Live data from Hacker News

“Stop reverse engineering our code”

blogs.oracle.com

291–300 of 358 posts

Re: “Stop reverse engineering our code”

#291
post #187
post #132

I don't really see how a lot of the responses here match with the original blog post. People seem to be airing a lot of long-standing grievances about Oracle rather than responding to the specific post on its own. Viewed on its own, the post can basically be summarized as "Please stop treating our products like they are open source. They're not, and it is against the license agreement to reverse engineer our stuff to…

I don't think it's the lack of open-source code that is causing the grievances but rather the tone of the blog post and the overall theme of "Our IP is more important then your security concerns, no we don't care if you are a core bank". Microsoft, SAP, VMware all have closed source software that is very prevalent in enterprise, often in entrenched positions just like Oracle. Sure they aren't exactly all peaches eith…

> Our IP is more important then your security concerns, no we don't care if you are a core bank

But that isn't what it says, at all. It even explicitly says that if you do find a security flaw this way they will still fix it.

But the main point is that you can't do anything by reverse engineering the source code that they aren't already doing, and doing better than you because they have the actual source code.

Re: “Stop reverse engineering our code”

#292
post #187
post #132

I don't really see how a lot of the responses here match with the original blog post. People seem to be airing a lot of long-standing grievances about Oracle rather than responding to the specific post on its own. Viewed on its own, the post can basically be summarized as "Please stop treating our products like they are open source. They're not, and it is against the license agreement to reverse engineer our stuff to…

I don't think it's the lack of open-source code that is causing the grievances but rather the tone of the blog post and the overall theme of "Our IP is more important then your security concerns, no we don't care if you are a core bank". Microsoft, SAP, VMware all have closed source software that is very prevalent in enterprise, often in entrenched positions just like Oracle. Sure they aren't exactly all peaches eith…

The blog post doesn't make me think of license-agreements-as-a-weapon. Oracle's position is probably the strictest I've seen anyone be in favor of software IP protection. They are not adversarial, they are supremely protectionist (presumably because they think their software is so great that other people want to copy it). That protection (possibly over-protection) is the core of the disagreement, and the source of the article's tone and inherent frustration on both sides.

Oracle thinks it is self-evident that protection of their source code is paramount (i.e. as closed source as possible), other people disagree both with their priorities and the very idea of absolutely forbidding any deep analysis of any kind outside of Oracle itself. It still seems like a debate about the degree to which the source code is "closed." For Oracle, it is absolutely closed, while many of their competitors are more lenient (i.e. slightly less "closed".)

To be clear, I think Oracle is being silly with their over-sanitized and idealistic views regarding their intellectual property. The other companies you mentioned (Microsoft et al) have much more reasonable approaches and agreements.

Re: “Stop reverse engineering our code”

#293

There are too many points to discuss... it's really quite insane especially on the backs of Java exploit after Java exploit. But what I really don't get is this bug bounty hateathon. If it's only 3% of bugs (currently WITHOUT incentives like a bug bounty), then that's really not that much money... and in return you get more cred, something you might use for recruitment, and the off chance that you might increase that…

> Java exploit after Java exploit

One zero day in 2 years. Not quite the disaster area it's made out to be on HN.

Re: “Stop reverse engineering our code”

#294
post #243
post #80

Wow. Really? This single blog post is strong evidence for why you should never, ever buy an Oracle product, and if you are running anything written by them, why you should plan to migrate away. Now, the culture of consultants in the Oracle sphere of influence is pretty toxic and money-grubbing. I can imagine companies being badgered into paying security weasels big bucks to analyze software with tools that cough up a…

This is hardly a first. Oracle stuffs a bad, misspelled little poem in their DB protocols, not for any technical reason, but purely to attempt to extend copyright protection by forcing people to violate their copyrights to be compatible with Oracle. You can find a copy of it here: http://dacut.blogspot.com/2008/03/oracle-poetry.html Note the copyright statement on the mispelled, 3-line poem with no literary merit wha…

I was going to post Sega v. Accolade after seeing the first three paragraphs of your post. Yeah. Copyright isn't functional, duplicating the poem to achieve functionality wouldn't violate copyright.

Re: “Stop reverse engineering our code”

#295
post #99

I read the blog, but now it's returning a 404? Did they take it down? If so, then somebody at Oracle realized that post reflected poorly on their organization. Perhaps there is some hope for Oracle yet.

Archive.org: http://web.archive.org/web/20150811052336/https://blogs.orac...

Re: “Stop reverse engineering our code”

#296
post #293

There are too many points to discuss... it's really quite insane especially on the backs of Java exploit after Java exploit. But what I really don't get is this bug bounty hateathon. If it's only 3% of bugs (currently WITHOUT incentives like a bug bounty), then that's really not that much money... and in return you get more cred, something you might use for recruitment, and the off chance that you might increase that…

> Java exploit after Java exploit One zero day in 2 years. Not quite the disaster area it's made out to be on HN.

http://www.cisco.com/web/offers/lp/2014-annual-security-repo...

"91% of web exploits are targeting Java"

Re: “Stop reverse engineering our code”

#297

Earlier quoted context omitted.

To put it another way: "pi is exactly 3" is extremely precise, but not very accurate.

The very next task of mine is a new value of pi to define. I think I'll use 3 it's much simpler you see; than 3.14159

You've simpified pi, that's fo' shore.

But rivalry says "level-up score".

With competitive drive,

It's yet higher I strive.

The value I'll use shall be four.

Re: “Stop reverse engineering our code”

#299

Earlier quoted context omitted.

The place where I work, regret a decision to use Oracle, our application build with Oracle Form Builder, which is awfully hard to use, broken easily. But I must admit, their pre-sales really good at describing their product, my boss really hooked up by them. "Oh, for that problem we have this, it will cost this much, but for now, you can just use it for free" then some wild invoice came to our office.

The dept I used to work at was mostly ex-B4 people and I later did enterprise consulting later: What happens is that sales people talk to people high enough up on the food chain that they get the run of the place, and so it's nearly impossible to kick them out or refuse their requests without a substantial political cost/justification. It's called "building a beachhead" and involves the engagement team worming their…

Dell Hell.

iSCSI purchase that was promised to be supported on CentOS (it wasn't: RHEL only, despite no deltas), and which Dell itself didn't understand. Ended up getting RHEL just to get a comparison baseline install.

At one point, got cussed out by Dell's support manager in the process (the front-line support team was good). The quote was "I'm not here to support you." Ultimately cost me my job (though we did get the product running).

I'm usually pretty free with sharing my documentation, but in this case made an exception: Dell's support was so fucking crap I refused to provide any assistance for them at all.

Re: “Stop reverse engineering our code”

#300
I worked in Oracle SOA product(BPEL) for 2 years. We had to do migration from 10g to 11g because Oracle wasn't supporting 10g version anymore. While migrating we came across a lot of issues that worked fine with 10g but failed in 11g. So we raised a lot of service requests with Oracle. Most of those got rejected by Oracle as they were not high priority meaning there were terrible workarounds existing for them. They only bothered fixing those ones without which we can't work(I guess they had to or my company would have sued Oracle). We ended up writing a lot of horrible work around just to make existing code work.

Yes we did not reverse engineer that code even though I feel it would have done lot of good for us. Not to mention the tool set provided by Oracle is utter crap as in it barely works on its own.

So I am not at all surprised that Oracle have that kind of mentality here. In all our communications with Oracle I felt they never really actually cared for what we the customers really want. All they actually care about it protecting their investments.

Post reply on HN