11 ms·
Oracle attempt to hide cybersecurity incident from customers?
- LZ_Khan 2y agoAnnnnd this is why Google bought Wiz huh.
- layman51 2y agoThe scary thing is that Oracle is able to take down items from Archive.org.
- abeyer 2y agohttps://help.archive.org/help/how-do-i-request-to-remove-something-from-archive-org/ https://help.archive.org/help/how-do-i-request-to-remove-som...
- MPSFounder 2y agoOracle is notoriously stingy. They'd rather lose the data, pay a fine and deny it happened (settle), than own up for it.
- deleted 2y ago[deleted]
- richwater 2y agoPretty on par for what I expect from Oracle. I'm surprised there's no corporate contracts involved yet.
- neuroelectron 2y agoThe hacker is following a number of corporations. Is it an empty threat or a hint? https://imgur.com/a/IsksRrZ https://imgur.com/a/IsksRrZ
- ziddoap 2y agoNeither. I would not read anything into a random hacker's twitter follow list.
- NickC25 2y agohow is that not securities fraud? they are under legal obligation to tell investors about this sort of shit.
- rubiquity 2y agoWelcome to the (most recent) era of deregulation. Get ready for all Fortune 500s to deny, deny, deny, and bribe.
- deleted 2y ago[deleted]
- mentalgear 2y agoCrypto is a prime asset for bribing. Not for nothing the president has his own shit coin.
- PenguinCoder 2y agoNot related to this story at all.
- _DeadFred_ 2y agoSometimes comments are made in relation to upstream comments. In this case "Welcome to the (most recent) era of deregulation. Get ready for all Fortune 500s to deny, deny, deny, and bribe."
- lucianbr 2y agoPresumably the requirements for public companies to disclose stuff and generally follow all kinds of rules were somehow for the health of the markets or something like that. I wonder how the markets will fare with the rules neutered. To be fair, they're trending down at the moment, so maybe there was something there. But truly only time will tell.
- zitsarethecure 2y agoIf no one enforces the law, it's not illegal.
- nerdjon 2y agoThis is honestly wild. Whether we like it or not security incidents have become such common place in the last several years that if they just admitted to it this entire story would have likely been shrugged off and mostly forgotten about in a couple days but instead it is turning into an entire thing that just seems to be getting deeper and deeper. (Not downplaying the security incident, but that is the unfortunate reality). Seriously if I can't trust that I am going to actually be told and not lied too when there is a security incident at the bare minimum, why would I chose to work with a company? What is Oracle's end goal here? Are they somehow really confident that this didn't happen, maybe they don't have the logs to confirm it? Trying to think about how this is anything except them just straight up lying. I can't remember the last time we saw a company this strongly try to deny that something like this happened. Especially when according to Ars Technica: > On Friday, when I asked Oracle for comment, a spokesperson asked if they could provide a statement that couldn’t be attributed to Oracle in any way. After I declined, the spokesperson said Oracle would have no comment.
- hdjjhhvvhga 2y agoThat's why in Europe there are strict laws regarding lax security of customer data and companies can be fined with a percentage of their turnover - which in the case of Oracle could hurt a bit.
- sofixa 2y ago> Seriously if I can't trust that I am going to actually be told and not lied too when there is a security incident at the bare minimum, why would I chose to work with a company? What is Oracle's end goal here? I think you're coming at this from the wrong point of view. Oracle couldn't care in the slightest about what regular people think of them. Remember, they are the company that sent lawyers after the employers of folks who downloaded non-free but bundled by default extensions to VirtualBox, and the company that declared that you need to license every core their software could _potentially_ run on in your virtualisation estate (so if you have a 8 vCPU VM for some Oracle software, you need licenses for however many physical cores you have on your cluster). They've variously been described as a law firm with an engineering side business, and One Rich Asshole Called Larry Ellisson. Speaking of whom, he multiple times flat out lied on stage to make his shitty "cloud" nobody cares about seem relevant compared to AWS. Nobody buys Oracle because they like them or their good reputation. You buy them because you have legacy stuff that depends on them and you have no choice (even Amazon took many years to get off Oracle databases, and they wrote a gloating success story one they were done with it because they were that happy to be rid of the leeches), or because your bosses' boss was convinced at a golf course they're getting a good deal. Or because their bandwidth is very cheap and you accept the risk of dealing with the devil incarnate with zero morals. (cf. Zoom). Oracle is like Broadcom. Everyone hates their guts, everyone who worked there has a black mark on their CV. Yet they persist, continue leeching off companies too scared to make the jump elsewhere.
- autoexec 2y agoThere are various state laws that require companies to notify their customers of security breaches, but they lack enforcement/teeth so they're routinely ignored. It'll never happen in our current environment but we really need a federal law that causes violators enough pain that companies will actually bother to follow the law.
- eru 2y agoI don't get your argument. Wouldn't adding teeth to the state laws be the right thing to do?
- autoexec 2y agoIt would help, but it'd be better for everyone if there was just one law to worry about which covered everyone (or at least set a minimum standard) rather than having 50 different versions of the same law all over the country each with their own definitions, thresholds, penalties, etc. It'd make things a lot less complicated for both companies and consumers, especially given how often a single company's data being exposed impacts people all over the nation.
- eru 2y agoYou don't like federalism much, do you? Btw, states already coordinate voluntarily on things like traffic signs, without there being a central authority. (That's both true for states in the US, and for different countries around the world. A stop sign looks pretty much nearly the same around the world, without any central authority enforcing that.)
- TrueDuality 2y agoWhile that's true, many enterprise customers are going to have MSAs with notification requirements that have contractual punishments for failure to notify of material security incidents. Those are probably what Oracle is trying to avoid.
- 2y ago
- mentalgear 2y agoAh, another notch in the belt for Larry Elison's Oracle data security scandals. Matches Larry's other political and societal scandals.
- jjice 2y agoTangential, but there’s an old interview with Ellison where he said that Amazon would never be able to get off of Oracle DB because it’s too critical a piece of software. This was in response to Amazon announcing it was something they had planned. Amazon got it done ahead of schedule and there’s a video of them popping champagne to celebrate when they shut the last server down. I’m not a big Amazon fan, but the enemy of my enemy is my friend.
- polski-g 2y agoLarry Ellison hasn't been CEO for over a decade.
- terom 2y agohttps://news.ycombinator.com/item?id=43486945 https://news.ycombinator.com/item?id=43486945 related
- islanderfun 2y agoPost-truth era is wild. But this seems like standard Oracle behavior for a while now.
- 1970-01-01 2y agoI hear fines are up to thousands of dollars now..
- compootr 2y agotens*
- mosura 2y ago[dead]
- homiedk 2y agoThe troubling aspect is (besides the denials of course) is the absence of controls that should have sniffed this out ASAP. Apparently: - no passive network monitors showing an unknown IP/Mac/Location - no SOAR to kill off the attempts to gain a foothold/move laterally - no alerts on above or anything else in the SOC
- tmpz22 2y agoIts times like this Oracle needs to lean on its good reputation and ask for forgiveness from the customers they've been loyal to for so long.
- mrbluecoat 2y ago> NetSuite will indemnify Customer up to an amount equal to five (5) times the equivalent of 12 months of license fees applicable at the time of the event, from and against any Losses incurred by Customer https://www.sec.gov/Archives/edgar/data/1428669/000119312508062588/dex1027.htm https://www.sec.gov/Archives/edgar/data/1428669/000119312508...
- legitster 2y agoIf you are already a customer of Oracle, I can't imagine this matters to you. You did not choose Oracle because it was a good product and they are a good company. You are a customer of Oracle because there was a backroom executive deal with the Devil. No one is surprised or outraged or even has any choices.
- protocolture 2y agoI was talking to a customer in a construction company that had its entire internal project management platform sold to Oracle. < This was why they couldnt manage their end of a large project. Oracle futzed it, and after a complete roll of the construction firms board of directors, they were in negotiations to buy their own program back for twice the price.
- BoppreH 2y agoI use Oracle Cloud for my personal projects because of their generous free tier[1] which includes 4x Ampere A1 cores, 24 GB of RAM, and 10 TB of outbound data transfer per month. I was ready to jump ship if they changed the terms, but I was not expecting a security incident. [1]: https://www.oracle.com/cloud/free/ https://www.oracle.com/cloud/free/
- noja 2y agoIf the tables were turned, Oracle would be taking advantage of the situation. Take note.
- redleggedfrog 2y agoAs my buddy from Oracle likes to say, "No one cares what we do as long as the flow of streak, coke, and strippers doesn't stop." He's a big Zed Shaw fan.
- FlyingSnake 2y agoI’m sorry but I don’t get this Zed Shaw reference, what did I miss?
- 2y ago
- aurizon 2y agoCreate a 'Wicki-hacks.com', like Wikipedia, where incidents are listed in detail - anonymously and indexed akin to Wikipedia with editors that create and verify an incident is such a way that Horacle etc can not deny or get it taken down
- prdonahue 2y agoWe're primarily an AWS shop but some Oracle BDR assigned to cover us recently reached out on LinkedIn. I asked for an incident report and received this terse response: > There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.
- blast 2y agoThat exact statement is quoted in the OP too.
- prdonahue 2y agoYeah, they've clearly been given some minimal company line and aren't deviating from it. Not going to win any trust.
- decimalenough 2y agoPer article, Oracle has hastily rebranded the breached service as "Oracle Classic", for the sole purpose of being able to claim with a straight face that "Oracle Cloud" was not impacted.
- smithkl42 2y agoFWIW, that doesn't appear to be a "hasty rebrand" - Oracle has had this distinction for a long time. https://docs.oracle.com/en/cloud/saas/enterprise-performance-management-common/cgsad/idcs_oci_classic_diffs.html https://docs.oracle.com/en/cloud/saas/enterprise-performance...
- decimalenough 2y agoThe hacker has demonstrated that they have/had write access to URLs under login.us2.oraclecloud.com. It's incredibly disingenuous on Oracle's part to claim that this is not "Oracle Cloud".
- xyst 2y agoThis is a deliberate attempt to cover up their incompetence. It should be criminal to deceive the public and your _paying_ customers. Executives need to go to jail. People need to be fired. This won’t happen though, definitely not under this current administration.