Live data from Hacker News

Oracle attempt to hide cybersecurity incident from customers?

doublepulsar.com

111–120 of 136 posts

Re: Oracle attempt to hide cybersecurity incident from customers?

#111
post #42
post #7

This is honestly wild. Whether we like it or not security incidents have become such common place in the last several years that if they just admitted to it this entire story would have likely been shrugged off and mostly forgotten about in a couple days but instead it is turning into an entire thing that just seems to be getting deeper and deeper. (Not downplaying the security incident, but that is the unfortunate r…

Security incidents have become so common place that the fact that they happen is not the newsworthy event; rather, its how a company responds to them that is the newsworthy event. And Oracle flunked this test

My guess is that admitting a security incident triggers lots of contractual clauses.

They have probably decided it's cheaper to simply deny the event (therefore not triggering those clauses).

If it gets to court, Oracle will find some expert who says there was no incident, and the other side will present clear evidence there was an incident, but the non-technical judge will probably still not be sure.

Re: Oracle attempt to hide cybersecurity incident from customers?

#112
post #85

Earlier quoted context omitted.

You pay in other ways. I understand if you have absolutely no money, but even then repeatedly trying to provision a server and getting a error- something like no capacity available - isn't a fun time. Whatever, I'll pay 7$ a month to not deal with that.

You can automate it using their API and some Python. It's like a puzzle game and I'm personally thankful for the free tier, it's pretty cool if you max it out you have multiple IPv4 addresses, IPv6 prefixes and so on - the machines boot via UEFI, you can run nixos and ZFS on them, you have a serial console via ssh/vnc and at least in Germany they have good connectivity and 10tb Traffic is plenty. Using it for somethi…

I had a script calling their apis to setup one of their free arm instances after I deleted the one I had to change the OS (something I had done before).

After running every hour for several months I gave up (always out of capacity and it was impossible to change the region on free tier back then). They either had a bug that still showed my account as using the deleted resources or no capacity, both which seem out of place in a “cloud” infrastructure.

Re: Oracle attempt to hide cybersecurity incident from customers?

#114
post #82

Earlier quoted context omitted.

Anytime Oracle is brought up is a great time to repost the famous Lawnmower quote: > "As you know people, as you learn about things, you realize that these generalizations we have are, virtually to a generalization, false. Well, except for this one, as it turns out. What you think of Oracle, is even truer than you think it is. There has been no entity in human history with less complexity or nuance to it than Oracle.…

You elided the most famous quote from that diatribe. The lawnmower comparison is the expansion on: "Do not fall into the trap of anthropomorphizing Larry Ellison"

Indeed it's hard to explain how he can be 80 years old and look like this:

https://en.wikipedia.org/wiki/File:Larry_Ellison_-_American_...

Re: Oracle attempt to hide cybersecurity incident from customers?

#115

Earlier quoted context omitted.

Lies. Fucking lies. We were a three environment shop until we moved to Exa and the compute/$ ratio is so bad that we had to cut it down to two. But we're talking about Oracle here so that's par for the course.

I didn't make any claims about performance per $, just relative performance compared to VMs. I hate Oracle as much as anyone but the EXADATA is impressive hardware. It has lots of RAM and Infiniband networking. It can push query predicates to the storage controllers to reduce the data that had to be transferred.

It is impressive. But for the same cost you can get vastly better performance with Postgres and bigger hardware.

It does come with internal redundancy, but do you need that? Also the cluster nature of it can come with some surprises as compared to a single database.

Re: Oracle attempt to hide cybersecurity incident from customers?

#116

If you are already a customer of Oracle, I can't imagine this matters to you. You did not choose Oracle because it was a good product and they are a good company. You are a customer of Oracle because there was a backroom executive deal with the Devil. No one is surprised or outraged or even has any choices.

As my buddy from Oracle likes to say, "No one cares what we do as long as the flow of streak, coke, and strippers doesn't stop." He's a big Zed Shaw fan.

The problem is the people who have to use Oracle aren't the ones getting the steak or strippers.

Re: Oracle attempt to hide cybersecurity incident from customers?

#117
post #42
post #7

This is honestly wild. Whether we like it or not security incidents have become such common place in the last several years that if they just admitted to it this entire story would have likely been shrugged off and mostly forgotten about in a couple days but instead it is turning into an entire thing that just seems to be getting deeper and deeper. (Not downplaying the security incident, but that is the unfortunate r…

Security incidents have become so common place that the fact that they happen is not the newsworthy event; rather, its how a company responds to them that is the newsworthy event. And Oracle flunked this test

Note that it was an almost 4 year old already disclosed CVE which was used. Oracle messed up, big time. That's why they're trying to get rid of all incriminating evidence for potential lawsuits.

https://nvd.nist.gov/vuln/detail/cve-2021-35587

Re: Oracle attempt to hide cybersecurity incident from customers?

#118

We're primarily an AWS shop but some Oracle BDR assigned to cover us recently reached out on LinkedIn. I asked for an incident report and received this terse response: > There has been no breach of Oracle Cloud. The published credentials are not for the Oracle Cloud. No Oracle Cloud customers experienced a breach or lost any data.

Per article, Oracle has hastily rebranded the breached service as "Oracle Classic", for the sole purpose of being able to claim with a straight face that "Oracle Cloud" was not impacted.

FWIW, that doesn't appear to be a "hasty rebrand" - Oracle has had this distinction for a long time.

https://docs.oracle.com/en/cloud/saas/enterprise-performance...

Re: Oracle attempt to hide cybersecurity incident from customers?

#119
post #82

Earlier quoted context omitted.

You elided the most famous quote from that diatribe. The lawnmower comparison is the expansion on: "Do not fall into the trap of anthropomorphizing Larry Ellison"

Indeed it's hard to explain how he can be 80 years old and look like this: https://en.wikipedia.org/wiki/File:Larry_Ellison_-_American_...

Botox, DHEA, collagen, plastic surgery...

Re: Oracle attempt to hide cybersecurity incident from customers?

#120
post #82

Earlier quoted context omitted.

You elided the most famous quote from that diatribe. The lawnmower comparison is the expansion on: "Do not fall into the trap of anthropomorphizing Larry Ellison"

Indeed it's hard to explain how he can be 80 years old and look like this: https://en.wikipedia.org/wiki/File:Larry_Ellison_-_American_...

He is starting to look more and more like Donald Trump.
Post reply on HN