Live data from Hacker News

“Stop reverse engineering our code”

blogs.oracle.com

151–160 of 358 posts

Re: “Stop reverse engineering our code”

#151
post #19

The submitted title ('Oracle CSO: ~“Only we can do security, trust us and do not reverse engineer”') breaks the HN guidelines: it's editorialized (whatever one thinks of the article), and it's a quote-looking-thing that isn't a quote, so misleading. Please don't do this. The HN guidelines ask you to use the original title. If that's really not suitable, a subtitle or some representative language from the article is o…

[deleted]

Re: “Stop reverse engineering our code”

#153
post #147

Earlier quoted context omitted.

No, it got nothing to do with open source. Reverse engineering and pen testing the binary, closed source software is a standard practice and in many countries it is illegal not to allow doing it.

Reverse engineering software is completely different from penetration testing, and it is the reverse engineering bit that Oracle has an issue with. They mostly just don't want anyone/everyone trying to recreate their source code because of copyright/intellectual property concerns (note: I do not agree with those, but that is Oracle's stance). It doesn't make sense for it to be illegal to forbid reverse engineering in…

> Reverse engineering software is completely different from penetration testing

How is it so? You cannot find funny vulnerabilities without reverse engineering the binaries.

> It doesn't make sense for it to be illegal to forbid reverse engineering in a license agreement, where is that the case?

France, Switzerland, Russia and many more.

> it would make more sense to just forbid closed source software

How did you make this leap from reverse engineering to closed vs. open source?

> If the code was open, you wouldn't need to reverse engineer it.

Even with the full source available you still have to analyse (read: reverse-engineer) the binaries, especially those widely shipped.

> rather than violating their agreement

Their agreement is void in many countries where reverse engineering is explicitly allowed (when done for the reasons of security and interoperability).

Re: “Stop reverse engineering our code”

#154
post #80

Wow. Really? This single blog post is strong evidence for why you should never, ever buy an Oracle product, and if you are running anything written by them, why you should plan to migrate away. Now, the culture of consultants in the Oracle sphere of influence is pretty toxic and money-grubbing. I can imagine companies being badgered into paying security weasels big bucks to analyze software with tools that cough up a…

I went to a prominent tech school that adopted an Oracle platform for student course management in my last few years. I won't mince words: it was a piece of shit, and my school's administrators ate shit by agreeing to a contract that forbid them from making any changes to Oracle's broken system. Now I work in college administration and we have to deal with the very same pile of junk. Someone once told me that Larry E…

UMass Amherst was this side of non-functional for the first three days of the school year in 2005 because of a botched Peoplesoft (at that time recently purchased by Oracle) rollout.

http://www.cio.com/article/2439102/enterprise-resource-plann...

Re: “Stop reverse engineering our code”

#155

This is exactly the problem with legality of RE and penetration testing. "You broke the law by wasting our time, violating your license agreement." I understand author's points. Not very good points, disappointingly. No matter how interpersonal she puts it. It makes me not ever want my system to rely on a company that threatens and belittle customers for protecting themselves. If I bought a fridge for my house, I fou…

> Yes, it's your product, but this is my home! My stance is that EULAs are bullshit, period. If you purchase a product, it is yours, and no one should be able to dictate how you use it.

Unfortunately courts seem to not share your stance, it seems.

Re: “Stop reverse engineering our code”

#156
post #43
post #25

I laughed at this line where she tries to prove her point by touting that Oracle already found a bug that a security researcher reported to them (but wasn't fixed yet): "(Small digression: I was busting my buttons today when I found out that a well-known security researcher in a particular area of technology reported a bunch of alleged security issues to us except – we had already found all of them and we were alread…

heh, 'alleged'...

"They weren't real vulnerabilities, because we knew about them!"

Re: “Stop reverse engineering our code”

#157
What a bully! Reminds of someone at work, especially with this line: "I do not need you to analyze the code since we already do that, it’s our job to do that, we are pretty good at it".

This makes me want to climb the empire state building, beat my chest like a gorrilla, and yell "Let me do what I know best!"

Re: “Stop reverse engineering our code”

#158

> A. The customer signed the Oracle license agreement, and the consultant hired by the customer is thus bound by the customer’s signed license agreement. Otherwise everyone would hire a consultant to say (legal terms follow) “Nanny, nanny boo boo, big bad consultant can do X even if the customer can’t!” Really? What if no money changes hands?

No, she's utterly ignorant of contract law:

Privity is a doctrine in English contract law that covers the relationship between parties to a contract and other parties or agents. At its most basic level, the rule is that a contract can neither give rights to, nor impose obligations on, anyone who is not a party to the original agreement, i.e. a "third party".

Re: “Stop reverse engineering our code”

#159
post #71
post #35

This is a marketing layup for any FLOSS ERP company (or the PostgreSQLs of the world). Basically "by all means check our code for any issue you may find. We'll gladly accept any suggestions for code improvements you may have." This post is an absolute nightmare/facepalm. Basically my takeaway is "I guess I don't want to buy Oracle software". It's really mind blowing that this is the position of a major software compa…

If you dump a 400 page output dump of some static analysis tool on a FOSS project, not much will happen either. They will probably challenge you to find the actual issues yourself and enter bug reports.

Yes, but all other things equal, wouldn't you rather know what's in there?

Sun had an open bug database, it was glorious. That got snapped shut after purchase.

Re: “Stop reverse engineering our code”

#160
post #94

Earlier quoted context omitted.

I've recently read "The Difference Between God and Larry Ellison *God Doesn't Think He's Larry Ellison" and while it was published over 10 years ago, this sounds exactly like a lot of things that happened in the book. The Oracle corporate culture seems to basically be reflection of Larry Ellison's megalomania. Their will to rack sales is just insatiable.

You might enjoy this talk by Bryan Cantrill, where he describes the Oracle acquisition of Sun: https://www.youtube.com/watch?v=-zRN7XLCRhc&t=34m7s > "what you think of Oracle is even truer than you think it is. There has been no entity in human history with less complexity or nuance to it than Oracle" > "this company is about one man and his alter ego and what he wants to inflict upon humanity" Edit: And how could I…

You forgot the bit about "The Larry Ellison Institute for the Prolonging of Life: namely his"
Post reply on HN