Auditing an Oracle database for security issues is very important. PeteFinnigan.com provides all of the information and tools that you will need Click here for details of PeteFinnigan.com Limited's detailed Oracle database security audit service Click here for details of PeteFinnigan.com Limited's Oracle Security Training Courses
There are 23 visitors online    

Pete Finnigan's Oracle security weblog


Home » Archives » July 2005 » Mary Ann Davidson fights back - When security researchers become the problem

[Previous entry: "web seminar for Oracle roadmap of Oblix integration"] [Next entry: "Oracle's 10g Encryption Feature Is a Fine First Step"]

Mary Ann Davidson fights back - When security researchers become the problem

July 27th, 2005 by Pete

Post to del.icio.us   Post to Furl   Digg!

I just saw that Mary Ann Davidson - Oracle's Chief Security Officer - has written a news article for news.com titled "When security researchers become the problem". This is a very interesting article and is quite clearly a rebut against recent challenges to Oracle to fix bugs more quickly by releasing advisories for unfixed bugs. This is a good article where Mary Ann tries to defend her position whilst attacking the position of those who have released details of exploits. It is also interesting that she tries to justify Oracles timescales which is fair enough - her argument is good but she doesn't actually explain why it takes 2 years to fix bugs.

The article doesn't mention the recent problems with the April CPU and subsequent problems with the fixes to the April CPU or the issues raised by Cesar on the July CPU. It also doesn't say when the outstanding lists of bugs on the likes of Alex, David Litchfields and Argeniss's sites will be fixed, a lot of which were reported more than one year ago.

The article has a link at the bottom where it is possible to leave a comment for Mary Ann.


July 2005
SMTWTFS
     12
3456789
10111213141516
17181920212223
24252627282930
31      

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

Weblog Home
Weblog Archives

Oracle Security Step-by-Step (Version 2.0)

Home
Oracle Security Tools page
Oracle security papers
Oracle Security alerts

Web Development
SQL Server Security

RSS 1.0 FEED
RSS 2.0 FEED
Atom 0.3 FEED
Powered by gm-rss 2.0.0


Valid XHTML 1.0!