Live data from Hacker News

Oracle attempt to hide cybersecurity incident from customers?

doublepulsar.com

31–40 of 136 posts

Re: Oracle attempt to hide cybersecurity incident from customers?

#32
post #16
post #7

This is honestly wild. Whether we like it or not security incidents have become such common place in the last several years that if they just admitted to it this entire story would have likely been shrugged off and mostly forgotten about in a couple days but instead it is turning into an entire thing that just seems to be getting deeper and deeper. (Not downplaying the security incident, but that is the unfortunate r…

> Seriously if I can't trust that I am going to actually be told and not lied too when there is a security incident at the bare minimum, why would I chose to work with a company? What is Oracle's end goal here? I think you're coming at this from the wrong point of view. Oracle couldn't care in the slightest about what regular people think of them. Remember, they are the company that sent lawyers after the employers o…

My wife is a hospital pharmacist. Cerner is a poular EMR system, is ~#2 in the market (behind Epic). These systems are ridiculously difficult to change between (everyone from your front-check-in desk to every surgeon who has privileges needs to be trained on how the new system works in addition to the technical problems with ETL'ing all your data over, and each hospital has an enormous amount of customization done to their workflows that has to be ported over to the new system)- she's done that twice at two different places and it was a huge, process, 18 months minimum. So these EMR's have an enormous amount of lock-in.

The punchline is, in 2022 Oracle purchased Cerner, renamed it Oracle Health, and started accelerating the process of enshittifying it. I have to tip my hat to them, it's like their BizDev team found a market segment that had as much lock-in as SQL databases do, and are now trying to replicate all the evil tricks they learned from that in another market segment. Because what are hospitals but giant bags of money to be drained so Larry Ellison can buy another yacht?

Re: Oracle attempt to hide cybersecurity incident from customers?

#34

Earlier quoted context omitted.

Crypto is a prime asset for bribing. Not for nothing the president has his own shit coin.

Not related to this story at all.

Sometimes comments are made in relation to upstream comments. In this case

"Welcome to the (most recent) era of deregulation. Get ready for all Fortune 500s to deny, deny, deny, and bribe."

Re: Oracle attempt to hide cybersecurity incident from customers?

#36
post #28

Its times like this Oracle needs to lean on its good reputation and ask for forgiveness from the customers they've been loyal to for so long.

> Oracle needs to lean on its good reputation It's what now?

Something tells me parent implied the /s.

Re: Oracle attempt to hide cybersecurity incident from customers?

#37
post #4

how is that not securities fraud? they are under legal obligation to tell investors about this sort of shit.

They are indeed under a legal obligation to disclose "material" cybersecurity incidents. For people who want to see the details, here's the SEC release https://www.sec.gov/newsroom/press-releases/2023-139

Now will the SEC enforce against oracle? In this environment I highly doubt anyone at the SEC would have the appetite but I could be wrong.

So will any investors with standing choose to bring a civil action? Could well do it. There are for sure investors (eg Elliot) who in general would fight anyone at all if they thought they had a case. I don't know if there's anyone like that who had a position in Oracle specifically, but it wouldn't suprise me.

Re: Oracle attempt to hide cybersecurity incident from customers?

#38
post #14

Earlier quoted context omitted.

While that's true, many enterprise customers are going to have MSAs with notification requirements that have contractual punishments for failure to notify of material security incidents. Those are probably what Oracle is trying to avoid.

I believe enterprise customers are not going to care much unless it helps with lowering existing costs. OTOH, Oracle as part of BSA can demand an audit so they will inflict / make up reason to also punish (i.e. licensing or pull support). The business could invoke an MSA punishment clause and win temporarily but it will cause a headache going forward (further demands from Oracle, higher costs etc.) Either way, Oracle…

Unless the customer already wants to ditch Oracle.

Re: Oracle attempt to hide cybersecurity incident from customers?

#39
post #15
post #4

how is that not securities fraud? they are under legal obligation to tell investors about this sort of shit.

they likely aren't under an obligation to tell investors about it immediately and simply putting something in their quarterly report about it will probably be fine. That being said if they put something in some communication that said "we take security seriously" or something that would probably be grounds to sue as this obviously shows they aren't serious or something. The barriers to shareholder lawsuits for securi…

The SEC says they have 4 business days

"An Item 1.05 Form 8-K will generally be due four business days after a registrant determines that a cybersecurity incident is material. The disclosure may be delayed if the United States Attorney General determines that immediate disclosure would pose a substantial risk to national security or public safety and notifies the Commission of such determination in writing." (from https://www.sec.gov/newsroom/press-releases/2023-139)

Re: Oracle attempt to hide cybersecurity incident from customers?

#40
If you are already a customer of Oracle, I can't imagine this matters to you. You did not choose Oracle because it was a good product and they are a good company. You are a customer of Oracle because there was a backroom executive deal with the Devil. No one is surprised or outraged or even has any choices.
Post reply on HN