An Information Security Place

Commentary on the State of Information Security
Filed under Pre-Categories


So Oracle decided to patch. I am not a Microsoft bigot by any means, but at least they patch monthly. Sheesh! What’s up, Mr. Ellison??? By the way, is Larry Ellison a little stuck on himself? Take a look at the picture on the right, then take a look at the picture at the link with his name above. Sheesh. But I digress…

Mike Fratto made a lot of sense when he had this to say:

“Oracle has a horrible track record in acknowledging and fixing problems. Peruse the advisories at NGS Software Ltd. or Red Database Security for Oracle issues and you will see that in many cases the time from vendor to notification to the time to patch is measures in months, sometimes over a year. We aren’t talking piddly little vulnerabilities either. These are pretty serious holes…. Kids, the database is where the data is! If the database gets owned, kiss your information goodbye. It’s time you Oracle software owners starting demanding faster patches from Oracle. “

I don’t use Oracle, but all this bloated, better-than-Microsoft stuff needs to be toned down in light of this kind of evidence. And this is out there, folks! The bloggers are on this, and it needs to be publicized even more! Oracle controls something like 40% or the market, the last I heard, so there is a big hole there.

Just remember, friends, DEFENSE-IN-DEPTH!!!

Vet

Posted by Michael Farnum on Monday, April 24th, 2006