP company (or the PostgreSQLs of the world). Basically "by all means check our code for any issue you may find. We'll gladly accept any suggestions for code improvements you may have." This post is an absolute nightmare/facepalm. Basically my takeaway is "I guess I don't want to buy Oracle software". It's really mind blowing that this is the position of a major software company in this day and age. I mean I guess I shouldn't be shocked since it is in the EULA but man I'm kind of speechless (this clause has to be illegal in some countries, too). Edit: as an aside as a bad guy this would make me very interested in reverse engineering Oracle products. If they disallow it for their customers the reaction times to any security issues will be lower and it will be pretty valuable to find bugs in their products. Edit2: Seems like the blog was cracked. At least the "About" on the side seems to indicate that.
- binarymax 11y ago> (this clause has to be illegal in some countries, too) Pedantic: not illegal, but invalid.
- qznc 11y agoIf you dump a 400 page output dump of some static analysis tool on a FOSS project, not much will happen either. They will probably challenge you to find the actual issues yourself and enter bug reports.
- anarazel 11y agoYes, agreed. Especially if, after checking out the first 100 or so, all of them are false positives. But the big difference is that it's realistic, allowed and in many cases warmly welcomed if you submit actual problems.
- imglorp 11y agoYes, but all other things equal, wouldn't you rather know what's in there? Sun had an open bug database, it was glorious. That got snapped shut after purchase.
- Keyframe 11y ago
- Stratoscope 11y ago> Q. If you don’t let customers reverse engineer code, they won’t buy anything else from you. > A. I actually heard this from a customer. It was ironic because in order for them to buy more products from us (or use a cloud service offering), they’d have to sign – a license agreement! With the same terms that the customer had already admitted violating. “Honey, if you won’t let me cheat on you again, our marriage is through.” “Ah, er, you already violated the ‘forsaking all others’ part of the marriage vow so I think the marriage is already over.” What a thoroughly nasty comment. She is comparing her customer with someone who is cheating on their spouse. Disgusting.
- juliangregorian 11y agoThe scorn for customers in general is palpable. Why is Oracle even allowing this person to be a voice for their brand?
- wolfgke 11y ago> Why is Oracle even allowing this person to be a voice for their brand? Because her text will probably only infuriate people that will arguably never be Oracle customers?
- throwaway7767 11y ago> Because her text will probably only infuriate people that will arguably never be Oracle customers? As a sysadmin with customers who run oracle, and who put some stock in what I say, I can say I am more likely to warn people away from oracle in the future. While in some companies, tech purchasing decisions are made by suits with little or no input from techies, that's not universal.
- mhurron 11y agoIf Oracle won't sick the sales people on your upper managers if they even get wind that someone at the company want's to move away, you're just not a large enough customer and Oracle doesn't give a shit if you move.
- davidgerard 11y agoThis is one of the finest pieces of Postgres marketing I can recall seeing in recent times. They've made the case for open source better than anyone in 2015. (We're in the midst of an Oracle->Postgres conversion right now. It's going wonderfully. I strongly advise you to look into it, bet you'll find it way easier than you think.) (One of the nicest things about it: we give every app its own cluster of two PG boxes, because you can just do that instead of running a centralised monster box with an expensive license. It turns out that just everything not having to play nice with others makes stuff stupendously easier to manage.)
- konradb 11y agoHow do you arrange your PG clusters, are you using streaming replication?
- davidgerard 11y agoFailover pair with a primary and standby. The primary streams write-ahead log records to standby as they're generated. Some script gaffer-tape to watch for primary failure and fail over. I think we haven't ever yet actually had to invoke this though :-) This was all cobbled together following the docs. There are almost certainly better ways to do everything we've done so far. The Postgres is just 9.3 out of the Ubuntu 14.04 repo. Oracle was STUPENDOUS overkill for what it was actually being used for, but MySQL wasn't up to the job. The heavy lifting for the conversion is done using ora2pg http://ora2pg.darold.net/ http://ora2pg.darold.net/ Then there's a pile of faff and twiddling and unit tests and so forth. See also https://wiki.postgresql.org/wiki/Oracle_to_Postgres_Conversion https://wiki.postgresql.org/wiki/Oracle_to_Postgres_Conversi...
- konradb 11y agoSorry for late reply, thanks for the info! Interesting to see what others are doing.
- muhuk 11y agoNoticed that obscure death threat in the beginning? I'm not surprised to see it in a post about licenses.
- hyperdunc 11y agoIn the first paragraph the writer insinuates that she'd like to kill people who drive too close behind her. Any subsequent valid points she makes - and there aren't many - are undermined by this bitterness. Heightened emotion so often enables effective communication, but it doesn't do any favors in this post.
- anentropic 11y agoAlso, she loathes Keynes :(
- tat45 11y agoThat was her one redeeming statement in that blog post. :)
- gizi 11y agoI like it that Oracle openly publishes this kind of blogs. I would personally never work for a company which expects me to develop anything using Oracle gear. It's simple. I can always find another company that doesn't and that pays the same or better. That is also why I suspect that someone who works in those circumstances really has to, because he has no other options.
- mathiasrw 11y agoLove security by obscurity
- agounaris 11y agoI don't understand why everybody is mad about this post, oracle has proprietary software that is bound with a license. In that sense I don't see why people do not moan about having to pay a rent because your tenancy contract that you signed says so... Long story short, its a right of a SOFTWARE mostly company to protect its software, open source is not always the solution and reverse engineering something, consumes way more energy for the problems it actually solves.
- jnbiche 11y ago> open source is not always the solution and reverse engineering something, consumes way more energy for the problems it actually solves. You think customers are reverse engineering Oracle products for fun? They're doing it because there's a problem somewhere, they've filed a bug report and not got a satisfactory result, and so they have to go pay an expensive consultant to try and track down the problem for them with no source code. Even if none of the other arguments for open source were persuasive, this situation with Oracle alone would be enough to convince many people of the wisdom of choosing an open source vendor.
- TeMPOraL 11y agoWhat's wrong with reversing for fun? It's how progress of technology happens.
- tremon 11y agoYour boss is unlikely to pay you for it. The companies using Oracle software are usually not in software (database) development themselves, so there's no business incentive to pay you for having "fun" with expensive software.
- jnbiche 11y agoI think reversing for fun is great! But it's pretty unlikely that Oracle customers are doing it for this reason. Instead, I suspect their reversing is borne of desperation.
- 11y ago
- agounaris 11y agoI don't understand why everybody is mad about this post, oracle has proprietary software that is bound with a license. In that sense I don't see why people do not moan about having to pay a rent because your tenancy contract that you signed says so... Long story short, its a right of a SOFTWARE mostly company to protect its software, open source is not always the solution and reverse engineering something consumed way more energy for the problems it actually solves.
- EdwardDiego 11y ago> Generally, our code is shipped in compiled (executable) form (yes, I know that some code is interpreted). Customers get code that runs, not the code “as written.” That is for multiple reasons such as users generally only need to run code, not understand how it all gets put together, and the fact that our source code is highly valuable intellectual property (which is why we have a lot of restrictions on who accesses it and protections around it). Your JDBC driver IP isn't that valuable, just give me the damned source code so I can figure out why my Postgres copy out stream is blocking when I insert it into your copy in stream. /rant
- dolfje 11y agoApart from the legal stuff and a lot off egocentric 'we can do it better', she has one point. There are many companies giving a lot of money for security, manually scrubbing all exploits that come out, create their own patches. While some lack the basic security guidelines. I think this money can be better spend upstream, to create tools so they can test patches for exploits better and create a faster security update release pipeline, so that all downstream and customers can rely on the security releases and that it can be released quicker to everyone. (Controversial: Maybe even adding automatic security updates to the package itself, like wordpress did, so that customer cannot be on a release with exploits) Though saying to your client that they cannot reverse engineer to look for security problems, is totally not done! What is next? "Exploits will not be fixed, because the users has signed an agreement that they will not hack?"
- josch 11y ago_She_ has that point (Mary Ann).
- ck2 11y agoDon't worry, if you won't let your paying customers check for security holes, there are plenty of people in China who are going to do it for you instead.
- jjoos 11y ago> I am not dissing bug bounties, just noting that on a strictly economic basis, why would I throw a lot of money at 3% of the problem Aren't the issues not found by Oracle the problem? I'm amazed that stil 23% of the externally found security issues are reported by researchers, the incentive to responsibly disclose security issues to Oracle isn't really big. It sounds like a cumbersome process with potential legal consequences. There also are researchers(, maybe after a first bad experience about an EULA,) that sell security issues to the grey/black market. Is there any data on how many Java zero days are exploited in the wild before being fixed? Changing your stance and being grateful for responsible disclosures and only using your EULA to threaten and sue the bad people can potentially save everyone with java installed from a few zero days at zero cost.
- jackweirdy 11y agoI agree with that point, and think it hits at something bigger. Having a bug bounty doesn't just say 'we give out money for bugs'. It also says 'we have a thought-out programme for handling serious user-reported problems, and we won't reprimand or dismiss you for sharing them'.
- Nadya 11y agoWhen 0-days can exist in the 13% she handwaved away, it really makes you wonder how she's Chief Security Officer...
- golemotron 11y ago> A. The customer signed the Oracle license agreement, and the consultant hired by the customer is thus bound by the customer’s signed license agreement. Otherwise everyone would hire a consultant to say (legal terms follow) “Nanny, nanny boo boo, big bad consultant can do X even if the customer can’t!” Really? What if no money changes hands?
- revmoo 11y agoNo, she's utterly ignorant of contract law: Privity is a doctrine in English contract law that covers the relationship between parties to a contract and other parties or agents. At its most basic level, the rule is that a contract can neither give rights to, nor impose obligations on, anyone who is not a party to the original agreement, i.e. a "third party".
- dferlemann 11y agoThis is exactly the problem with legality of RE and penetration testing. "You broke the law by wasting our time, violating your license agreement." I understand author's points. Not very good points, disappointingly. No matter how interpersonal she puts it. It makes me not ever want my system to rely on a company that threatens and belittle customers for protecting themselves. If I bought a fridge for my house, I found a listening device and a pinhole camera in the fridge. Just because the company has a clause I am not allowed to open up the fridge, it doesn't mean I shouldn't. Well, the company might have found the devices. Indeed maybe nothing customers can do until the company fixes it. Keep telling customers they are not allow to look for flaws it just ridiculous. Yes, it's your product, but this is my home!
- Thriptic 11y ago> Yes, it's your product, but this is my home! My stance is that EULAs are bullshit, period. If you purchase a product, it is yours, and no one should be able to dictate how you use it.
- mhuffman 11y agoUnfortunately courts seem to not share your stance, it seems.
- zyM7A6bQzJKBHnS 11y agoCourts of which country? There are a lot of countries out there, some of them allowing reverse engineering (especially in Europe for example).
- dferlemann 11y agoI read up on some of DCMA stuff, it does seem to allow some degree of reverse engineering in U.S..
- charltones 11y agoThere is just no upside to this kind of response. Surely for any tech company that has reached a certain size, the only workable approach is to recruit an appropriately sized security team and politely welcome and respond to each and every security report received, triage them as quickly as possible and fix the ones that are found to be real vulnerabilities. Even if you aren't happy with the motives or the methods they employ, they are potentially finding flaws in your products for you.
- lorenzhs 11y agoTo me, this reads like a post explaining the benefits of free software by demonstrating the disadvantages of using proprietary systems. A bit hyperbolic at that, though. RMS would have a field day.
- kabdib 11y agoWow. Really? This single blog post is strong evidence for why you should never, ever buy an Oracle product, and if you are running anything written by them, why you should plan to migrate away. Now, the culture of consultants in the Oracle sphere of influence is pretty toxic and money-grubbing. I can imagine companies being badgered into paying security weasels big bucks to analyze software with tools that cough up a zillion false positives, whereupon the weasel looks like a hero and is paid a bunch of cash, the customer panics and demands that Oracle fix a pile of non-existent vulns, and some department buried inside Oracle doesn't know how to deal. Whereupon the weasel skates off to another company to run the same scam: rinse, repeat, and this blog post. In which case Oracle should simply call it out: "Please don't send us crappy automated scanning tool reports from the shitty security weasel consultant you hired because those reports are useless, and the same weasels have been sending identical ones in, monthly, for years, and you are being ripped off." But Oracle never passes up the opportunity to express contempt for its customers, nor can it admit to being wrong. Better to avoid that whole ecosystem.
- bmir-alum-007 11y agoStanford was taken to the cleaners to the tune of $1.5 x 10^8 USD in the deployment of Oracle Financials and related products via endless "consultant implementation" charges that didn't really deliver much value, were rarely on schedule or on budget. Oracle's enterprise calendaring program was totally inadequate and had UX that made most point-of-sale systems look effortless by contrast. Also, the assets managing app, Sunflower, was another dud. The only thing Oracle Database had going for it was no crippling license activation (license scofflaws are/were sued or fined into oblivion worse than M$FT), which one could say was equivalent to MS SQL. Unlike MS MSQL, Oracle DBMS has/had bazillions of support patches to apply to run a real production box, analogous to the previously separate Sun's Solaris patchsets. Btw: For smaller enterprisey shops, either MS SQL or Postgres are the way to go. Often multiple similar components are needed because different apps have firm requirements that only support one or another; but generally try to avoid this because supporting too many heterogenous components is expensive (laborious)... hence the prevalence of local "standards." Deploying everything with cfengine3 or puppet can help reduce the manualness and nudge vendors into repeatable, idempotent deployments rather than clicking on inane GUI installers like an animal. ProTip: Don't let consultants "provide" oversight / free-reign for their own projects, budgets, etc., that's like the wolf guarding the henhouse. The client must hire their own project managers, have clear accountability/authority paths to their management and know exactly what they need (avoid endless upselling). Or lots of money will be transferred from idiots to crooks (enterprise caveat emptor). Edit: fixed grammar
- bradleyankrom 11y agoNo matter how valid her points are, the tone is inexcusable in a public-facing blog, especially when discussing customer behavior. I recognize the strong points of Oracle's offerings, but let's not pretend that there is not competition from other, open software.
- hownottowrite 11y agoMary Ann Davidson's testimony on "cybersecurity" (2009) https://www.whitehouse.gov/files/documents/cyber/Congress%20-%20Davidson-Oracle-SFR_10Mar09.pdf https://www.whitehouse.gov/files/documents/cyber/Congress%20...
- deleted 11y ago[deleted]
- WormyMcSquirmy 11y ago>Ah, well, we find 87% of security vulnerabilities ourselves, security researchers find about 3% and the rest are found by customers. They admit more security vulnerabilities are found by customers than security researchers and still they release this smug "fuck off" toned blog.
- discreditable 11y agoLink is giving me a 404. Anyone got a mirror?
- anglebracket 11y agohttps://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t https://web.archive.org/web/20150811052336/https://blogs.ora...
- opless 11y agoJust in case a robot.txt kills that http://pastebin.com/rcPSyRnR http://pastebin.com/rcPSyRnR
- snsr 11y agoIt's also on seclists.org - http://seclists.org/isn/2015/Aug/4 http://seclists.org/isn/2015/Aug/4
- hughw 11y agoWould archive.org typically honor a robots.txt for a resource it already retrieved? I never understood the intent of a robots.txt to be retroactive.
- mikeash 11y agoApparently yes, it would: https://archive.org/about/exclude.php https://archive.org/about/exclude.php
- X-Istence 11y agoYes, it simply hides the content, it is still kept in their database so if the robots.txt disappears, it pops back from their archive. New pages won't be archived though.
- syncsynchalt 11y agoMy understanding is that sites like archive.org honor robots.txt retroactively not because they are required to, but to best honor the wishes of the content provider.
- ikeboy 11y ago>We will also not provide credit in any advisories we might issue. You can’t really expect us to say “thank you for breaking the license agreement.” Well, Apple does (for jailbreak exploits). >I am not dissing bug bounties, just noting that on a strictly economic basis, why would I throw a lot of money at 3% of the problem Uh ... You don't think that percentage will increase if you offer bounties?
- XMPPwocky 11y ago>>I am not dissing bug bounties, just noting that on a strictly economic basis, why would I throw a lot of money at 3% of the problem >Uh ... You don't think that percentage will increase if you offer bounties? And if it doesn't, well, they don't pay out much. It's not like bug bounties consist of just throwing money at random people and hoping they find vulns; you pay for results. That's sort of the point.
- crypt1d 11y agoSeems like the original blog post was deleted, here is the archive - https://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t https://web.archive.org/web/20150811052336/https://blogs.ora...
- bradleyankrom 11y agoGlorious. Somewhat surprised it was taken down, though.
- OJFord 11y agoI'm more surprised it was posted! (at least in ~current~ as-it-was form)
- vetrom 11y agoI am not at all surprised that oracle would memory hole something that escapes PR control.
- DonHopkins 11y ago"Stop reverse engineering our blogs!"
- deleted 11y ago[deleted]
- cheshire137 11y agoThanks for the mirror!
- nickysielicki 11y agoThank you for using the word, "mirror" so that I could find it quickly.
- 16bytes 11y agoI read the blog, but now it's returning a 404? Did they take it down? If so, then somebody at Oracle realized that post reflected poorly on their organization. Perhaps there is some hope for Oracle yet.
- baseballmerpeak 11y agohttp://webcache.googleusercontent.com/search?q=cache:https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t http://webcache.googleusercontent.com/search?q=cache:https:/...
- fluidcruft 11y agoTheir IT probably have an automatic preemptive policy of 404'ing any pages that become "popular"--any such content is is pretty much guaranteed to reflect poorly on their organization. False positives can always be waved away by a euphemism for a transient technical error ex post facto.
- dredmorbius 11y agoArchive.org: http://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t http://web.archive.org/web/20150811052336/https://blogs.orac...
- jurre 11y agoIt seems to have been removed, here's a pastebin of the original post: http://pastebin.com/bbMshdU1 http://pastebin.com/bbMshdU1
- Patriotspade 11y agoAlso can be viewed with wayback machine here... https://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t https://web.archive.org/web/20150811052336/https://blogs.ora...
- Ben0xA 11y agoOracle pulled the original post - here it is on pastebin http://pastebin.com/wkk8b7FJ http://pastebin.com/wkk8b7FJ
- nosnos 11y agoThey took it down. Mirror?
- khaki54 11y agoWayback machine: https://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t https://web.archive.org/web/20150811052336/https://blogs.ora...
- akshatpradhan 11y agoWho's the author?
- khaki54 11y agoChief Security Officer for Oracle, Mary Ann Davidson
- deleted 11y ago[deleted]
- alediaferia 11y agoThe author must have been undergoing some bad moments so far. The post seems just the outcome of a more complex series of inputs. Most points are not valid from my own personal point of view but still may have been good points if written in a more objective way. BTW, the post is gone.
- khaki54 11y agoOracle JRE is literally one of the more vulnerable pieces of software underpinning the web and computing as a whole. JRE CVEs: http://www.cvedetails.com/vulnerability-list/vendor_id-93/product_id-19117/Oracle-JRE.html http://www.cvedetails.com/vulnerability-list/vendor_id-93/pr... It's been 5 years since Oracle took over Java, so they can't claim it was left over. Oracle's security record is terrible by all accounts, so how can their CSO justify anything in this blog post? ORACLE product list CVEs: http://www.cvedetails.com/product-list/product_type-/firstchar-/vendor_id-93/page-1/products-by-name.html?sha=2a9718c5c6139d3034698d7627abb350713f75e4&order=3&trc=256 http://www.cvedetails.com/product-list/product_type-/firstch...
- faragon 11y agoWhy? Is Oracle "sacred" or something?
- vlunkr 11y agoThe author did refer to the act of reverse engineering their code as "sinning". So yes.
- baseballmerpeak 11y ago404 Error now http://webcache.googleusercontent.com/search?q=cache:https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t http://webcache.googleusercontent.com/search?q=cache:https:/...
- HelloNurse 11y agoThe post seems real, by comparison with other articles in the blog: in particular similar silliness and dislike for security advisories in https://blogs.oracle.com/maryanndavidson/entry/is_your_shellshocked_poodle_freaked https://blogs.oracle.com/maryanndavidson/entry/is_your_shell... and similar anti-reverse engineering stance in https://blogs.oracle.com/maryanndavidson/entry/mandated_third_party_static_analysis https://blogs.oracle.com/maryanndavidson/entry/mandated_thir... and https://web.archive.org/web/20140123033110/https://blogs.oracle.com/maryanndavidson/entry/those_who_can_t_do https://web.archive.org/web/20140123033110/https://blogs.ora...
- jaawn 11y agoI don't really see how a lot of the responses here match with the original blog post. People seem to be airing a lot of long-standing grievances about Oracle rather than responding to the specific post on its own. Viewed on its own, the post can basically be summarized as "Please stop treating our products like they are open source. They're not, and it is against the license agreement to reverse engineer our stuff to find the source code." A lot of people think open source software is a much better methodology than proprietary, highly-protected source code. That's fine, there are a lot of good arguments there. However, it doesn't make sense to throw a bunch of other, barely related insults at a company when really, all you're upset about is that their code is not open source. Criticize that...that is what you're upset about (at least so far as this specific blog post is concerned)
- sklogic 11y agoNo, it got nothing to do with open source. Reverse engineering and pen testing the binary, closed source software is a standard practice and in many countries it is illegal not to allow doing it.
- jaawn 11y agoReverse engineering software is completely different from penetration testing, and it is the reverse engineering bit that Oracle has an issue with. They mostly just don't want anyone/everyone trying to recreate their source code because of copyright/intellectual property concerns (note: I do not agree with those, but that is Oracle's stance). It doesn't make sense for it to be illegal to forbid reverse engineering in a license agreement, where is that the case? If that is the legal environment anywhere, it would make more sense to just forbid closed source software. It would save a ton of time and effort and achieve the same goal. And by the way, it has everything to do with open source. If the code was open, you wouldn't need to reverse engineer it. Every security analyst could just review the code directly and search for vulnerabilities. The whole disagreement stems from Oracle (and the author) deciding that they want protected, closed source because they view it as intellectual property, while some of their customers feel they can't depend on that software unless they verify it themselves. Well...you can't fully verify closed source software yourself. It is really a very simple and fundamental disagreement on this one topic that creates the whole issue. It is completely valid to disagree with Oracle on this, and to tell Oracle you disagree with them. However, rather than violating their agreement, it would make more sense to decide to use an open source solution instead.
- tux 11y agoMirror: https://archive.is/iz4H2 https://archive.is/iz4H2
- beedogs 11y ago404 now... looks like somebody's gotten word of it...
- anonu 11y agoIf you look back at the author's earlier blog posts you'll find similarly-minded thoughts: https://blogs.oracle.com/maryanndavidson/entry/mandated_third_party_static_analysis https://blogs.oracle.com/maryanndavidson/entry/mandated_thir...
- nashashmi 11y agoWhat a bully! Reminds of someone at work, especially with this line: "I do not need you to analyze the code since we already do that, it’s our job to do that, we are pretty good at it". This makes me want to climb the empire state building, beat my chest like a gorrilla, and yell "Let me do what I know best!"
- selimthegrim 11y agoIs this woman aware that static analysis is a non-negotiable requirement for filing your 510(k) if you do anything vaguely medical the FDA has to look at? Not that I would willingly choose Oracle for medical device applications, but the cognitive dissonance here is amusing. Pax vobsicum indeed.
- Sanddancer 11y agoThey do use static analysis. However, they do not let third parties analyze their source code. Which shows even more hubris, because they're all but saying, "only we're smart enough to analyze our code."
- hgears 11y agoOriginal has been deleted, cached version available: http://webcache.googleusercontent.com/search?q=cache:ntXM0RlghUUJ:https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t+&cd=1&hl=en&ct=clnk&gl=us http://webcache.googleusercontent.com/search?q=cache:ntXM0Rl...
- extc 11y agoAnd just in case: http://pastebin.com/raw.php?i=fAh2fcfn http://pastebin.com/raw.php?i=fAh2fcfn
- f00644 11y agoFOUR OH FOUR, Guess it's over....
- DannyBee 11y agoExcept, uh, in plenty of countries, those anti-reverse engineering clauses are void as a matter of public policy. And in any product that uses LGPL code, for example, it's actually a license violation to forbid customer modification and reverse engineering for the purpose of debugging those modifications. (Though, admittedly, everyone always violates this term)
- eastbayjake 11y agoWhen I read this, I thought for sure it was just a lower-level engineering manager. I can't believe she's the Chief Security Officer, and that someone with a Wharton MBA could write something so unprofessional and full of disdain for your customers.
- Simulacra 11y agoThis makes me want to reverse engineer Oracle code immediately.
- dr_zoidberg 11y agoWhile I admit that I didn't read the whole post (to me it was a wall of text full of complaints going around the same point, always saying the same without too much variation), I really don't get this obsession with reverse engineering. Yes, their license agreement states that it can't be done. But you deploy code, executable code, but still code. Code that people can understand, if they go through the process of analyzing it. While I don't endorse breaking the agreement (which was properly signed and "celebrated", as lawyers say), I find it funny in the first place that they're selling a glass container and say "you can't look into it, just use it". I prefer the honesty of free software/open source projects that sell customer support to this business model (which is also adopted by others, not just Oracle). However, if I were already bound to it, and couldn't pay the cost of migration, I understand I'd have to stick with it. It's also amusing that people/organizations seriously believe they can reverse engineer something as complex as a database engine and "fix it" without acces to the diagramas, docs, tests, source code, build environment, etc.
- sprayk 11y agoI'm not sure what the author's argument is here. Is me reversing simply a nuisance and waste of Oracle's time? Is Oracle trying to obtain security via contractual obscurity? I see lots of comments here proposing that Oracle is protecting its IP, but I don't see evidence for that in the article (maybe its elsewhere, though). I wonder if Oracle would send one of those reminders to a customer who analyzed an attack by an attacker who "broke the license agreement" by reversing the customer's copy of some Oracle software.
- vlunkr 11y agoWhew. I've never read something from a company that was so insulting to it's own customers. I'd wager a bet that they won't be keeping their job for long.
- hharnisch 11y agoThis appears to have been taken down, I'm directed to a 404 page
- kuschku 11y agoDid anyone notice that the post contains Microsoft Office Word metadata? http://hastebin.com/daxiyaguma.html http://hastebin.com/daxiyaguma.html
- pronoiac 11y agoIt's been deleted. Here's a mirror: https://web.archive.org/web/20150811052336/https://blogs.oracle.com/maryanndavidson/entry/no_you_really_can_t https://web.archive.org/web/20150811052336/https://blogs.ora... - and while it's full of cringeworthy analogies, such as breaking a contract is just like cheating on your spouse, there's also, well, "logic" that defies conventional wisdom: Q. But one of the issues I found was an actual security vulnerability so that justifies reverse engineering, right? A. Sigh. At the risk of being repetitive, no, it doesn’t, just like you can’t break into a house because someone left a window or door unlocked. I’d like to tell you that we run every tool ever developed against every line of code we ever wrote, but that’s not true. We do require development teams (on premises, cloud and internal development organizations) to use security vulnerability-finding tools, we’ve had a significant uptick in tools usage over the last few years (our metrics show this) and we do track tools usage as part of Oracle Software Security Assurance program. We beat up – I mean, “require” – development teams to use tools because it is very much in our interests (and customers’ interests) to find and fix problems earlier rather than later. That said, no tool finds everything. No two tools find everything. We don’t claim to find everything. That fact still doesn’t justify a customer reverse engineering our code to attempt to find vulnerabilities, especially when the key to whether a suspected vulnerability is an actual vulnerability is the capability to analyze the actual source code, which – frankly – hardly any third party will be able to do, another reason not to accept random scan reports that resulted from reverse engineering at face value, as if we needed one. Q. Hey, I’ve got an idea, why not do a bug bounty? Pay third parties to find this stuff! A. <Bigger sigh.> Bug bounties are the new boy band (nicely alliterative, no?) Many companies are screaming, fainting, and throwing underwear at security researchers to find problems in their code and insisting that This Is The Way, Walk In It: if you are not doing bug bounties, your code isn’t secure. Ah, well, we find 87% of security vulnerabilities ourselves, security researchers find about 3% and the rest are found by customers. (Small digression: I was busting my buttons today when I found out that a well-known security researcher in a particular area of technology reported a bunch of alleged security issues to us except – we had already found all of them and we were already working on or had fixes. Woo hoo!) I am not dissing bug bounties, just noting that on a strictly economic basis, why would I throw a lot of money at 3% of the problem (and without learning lessons from what you find, it really is “whack a code mole”) when I could spend that money on better prevention like, oh, hiring another employee to do ethical hacking, who could develop a really good tool we use to automate finding certain types of issues, and so on. This is one of those “full immersion baptism” or “sprinkle water over the forehead” issues – we will allow for different religious traditions and do it OUR way – and others can do it THEIR way. Pax vobiscum.
- deleted 11y ago[deleted]
- sada123 11y agoThat's why everybody sane should avoid using Oracle or Microsoft for the sake of mental health.
- patmcguire 11y agoIf you read what else she's written, static analysis is kind of her Moby Dick.
- dgarbvt 11y agoOracle took down the blog post. Link is now returning a 404.
- lwhalen 11y agoSome media flack must've clapped eyes on that and had a VERY bad morning. The post has since been taken down, but here's a copy: http://pastebin.com/RQA90EEb http://pastebin.com/RQA90EEb
- deleted 11y ago[deleted]
- ilaksh 11y agoReason #78,429 to join the I-hate-Oracle-club http://forums.thedailywtf.com/forums/17.aspx http://forums.thedailywtf.com/forums/17.aspx https://what.thedailywtf.com/t/please-stop-poking-holes-in-our-cardboard-security/50505 https://what.thedailywtf.com/t/please-stop-poking-holes-in-o...
- minusSeven 11y agoI worked in Oracle SOA product(BPEL) for 2 years. We had to do migration from 10g to 11g because Oracle wasn't supporting 10g version anymore. While migrating we came across a lot of issues that worked fine with 10g but failed in 11g. So we raised a lot of service requests with Oracle. Most of those got rejected by Oracle as they were not high priority meaning there were terrible workarounds existing for them. They only bothered fixing those ones without which we can't work(I guess they had to or my company would have sued Oracle). We ended up writing a lot of horrible work around just to make existing code work. Yes we did not reverse engineer that code even though I feel it would have done lot of good for us. Not to mention the tool set provided by Oracle is utter crap as in it barely works on its own. So I am not at all surprised that Oracle have that kind of mentality here. In all our communications with Oracle I felt they never really actually cared for what we the customers really want. All they actually care about it protecting their investments.
- Orinocco 11y agoThe article seems to have been taken down from the Oracle site.. I leave this from an unclosed tab for posterity: http://pastebin.com/hU1mg1K9 http://pastebin.com/hU1mg1K9
- digi_owl 11y agoOracle seems to be like MS in that their reason for existing is that they came to be at the right time at the right place, and has pulled every trick in the book to pull up ladders behind themselves.
- imadfy 11y agohttp://ismaryanndavidsonfiredyet.com/ http://ismaryanndavidsonfiredyet.com/
- joeyespo 11y agoDoesn't antivirus software do static analysis?