Live data from Hacker News

Oracle attempt to hide cybersecurity incident from customers?

doublepulsar.com

71–80 of 136 posts

Re: Oracle attempt to hide cybersecurity incident from customers?

#71
post #50

Earlier quoted context omitted.

> everyone who worked there has a black mark on their CV I hope this is hyperbole. Rank and file employees are not responsible for corporate policy or direction, especially in places like Oracle.

It really isn't. Oracle has had a terrible reputation since forever, and every ex-Sun engineer I've met has taken great pains to explain they did not join Oracle voluntarily. It's kind of like working for a tobacco company or arms manufacturer in payroll or something: you're not directly responsible for killing millions of people, but by choosing to work there you're still kind of condoning it.

I'm curious, does it end only at Oracle?

What about Google, Facebook & Microsoft. They do some things that are disliked by many. Should we consider that the engineers who work there are indirectly condoning the no-privacy, ad-infested dystopia that HN hates, and should they be penalized. I bet many of these companies and a lot of others use Oracle products and there by support them directly with money. If you know that your favorite website/product is built on top of Oracle database/products, will you stop using it?

If Oracle (or any other unpopular company) employees are really shunned, then that's only because rejecting them is a no-risk, no-cost, easy thing to do.

Re: Oracle attempt to hide cybersecurity incident from customers?

#72
post #60

Earlier quoted context omitted.

I've started seeing ads for Oracle OCI in some podcasts I listen to so I think they are starting to see if they can attract customers outside of their "enterprise sales process". I'm not sure who those ads are supposed to appeal to besides the podcasts hosts raking in the ad dollars.

I haven’t seen the ads, but Oracle Cloud is definitely the public cloud provider with the most generous free tier. That’s not to say you should use and trust them, but I can see why many would.

My personal multicloud strategy for many years was to make full use of the free tier on as many providers as necessary.

Re: Oracle attempt to hide cybersecurity incident from customers?

#73
post #71

Earlier quoted context omitted.

It really isn't. Oracle has had a terrible reputation since forever, and every ex-Sun engineer I've met has taken great pains to explain they did not join Oracle voluntarily. It's kind of like working for a tobacco company or arms manufacturer in payroll or something: you're not directly responsible for killing millions of people, but by choosing to work there you're still kind of condoning it.

I'm curious, does it end only at Oracle? What about Google, Facebook & Microsoft. They do some things that are disliked by many. Should we consider that the engineers who work there are indirectly condoning the no-privacy, ad-infested dystopia that HN hates, and should they be penalized. I bet many of these companies and a lot of others use Oracle products and there by support them directly with money. If you know th…

> Should we consider that the engineers who work there are indirectly condoning the no-privacy, ad-infested dystopia that HN hates, and should they be penalized. > [..] then that's only because rejecting them is a no-risk, no-cost, easy thing to do.

Exactly as you say. It's less about enforcing ethical behaviour than getting safe revenge on what is perceived as an easy target. For example considering the rise of LLMs, people affiliated with google search are probably about to feel the full force of 10+ years of increasing frustration with declining quality, rather than being legendary high value hires. Unhirables that are completely ostracized? Of course not. But a black mark? Yes, probably.

Re: Oracle attempt to hide cybersecurity incident from customers?

#74
post #16
post #7

This is honestly wild. Whether we like it or not security incidents have become such common place in the last several years that if they just admitted to it this entire story would have likely been shrugged off and mostly forgotten about in a couple days but instead it is turning into an entire thing that just seems to be getting deeper and deeper. (Not downplaying the security incident, but that is the unfortunate r…

> Seriously if I can't trust that I am going to actually be told and not lied too when there is a security incident at the bare minimum, why would I chose to work with a company? What is Oracle's end goal here? I think you're coming at this from the wrong point of view. Oracle couldn't care in the slightest about what regular people think of them. Remember, they are the company that sent lawyers after the employers o…

> everyone who worked there has a black mark on their CV. Yet they persist, continue leeching off companies too scared to make the jump elsewhere.

This is just your opinion. Most people I know who work there feel just fine if not very happy. Pay/benefits are good. Work is about same everywhere. In fact depending on group there maybe good, challenging technical work there.

As far as CV is concerned working there is mostly positive or at best neutral in term of job change.

> Nobody buys Oracle because they like them or their good reputation.

Oracle is quite expensive but they have reputation of solid database for enterprise workloads.

Also their cloud business is doing fine and growing and not irrelevant. One can see that from their quarterly results.

Re: Oracle attempt to hide cybersecurity incident from customers?

#75

Earlier quoted context omitted.

My wife is a hospital pharmacist. Cerner is a poular EMR system, is ~#2 in the market (behind Epic). These systems are ridiculously difficult to change between (everyone from your front-check-in desk to every surgeon who has privileges needs to be trained on how the new system works in addition to the technical problems with ETL'ing all your data over, and each hospital has an enormous amount of customization done to…

True, but with one exception that I saw (Memorial Sloan Kettering), every EMR that isn’t Epic is a steaming pile. And I think MSK is switching.

Epic is my wife's favorite, for sure. Both of the switch-overs she was involved in were to Epic. They also cost more than the others.

One thing I have learned in my two decades of SWE'ing is how vitally important active competition is. One of the major competitors voluntarily taking themselves out of the competition so it can be sucked dry of value always seems to be good news for the market share, dominance, and profitability of the #1 in the market, and bad news for everyone's customers.

Re: Oracle attempt to hide cybersecurity incident from customers?

#76
post #50
post #16

Earlier quoted context omitted.

> Seriously if I can't trust that I am going to actually be told and not lied too when there is a security incident at the bare minimum, why would I chose to work with a company? What is Oracle's end goal here? I think you're coming at this from the wrong point of view. Oracle couldn't care in the slightest about what regular people think of them. Remember, they are the company that sent lawyers after the employers o…

> everyone who worked there has a black mark on their CV I hope this is hyperbole. Rank and file employees are not responsible for corporate policy or direction, especially in places like Oracle.

Coincidentally, I posted an Ask HN on that same question (actually prompted by a post on a different company today), but it hasn't gotten upvoted yet:

Ask HN: Do you penalize hiring candidates from companies that do shady things? | 1 point by neilv 1 hour ago| 3 comments | https://news.ycombinator.com/item?id=43538530

Re: Oracle attempt to hide cybersecurity incident from customers?

#77
post #7

This is honestly wild. Whether we like it or not security incidents have become such common place in the last several years that if they just admitted to it this entire story would have likely been shrugged off and mostly forgotten about in a couple days but instead it is turning into an entire thing that just seems to be getting deeper and deeper. (Not downplaying the security incident, but that is the unfortunate r…

I'm guessing nobody chooses to work with Oracle anymore for reasons or in situations that we would consider reasonable. It's probably either governments contracts, with or without corruption, companies already locked in, contracts made by executives that don't really understand technology, that sort of thing.

I worked as a contractor for the Wisconsin state government and they had hundreds of Oracle databases that they were consolidating on the Oracle EXADATA11 servers. Insane having hardware that can only run Oracle but the Oracle DBA said that the Exadata was dozens of times faster than Oracle on VMware VMs.

Re: Oracle attempt to hide cybersecurity incident from customers?

#78
post #50

Earlier quoted context omitted.

> everyone who worked there has a black mark on their CV I hope this is hyperbole. Rank and file employees are not responsible for corporate policy or direction, especially in places like Oracle.

It really isn't. Oracle has had a terrible reputation since forever, and every ex-Sun engineer I've met has taken great pains to explain they did not join Oracle voluntarily. It's kind of like working for a tobacco company or arms manufacturer in payroll or something: you're not directly responsible for killing millions of people, but by choosing to work there you're still kind of condoning it.

> arms manufacturer in payroll or something: you're not directly responsible for killing millions of people, but by choosing to work there you're still kind of condoning it.

It morbidly amuses me that this kind of argument can still be made given what's going on in Ukraine. Governments have militaries for a reason, and there's a reason Europe is now scrambling to re-arm itself.

Re: Oracle attempt to hide cybersecurity incident from customers?

#80
post #74
post #16

Earlier quoted context omitted.

> Seriously if I can't trust that I am going to actually be told and not lied too when there is a security incident at the bare minimum, why would I chose to work with a company? What is Oracle's end goal here? I think you're coming at this from the wrong point of view. Oracle couldn't care in the slightest about what regular people think of them. Remember, they are the company that sent lawyers after the employers o…

> everyone who worked there has a black mark on their CV. Yet they persist, continue leeching off companies too scared to make the jump elsewhere. This is just your opinion. Most people I know who work there feel just fine if not very happy. Pay/benefits are good. Work is about same everywhere. In fact depending on group there maybe good, challenging technical work there. As far as CV is concerned working there is mo…

> Work is about same everywhere

Well, no. When a customer at my job makes a mistake, we don't send lawyers chasing after them because we're assholes. And when someone proposes something that will hurt those customers, people speak up and voice their disagreement.

Post reply on HN