Oracle customers confirm data stolen in alleged cloud breach is valid
41–50 of 85 posts
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#42Classic, Oracle denying breach despite clear evidence.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#43Earlier quoted context omitted.
I mean it's true that there's a rule, but at this point in US history I think we have reason to be sceptical that it will be enforced.
The SEC selectively enforcing the rule does not prohibit a shareholder suit against the company. "Everything Everywhere Is Securities Fraud" after all.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#44Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#45Earlier quoted context omitted.
7 days of revenue, 1 whole week out of 52 that all of your workforce production went to pay a fine? Yeah, that's quite noticeable for a corporation.
If this breach receives a fine in the top 5 fines ever issued in the entire history of GDPR enforcement . Don't forget to subtract out the money they saved from reduced investment in security over that time, as well. Noticeable? Sure. Nowhere near noticeable enough, though, in my opinion. Especially if we're serious about it and recognize this isn't going to be a top 5 fine.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#46Alone the fact that Oracle was hosting their login gateway on a product with a known vulnerability from 2021 with a CVSS score of 9.8 is quite disturbing.
Fun fact: Oracle has like 6+ LDAP/directory products, OAM is just one. Theres ODS, OIM, OID, OUD, OVD, NIS leftovers from Sun, and probably more honestly
OAM is an access management product, used to implement stuff like SSO (single sign-on). So, for example, it comes with a module you can install in Apache which will intercept HTTP requests and redirect them to OAM’s login page - which may potentially talk to an LDAP to authenticate you. Or you can do stuff like define some URL patterns in an app as sensitive so they require a more secure authentication mechanism (such as 2FA or smart card), other URL patterns as less sensitive so password-only login is sufficient
OIM is basically about provisioning accounts from a source system into target systems. Those systems could be LDAPs from various vendors, but can also be HR systems (Oracle’s various offerings and SAP too), IBM mainframes (RACF, TopSecret, ACF2), Unix/Linux hosts, database tables, custom apps… also lets you do things like setup workflows to approve system access requests, you can configure it to require reapproval of high risk access requests by management every X months or else they get revoked (used for Sarbanes-Oxley compliance), etc
Source: I used to work for Oracle Engineering, in a team which handled escalations for these products-especially OIM, but I stuck my fingers in most of them. When I left (back in 2017, so a while ago now) they were putting a lot of effort into their cloud offering (IDCS, more recently replaced by OCI IAM), but I’m sure the on-premise offerings are going to stick around for a long time, especially because they have some customers (e.g. in the national security space) for which cloud is unlikely to be a viable solution any time soon
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#47this incident certainly doesn’t help inspire confidence in their offerings.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#48Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#49Earlier quoted context omitted.
> It's not like there are any real penalties to a breach. Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach. There are fines (at least) if you don't disclose it afaik. Oracle is gonna have issue with the EU, most likely.
Maybe the EU wasn't on the Signal group chat when Oracle notified The Atlantic of the breach
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#50genuinely curious what kind of demographic is leveraging Oracle for cloud products — all I’ve heard about them suggests long-term pain. this incident certainly doesn’t help inspire confidence in their offerings.