Live data from Hacker News

Oracle attempt to hide cybersecurity incident from customers?

doublepulsar.com

121–130 of 136 posts

Re: Oracle attempt to hide cybersecurity incident from customers?

#121

Earlier quoted context omitted.

Per article, Oracle has hastily rebranded the breached service as "Oracle Classic", for the sole purpose of being able to claim with a straight face that "Oracle Cloud" was not impacted.

FWIW, that doesn't appear to be a "hasty rebrand" - Oracle has had this distinction for a long time. https://docs.oracle.com/en/cloud/saas/enterprise-performance...

The hacker has demonstrated that they have/had write access to URLs under login.us2.oraclecloud.com. It's incredibly disingenuous on Oracle's part to claim that this is not "Oracle Cloud".

Re: Oracle attempt to hide cybersecurity incident from customers?

#122

Earlier quoted context omitted.

> arms manufacturer in payroll or something: you're not directly responsible for killing millions of people, but by choosing to work there you're still kind of condoning it. It morbidly amuses me that this kind of argument can still be made given what's going on in Ukraine. Governments have militaries for a reason, and there's a reason Europe is now scrambling to re-arm itself.

Governments have militaries for many reasons. If you work at a US arms manufacturer, some of your output may indeed being going to defend Ukraine, but some of it is also going to the Israeli military in Gaza, the Saudi Arabian military in Yemen, and a long, long list of countries listed here: https://en.wikipedia.org/wiki/United_States_military_aid

See how the goalposts now move from "arms manufacturer in general" to "I don't agree with US foreign policy."

And even assuming that's true for the sake of argument, what? Lockheed Martin, Raytheon, et al. are just supposed to shut down for good the moment one politician makes a morally questionable decision? Life is not that black and white.

Re: Oracle attempt to hide cybersecurity incident from customers?

#123

Earlier quoted context omitted.

As my buddy from Oracle likes to say, "No one cares what we do as long as the flow of streak, coke, and strippers doesn't stop." He's a big Zed Shaw fan.

Anytime Oracle is brought up is a great time to repost the famous Lawnmower quote: > "As you know people, as you learn about things, you realize that these generalizations we have are, virtually to a generalization, false. Well, except for this one, as it turns out. What you think of Oracle, is even truer than you think it is. There has been no entity in human history with less complexity or nuance to it than Oracle.…

"Everyone Else Must Fail" is a good read.

Re: Oracle attempt to hide cybersecurity incident from customers?

#124
post #60

Earlier quoted context omitted.

I haven’t seen the ads, but Oracle Cloud is definitely the public cloud provider with the most generous free tier. That’s not to say you should use and trust them, but I can see why many would.

My personal multicloud strategy for many years was to make full use of the free tier on as many providers as necessary.

Making a cloud provider that just wraps other providers' free tiers would be a fun challenge.

Re: Oracle attempt to hide cybersecurity incident from customers?

#125

Earlier quoted context omitted.

Governments have militaries for many reasons. If you work at a US arms manufacturer, some of your output may indeed being going to defend Ukraine, but some of it is also going to the Israeli military in Gaza, the Saudi Arabian military in Yemen, and a long, long list of countries listed here: https://en.wikipedia.org/wiki/United_States_military_aid

See how the goalposts now move from "arms manufacturer in general" to "I don't agree with US foreign policy." And even assuming that's true for the sake of argument, what? Lockheed Martin, Raytheon, et al. are just supposed to shut down for good the moment one politician makes a morally questionable decision? Life is not that black and white.

You're inventing your own goal posts here, since I didn't say anything of the sort.

To repeat: if you work for an arms manufacturer, you condone killing people. Hopefully it's because you think the weapons are killing enough Nazis/terrorists/bad guys to outweigh the occasional innocent civilian, but their blood is still on your hands.

Re: Oracle attempt to hide cybersecurity incident from customers?

#126

Earlier quoted context omitted.

I didn't make any claims about performance per $, just relative performance compared to VMs. I hate Oracle as much as anyone but the EXADATA is impressive hardware. It has lots of RAM and Infiniband networking. It can push query predicates to the storage controllers to reduce the data that had to be transferred.

It is impressive. But for the same cost you can get vastly better performance with Postgres and bigger hardware. It does come with internal redundancy, but do you need that? Also the cluster nature of it can come with some surprises as compared to a single database.

Yes. DB2 on IBM z/OS is also very expensive.

Re: Oracle attempt to hide cybersecurity incident from customers?

#127
post #116

Earlier quoted context omitted.

As my buddy from Oracle likes to say, "No one cares what we do as long as the flow of streak, coke, and strippers doesn't stop." He's a big Zed Shaw fan.

The problem is the people who have to use Oracle aren't the ones getting the steak or strippers.

Isn’t that a feature?

Re: Oracle attempt to hide cybersecurity incident from customers?

#128
post #4

how is that not securities fraud? they are under legal obligation to tell investors about this sort of shit.

They are indeed under a legal obligation to disclose "material" cybersecurity incidents. For people who want to see the details, here's the SEC release https://www.sec.gov/newsroom/press-releases/2023-139 Now will the SEC enforce against oracle? In this environment I highly doubt anyone at the SEC would have the appetite but I could be wrong. So will any investors with standing choose to bring a civil action? Could w…

The SEC no longer exists. The billionaires like Elison completely own the US government right now.

Re: Oracle attempt to hide cybersecurity incident from customers?

#129

If you are already a customer of Oracle, I can't imagine this matters to you. You did not choose Oracle because it was a good product and they are a good company. You are a customer of Oracle because there was a backroom executive deal with the Devil. No one is surprised or outraged or even has any choices.

I use Oracle Cloud for my personal projects because of their generous free tier[1] which includes 4x Ampere A1 cores, 24 GB of RAM, and 10 TB of outbound data transfer per month.

I was ready to jump ship if they changed the terms, but I was not expecting a security incident.

[1]: https://www.oracle.com/cloud/free/

Re: Oracle attempt to hide cybersecurity incident from customers?

#130
post #50
post #16

Earlier quoted context omitted.

> Seriously if I can't trust that I am going to actually be told and not lied too when there is a security incident at the bare minimum, why would I chose to work with a company? What is Oracle's end goal here? I think you're coming at this from the wrong point of view. Oracle couldn't care in the slightest about what regular people think of them. Remember, they are the company that sent lawyers after the employers o…

> everyone who worked there has a black mark on their CV I hope this is hyperbole. Rank and file employees are not responsible for corporate policy or direction, especially in places like Oracle.

They're not responsible for the policy, but typically when you're thinking of a job at Oracle, you likely can have other options. At least if we're taking about software engineers and similar people. I was being recommended for a position by friends who moved there and I refused, because it's a shit company. The money is not worth it. It's the whole "contractors on Death Star" thing from Clerks.
Post reply on HN