NEWS Oracle is coming under increasing fire for its repeated claims that its software platform is "unbreakable" and able to withstand the best efforts of any hacker. silicon.com has spoken to two IT security firms in the last week that have found vulnerabilities in Oracle's flagship software and said the database giant is currently working on patches. Oracle's decision to use the "unhackable" guarantee as its marketing mantra has surprised many. Privately the company's techies are thought to be upset by the stance which has made the company's software a chief target for the hacking community. Larry Ellison, CEO of Oracle, kicked off the new campaign last week at US trade show Comdex, where he said the database had so far evaded all attempts to hack it. This week the company has been taking out front page adverts in the Financial Times offering users the chance to make their Microsoft applications "unbreakable" by running them on the Oracle application server platform. Ian Peacock, security consultant for penetration testing company Defcom, said: "This is bad, because if IT directors or company directors believe this then they might think they don't need to employ IT security as long as they have Oracle. "One of the biggest problems the industry faces is a lack of security awareness. This is just trying to build on ignorance." Last month Defcom highlighted a serious buffer overflow vulnerability in Oracle's 9i application server. Peacock said there were also well known denial of service vulnerabilities in Oracle systems. Security consultancy PenTest also said it has discovered vulnerabilities in Oracle's application suite, and added it is currently working with database company to resolve those flaws. John Denneny, MD of PenTest, said: "There are vulnerabilities in Oracle's applications, and by saying this Oracle is just making itself into a target. We know customers want their Oracle suite more secure than they can currently get them." In Oracle's defence he said the company had responded promptly to the vulnerabilities PenTest discovered and were taking the issue seriously. Oracle has avoided hitting the headlines with security slip ups but Ellison's latest boast puts the company firmly in the spotlight. Oracle was unable to provide a spokesperson to respond to the news. In a written statement it said: "Oracle9i is designed to be an unbreakable infrastructure. Oracle's customers can store all their data in the industry's most secure database and the data will not be compromised... Oracle9i Database has 14 independent security certifications - 14 more than both IBM and Microsoft."
"Invincible" Oracle not so secure
Cracks spreading...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Latest Software stories
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Systems engineering: Best practice for development success
Systems engineering isn't just a technical activity in the product lifecycle—it determines the commercial viability of...
-
The virtual presenter's handbook
Web seminars -- or webinars -- are online seminars or presentations used to engage remote audiences with any content...
-
Use product development for competitive advantage
Remember when MP3 players just played music? Today, consumers want players that can host music, stream video, support...
Popular Software stories
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Project Manager
Black Rock Studio [A division of Disney Interactive Media Group] is currently recruiting for a Project Manager to...
-
Senior Marketing Executive - Poole - £30,000
I am representing a market leading company based in the Bournemouth / Poole area that are urgently looking for...
-
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000
SAP Senior PC Product Costing Consultant - FICO (FI/CO) - End User - Up to £85,000SAP Senior PC Product...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




