Live data from Hacker News

“Stop reverse engineering our code”

blogs.oracle.com

241–250 of 358 posts

Re: “Stop reverse engineering our code”

#241

Earlier quoted context omitted.

I worked for a large company which will remain unnamed, who a few years after purchasing a 12-year unlimited support contract, switched to using Postgres. Read: they were already locked in to paying for Oracle's most expensive contract for 12 years, regardless of what services they used. In short, they concluded that due to the cost of developing for Oracle, it was cheaper to migrate to Postgres than to continue usin…

It is somewhat rare that companies will recognize the fallacy of sunk costs ("We've already spent so much, we need to do this"). I think the world would be a much different place if we could somehow overcome this cognitive error.

makes for good examples that everyone can learn from

Re: “Stop reverse engineering our code”

#242
It's been deleted. Here's a mirror: https://web.archive.org/web/20150811052336/https://blogs.ora... - and while it's full of cringeworthy analogies, such as breaking a contract is just like cheating on your spouse, there's also, well, "logic" that defies conventional wisdom:

Q. But one of the issues I found was an actual security vulnerability so that justifies reverse engineering, right?

A. Sigh. At the risk of being repetitive, no, it doesn’t, just like you can’t break into a house because someone left a window or door unlocked. I’d like to tell you that we run every tool ever developed against every line of code we ever wrote, but that’s not true. We do require development teams (on premises, cloud and internal development organizations) to use security vulnerability-finding tools, we’ve had a significant uptick in tools usage over the last few years (our metrics show this) and we do track tools usage as part of Oracle Software Security Assurance program. We beat up – I mean, “require” – development teams to use tools because it is very much in our interests (and customers’ interests) to find and fix problems earlier rather than later.

That said, no tool finds everything. No two tools find everything. We don’t claim to find everything. That fact still doesn’t justify a customer reverse engineering our code to attempt to find vulnerabilities, especially when the key to whether a suspected vulnerability is an actual vulnerability is the capability to analyze the actual source code, which – frankly – hardly any third party will be able to do, another reason not to accept random scan reports that resulted from reverse engineering at face value, as if we needed one.

Q. Hey, I’ve got an idea, why not do a bug bounty? Pay third parties to find this stuff!

A. Bug bounties are the new boy band (nicely alliterative, no?) Many companies are screaming, fainting, and throwing underwear at security researchers to find problems in their code and insisting that This Is The Way, Walk In It: if you are not doing bug bounties, your code isn’t secure. Ah, well, we find 87% of security vulnerabilities ourselves, security researchers find about 3% and the rest are found by customers. (Small digression: I was busting my buttons today when I found out that a well-known security researcher in a particular area of technology reported a bunch of alleged security issues to us except – we had already found all of them and we were already working on or had fixes. Woo hoo!)

I am not dissing bug bounties, just noting that on a strictly economic basis, why would I throw a lot of money at 3% of the problem (and without learning lessons from what you find, it really is “whack a code mole”) when I could spend that money on better prevention like, oh, hiring another employee to do ethical hacking, who could develop a really good tool we use to automate finding certain types of issues, and so on. This is one of those “full immersion baptism” or “sprinkle water over the forehead” issues – we will allow for different religious traditions and do it OUR way – and others can do it THEIR way. Pax vobiscum.

Re: “Stop reverse engineering our code”

#243
post #80

Wow. Really? This single blog post is strong evidence for why you should never, ever buy an Oracle product, and if you are running anything written by them, why you should plan to migrate away. Now, the culture of consultants in the Oracle sphere of influence is pretty toxic and money-grubbing. I can imagine companies being badgered into paying security weasels big bucks to analyze software with tools that cough up a…

This is hardly a first. Oracle stuffs a bad, misspelled little poem in their DB protocols, not for any technical reason, but purely to attempt to extend copyright protection by forcing people to violate their copyrights to be compatible with Oracle.

You can find a copy of it here: http://dacut.blogspot.com/2008/03/oracle-poetry.html

Note the copyright statement on the mispelled, 3-line poem with no literary merit whatsoever (which happens to be longer than the poem itself):

"The preceding key is copyrighted by Oracle Corporation. Dupl@ication of this key is not allowed without permission from Oracl1e Corporation. Copyright 2003 Oracle Corporation."

The purpose of this is to abuse the copyright on the above "poem" in order to prevent people from implementing the Oracle DB protocols. I guess they hope that everyone is ignorant of Sega v. Accolade? Even that trick of theirs is copied from elsewhere:

https://en.wikipedia.org/wiki/Sega_v._Accolade

EDIT: Reading that deliberate misspelling makes me wonder if I could start "Oracl1e Corporation" and give people permission to violate this? Sure, it'd be a ridiculous cheat, but so is the sham copyright on their worthless poem.

Re: “Stop reverse engineering our code”

#244

Earlier quoted context omitted.

s/accuracy/precision Sorry, I don't usually try to be pedantic, but when the conversation is already about nitpicking, I think it's necessary. Significant figures are precision, not accuracy. Accuracy is "being in the ballpark". Precision is "tight groups".

I'm sorry for the confusion. English is not my first language, and I resorted to https://en.wikipedia.org/wiki/Accuracy_and_precision to pick between "accuracy" and "precision".

To put it another way: "pi is exactly 3" is extremely precise, but not very accurate.

Re: “Stop reverse engineering our code”

#245
post #48

Earlier quoted context omitted.

Sure, but this is a contract matter between two private entities. Oracle can still revoke your license for doing it.

I'm pretty certain that national law takes precedence over what someone put in a contract. Example: It works like this for tenancy agreements in Germany. Your landlord can say that you're not allowed to change the locks all they want, and even if it's in the tenancy and you signed it, it's still null and void.

>I'm pretty certain that national law takes precedence over what someone put in a contract.

Yes but only if the law says that you can't create a contact that signs away that right.

For example, in the USA you can reverse engineer. Totally legal. But you can also sign away your right to reverse engineer. That is what a contract is, signing away your rights.

But the US could also pass a law saying it's illegal for a EULA to prevent reverse engineering.

So just finding a law that says reverse engineering is legal, doesn't mean a court won't hold you to a contract that prevents reverse engineering.

That said, it's probable that some countries have banned contracts that prevent reverse engineering.

Re: “Stop reverse engineering our code”

#246

Earlier quoted context omitted.

I went to a prominent tech school that adopted an Oracle platform for student course management in my last few years. I won't mince words: it was a piece of shit, and my school's administrators ate shit by agreeing to a contract that forbid them from making any changes to Oracle's broken system. Now I work in college administration and we have to deal with the very same pile of junk. Someone once told me that Larry E…

> Larry Ellison is the biggest asshole in Silicon Valley, and also the richest, so he must be doing something right. This weekend I learned that Larry Ellison purchased ~90% of an island in Hawaii.

Bordering on Bond villain status at this point.

Re: “Stop reverse engineering our code”

#247

So, I disagree with the poster on a bunch of things here (no surprise, really). But: this is authentic. This is what we (i.e. hackers) are always claiming we want. Someone speaking her mind, shooting from the hip, etc. Not an anodyne blob of corporate-speak: this is an opinion, stated pretty clearly, and backed up with fighting words. You'd expect: "Our legal team has advised us to remind consultants that they are bo…

If someone does one thing you like, among a bunch of other things you don't like, you can still complain about all the other stuff.

It's like if I say I wish people would stop murdering people with guns so much, then I get stabbed in the chest and you say, hey, isn't this what you want, people not using guns?

Re: “Stop reverse engineering our code”

#248

Earlier quoted context omitted.

I went to a prominent tech school that adopted an Oracle platform for student course management in my last few years. I won't mince words: it was a piece of shit, and my school's administrators ate shit by agreeing to a contract that forbid them from making any changes to Oracle's broken system. Now I work in college administration and we have to deal with the very same pile of junk. Someone once told me that Larry E…

UMass Amherst was this side of non-functional for the first three days of the school year in 2005 because of a botched Peoplesoft (at that time recently purchased by Oracle) rollout. http://www.cio.com/article/2439102/enterprise-resource-plann...

Hah! The guys at SFSU somehow forgot that. They just implemented a Peoplesoft last year, now a part of Oracle since forever, so no excuses for how badly it works.

Re: “Stop reverse engineering our code”

#249

Earlier quoted context omitted.

You might want to fact check yourself on Rockefeller: Founded 1870, antitrust 1911: https://en.wikipedia.org/wiki/Standard_Oil Crude prices in that time frame (and beyond): https://commons.wikimedia.org/wiki/File:Oil_Prices_Since_186... Production in that time frame (having trouble finding a nice long time-series chart): https://en.wikipedia.org/wiki/History_of_the_petroleum_indus... If we want to make a strong claim…

According to the very Wikipedia article you link, Standard Oil was found guilty of anticompetitive actions. Note that monopolistic behavior does not necessarily imply rising prices. See: Wal-Mart. Also see this quote from that Wikipedia article again: "The evidence is, in fact, absolutely conclusive that the Standard Oil Co. charges altogether excessive prices where it meets no competition, and particularly where the…

Without any comment on the business practices of Standard Oil, I do think it's interesting that the price of crude actually increased substantially after the antitrust ruling.

Re: “Stop reverse engineering our code”

#250
post #69

Earlier quoted context omitted.

She has no idea what she is talking about. Nobody is running static analysis on source code and sending her results. She's mixed up a lot of concepts here and is just plain wrong.

You can statically analyze a binary as well. "Static analysis" is just a technique for deducing the properties of a system without running it.

I know what static analysis is.
Post reply on HN