Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 34 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » July 2005 » Oracle's encryption not secure, researcher says - Alexander Kornbrust plans to detail his findings at Black Hat

[Previous entry: "Oracle Patches Its Security Patches - Database patches fix flaws found in previous fixes"] [Next entry: "web seminar for Oracle roadmap of Oblix integration"]

Oracle's encryption not secure, researcher says - Alexander Kornbrust plans to detail his findings at Black Hat

July 27th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

Rado has made a post in my Oracle Security Forum today titled "Alexander Kornbrust - Black Hat 2005 Presentation" that raises some good points about the effectiveness of the security imposed by Oracles built in database encryption methods. He is referring to Alex's presentation at the Black Hat conference going on now in Las Vegas. He also mentions a news article written by Robert McMillan on Computer World titled "Oracle's encryption not secure, researcher says - Alexander Kornbrust plans to detail his findings at Black Hat".

This news article starts by talking about the content of Alex Kornbrusts presentation at Black Hat in Las Vegas where he is going to say that Oracles standard database encryption mechanisms are weak and can be easily circumvented. Alex says most customers think that if they encrypt data with Oracles tools then it is safe - He says that this is not the case and a hacker can easily retrieve data such as credit card numbers from production databases. There are some interesting reactions from Paul Needham, the Oracle director of product management and some discussions about TDE and its cost per processor. This is a good article and worth reading. It is a two page article and page two is here.


July 2005
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930
31      

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!