Live data from Hacker News

“Stop reverse engineering our code”

blogs.oracle.com

141–150 of 358 posts

Re: “Stop reverse engineering our code”

#142
post #138
post #57

Earlier quoted context omitted.

> Why is Oracle even allowing this person to be a voice for their brand? Because her text will probably only infuriate people that will arguably never be Oracle customers?

I can only assume you've never dealt with Oracle. This is Oracle. Once your business is reliant on their products, this is how they act, because they can.

Could this rather be a reply to https://news.ycombinator.com/item?id=10040366 ?

Re: “Stop reverse engineering our code”

#143
post #137
post #132

I don't really see how a lot of the responses here match with the original blog post. People seem to be airing a lot of long-standing grievances about Oracle rather than responding to the specific post on its own. Viewed on its own, the post can basically be summarized as "Please stop treating our products like they are open source. They're not, and it is against the license agreement to reverse engineer our stuff to…

What was most astonishing to me about the post was the tone, which I found extremely condescending and unprofessional. The content was more or less par for the course, though I of course disagree (as do most tech folk).

That's a fair point, but it is a blog post, which implies that the tone will be more personal and informal. The author stated a few times that these were her personal views. I took it more as frustrated rather than condescending. I don't agree with what she said, but I recognize that the disagreement stems from one fundamental thing: open source vs. closed source.

Re: “Stop reverse engineering our code”

#144

Earlier quoted context omitted.

who knows – in many ways it's even better if it's satire, because it's just believable enough.

If it didn't have a 'most likely' in it I'd think it was satire, but that's the kind of weasel wording that you'd expect in a real release. There was another post in much the same vein on that blog: https://blogs.oracle.com/maryanndavidson/entry/those_who_can...

"Fixability. Only Oracle can fix vulnerabilities: SASO cannot. We have the code: they don’t."

Just one of many nuggets in this other arrogant posting. If somebody needs input why FOSS is better than closed source have a look into this one also.

Re: “Stop reverse engineering our code”

#145
post #99

I read the blog, but now it's returning a 404? Did they take it down? If so, then somebody at Oracle realized that post reflected poorly on their organization. Perhaps there is some hope for Oracle yet.

Their IT probably have an automatic preemptive policy of 404'ing any pages that become "popular"--any such content is is pretty much guaranteed to reflect poorly on their organization. False positives can always be waved away by a euphemism for a transient technical error ex post facto.

Re: “Stop reverse engineering our code”

#147
post #132

I don't really see how a lot of the responses here match with the original blog post. People seem to be airing a lot of long-standing grievances about Oracle rather than responding to the specific post on its own. Viewed on its own, the post can basically be summarized as "Please stop treating our products like they are open source. They're not, and it is against the license agreement to reverse engineer our stuff to…

No, it got nothing to do with open source. Reverse engineering and pen testing the binary, closed source software is a standard practice and in many countries it is illegal not to allow doing it.

Reverse engineering software is completely different from penetration testing, and it is the reverse engineering bit that Oracle has an issue with. They mostly just don't want anyone/everyone trying to recreate their source code because of copyright/intellectual property concerns (note: I do not agree with those, but that is Oracle's stance).

It doesn't make sense for it to be illegal to forbid reverse engineering in a license agreement, where is that the case? If that is the legal environment anywhere, it would make more sense to just forbid closed source software. It would save a ton of time and effort and achieve the same goal.

And by the way, it has everything to do with open source. If the code was open, you wouldn't need to reverse engineer it. Every security analyst could just review the code directly and search for vulnerabilities. The whole disagreement stems from Oracle (and the author) deciding that they want protected, closed source because they view it as intellectual property, while some of their customers feel they can't depend on that software unless they verify it themselves. Well...you can't fully verify closed source software yourself.

It is really a very simple and fundamental disagreement on this one topic that creates the whole issue. It is completely valid to disagree with Oracle on this, and to tell Oracle you disagree with them. However, rather than violating their agreement, it would make more sense to decide to use an open source solution instead.

Re: “Stop reverse engineering our code”

#148

This is exactly the problem with legality of RE and penetration testing. "You broke the law by wasting our time, violating your license agreement." I understand author's points. Not very good points, disappointingly. No matter how interpersonal she puts it. It makes me not ever want my system to rely on a company that threatens and belittle customers for protecting themselves. If I bought a fridge for my house, I fou…

> Yes, it's your product, but this is my home!

My stance is that EULAs are bullshit, period. If you purchase a product, it is yours, and no one should be able to dictate how you use it.

Re: “Stop reverse engineering our code”

#149
post #57

Earlier quoted context omitted.

> Why is Oracle even allowing this person to be a voice for their brand? Because her text will probably only infuriate people that will arguably never be Oracle customers?

> Because her text will probably only infuriate people that will arguably never be Oracle customers? As a sysadmin with customers who run oracle, and who put some stock in what I say, I can say I am more likely to warn people away from oracle in the future. While in some companies, tech purchasing decisions are made by suits with little or no input from techies, that's not universal.

If Oracle won't sick the sales people on your upper managers if they even get wind that someone at the company want's to move away, you're just not a large enough customer and Oracle doesn't give a shit if you move.
Post reply on HN