[HN Gopher] Oracle attempt to hide cybersecurity incident from c...
___________________________________________________________________
Oracle attempt to hide cybersecurity incident from customers?
Author : 2bluesc
Score : 426 points
Date : 2025-03-31 15:11 UTC (7 hours ago)
(HTM) web link (doublepulsar.com)
(TXT) w3m dump (doublepulsar.com)
| richwater wrote:
| Pretty on par for what I expect from Oracle. I'm surprised
| there's no corporate contracts involved yet.
| neuroelectron wrote:
| The hacker is following a number of corporations. Is it an
| empty threat or a hint?
|
| https://imgur.com/a/IsksRrZ
| ziddoap wrote:
| Neither. I would not read anything into a random hacker's
| twitter follow list.
| MPSFounder wrote:
| Oracle is notoriously stingy. They'd rather lose the data, pay a
| fine and deny it happened (settle), than own up for it.
| NickC25 wrote:
| how is that not securities fraud?
|
| they are under legal obligation to tell investors about this sort
| of shit.
| zitsarethecure wrote:
| If no one enforces the law, it's not illegal.
| bonestamp2 wrote:
| Not to mention all of the data breach notification laws.
| rubiquity wrote:
| Welcome to the (most recent) era of deregulation. Get ready for
| all Fortune 500s to deny, deny, deny, and bribe.
| mentalgear wrote:
| Crypto is a prime asset for bribing. Not for nothing the
| president has his own shit coin.
| PenguinCoder wrote:
| Not related to this story at all.
| _DeadFred_ wrote:
| Sometimes comments are made in relation to upstream
| comments. In this case
|
| "Welcome to the (most recent) era of deregulation. Get
| ready for all Fortune 500s to deny, deny, deny, and
| bribe."
| lucianbr wrote:
| Presumably the requirements for public companies to disclose
| stuff and generally follow all kinds of rules were somehow
| for the health of the markets or something like that. I
| wonder how the markets will fare with the rules neutered.
|
| To be fair, they're trending down at the moment, so maybe
| there was something there. But truly only time will tell.
| cwmma wrote:
| they likely aren't under an obligation to tell investors about
| it immediately and simply putting something in their quarterly
| report about it will probably be fine.
|
| That being said if they put something in some communication
| that said "we take security seriously" or something that would
| probably be grounds to sue as this obviously shows they aren't
| serious or something. The barriers to shareholder lawsuits for
| securities fraud are pretty low.
| seanhunter wrote:
| The SEC says they have 4 business days
|
| "An Item 1.05 Form 8-K will generally be due four business
| days after a registrant determines that a cybersecurity
| incident is material. The disclosure may be delayed if the
| United States Attorney General determines that immediate
| disclosure would pose a substantial risk to national security
| or public safety and notifies the Commission of such
| determination in writing." (from
| https://www.sec.gov/newsroom/press-releases/2023-139)
| seanhunter wrote:
| They are indeed under a legal obligation to disclose "material"
| cybersecurity incidents. For people who want to see the
| details, here's the SEC release
| https://www.sec.gov/newsroom/press-releases/2023-139
|
| Now will the SEC enforce against oracle? In this environment I
| highly doubt anyone at the SEC would have the appetite but I
| could be wrong.
|
| So will any investors with standing choose to bring a civil
| action? Could well do it. There are for sure investors (eg
| Elliot) who in general would fight anyone at all if they
| thought they had a case. I don't know if there's anyone like
| that who had a position in Oracle specifically, but it wouldn't
| suprise me.
| nerdjon wrote:
| This is honestly wild.
|
| Whether we like it or not security incidents have become such
| common place in the last several years that if they just admitted
| to it this entire story would have likely been shrugged off and
| mostly forgotten about in a couple days but instead it is turning
| into an entire thing that just seems to be getting deeper and
| deeper. (Not downplaying the security incident, but that is the
| unfortunate reality).
|
| Seriously if I can't trust that I am going to actually be told
| and not lied too when there is a security incident at the bare
| minimum, why would I chose to work with a company? What is
| Oracle's end goal here?
|
| Are they somehow really confident that this didn't happen, maybe
| they don't have the logs to confirm it? Trying to think about how
| this is anything except them just straight up lying.
|
| I can't remember the last time we saw a company this strongly try
| to deny that something like this happened. Especially when
| according to Ars Technica:
|
| > On Friday, when I asked Oracle for comment, a spokesperson
| asked if they could provide a statement that couldn't be
| attributed to Oracle in any way. After I declined, the
| spokesperson said Oracle would have no comment.
| sofixa wrote:
| > Seriously if I can't trust that I am going to actually be
| told and not lied too when there is a security incident at the
| bare minimum, why would I chose to work with a company? What is
| Oracle's end goal here?
|
| I think you're coming at this from the wrong point of view.
| Oracle couldn't care in the slightest about what regular people
| think of them. Remember, they are the company that sent lawyers
| after the employers of folks who downloaded non-free but
| bundled by default extensions to VirtualBox, and the company
| that declared that you need to license every core their
| software could _potentially_ run on in your virtualisation
| estate (so if you have a 8 vCPU VM for some Oracle software,
| you need licenses for however many physical cores you have on
| your cluster). They've variously been described as a law firm
| with an engineering side business, and One Rich Asshole Called
| Larry Ellisson. Speaking of whom, he multiple times flat out
| lied on stage to make his shitty "cloud" nobody cares about
| seem relevant compared to AWS.
|
| Nobody buys Oracle because they like them or their good
| reputation. You buy them because you have legacy stuff that
| depends on them and you have no choice (even Amazon took many
| years to get off Oracle databases, and they wrote a gloating
| success story one they were done with it because they were that
| happy to be rid of the leeches), or because your bosses' boss
| was convinced at a golf course they're getting a good deal. Or
| because their bandwidth is very cheap and you accept the risk
| of dealing with the devil incarnate with zero morals. (cf.
| Zoom).
|
| Oracle is like Broadcom. Everyone hates their guts, everyone
| who worked there has a black mark on their CV. Yet they
| persist, continue leeching off companies too scared to make the
| jump elsewhere.
| mandevil wrote:
| My wife is a hospital pharmacist. Cerner is a poular EMR
| system, is ~#2 in the market (behind Epic). These systems are
| ridiculously difficult to change between (everyone from your
| front-check-in desk to every surgeon who has privileges needs
| to be trained on how the new system works in addition to the
| technical problems with ETL'ing all your data over, and each
| hospital has an enormous amount of customization done to
| their workflows that has to be ported over to the new
| system)- she's done that twice at two different places and it
| was a huge, process, 18 months minimum. So these EMR's have
| an enormous amount of lock-in.
|
| The punchline is, in 2022 Oracle purchased Cerner, renamed it
| Oracle Health, and started accelerating the process of
| enshittifying it. I have to tip my hat to them, it's like
| their BizDev team found a market segment that had as much
| lock-in as SQL databases do, and are now trying to replicate
| all the evil tricks they learned from that in another market
| segment. Because what are hospitals but giant bags of money
| to be drained so Larry Ellison can buy another yacht?
| Spooky23 wrote:
| True, but with one exception that I saw (Memorial Sloan
| Kettering), every EMR that isn't Epic is a steaming pile.
| And I think MSK is switching.
| mandevil wrote:
| Epic is my wife's favorite, for sure. Both of the switch-
| overs she was involved in were to Epic. They also cost
| more than the others.
|
| One thing I have learned in my two decades of SWE'ing is
| how vitally important active competition is. One of the
| major competitors voluntarily taking themselves out of
| the competition so it can be sucked dry of value always
| seems to be good news for the market share, dominance,
| and profitability of the #1 in the market, and bad news
| for everyone's customers.
| senderista wrote:
| As a health consumer, Epic is so dang slow that I wonder
| what it's like for medical professionals.
| devsda wrote:
| > everyone who worked there has a black mark on their CV
|
| I hope this is hyperbole. Rank and file employees are not
| responsible for corporate policy or direction, especially in
| places like Oracle.
| decimalenough wrote:
| It really isn't. Oracle has had a terrible reputation since
| forever, and every ex-Sun engineer I've met has taken great
| pains to explain they did not join Oracle voluntarily.
|
| It's kind of like working for a tobacco company or arms
| manufacturer in payroll or something: you're not directly
| responsible for killing millions of people, but by choosing
| to work there you're still kind of condoning it.
| devsda wrote:
| I'm curious, does it end only at Oracle?
|
| What about Google, Facebook & Microsoft. They do some
| things that are disliked by many. Should we consider that
| the engineers who work there are indirectly condoning the
| no-privacy, ad-infested dystopia that HN hates, and
| should they be penalized. I bet many of these companies
| and a lot of others use Oracle products and there by
| support them directly with money. If you know that your
| favorite website/product is built on top of Oracle
| database/products, will you stop using it?
|
| If Oracle (or any other unpopular company) employees are
| really shunned, then that's only because rejecting them
| is a no-risk, no-cost, easy thing to do.
| photonthug wrote:
| > Should we consider that the engineers who work there
| are indirectly condoning the no-privacy, ad-infested
| dystopia that HN hates, and should they be penalized. >
| [..] then that's only because rejecting them is a no-
| risk, no-cost, easy thing to do.
|
| Exactly as you say. It's less about enforcing ethical
| behaviour than getting safe revenge on what is perceived
| as an easy target. For example considering the rise of
| LLMs, people affiliated with google search are probably
| about to feel the full force of 10+ years of increasing
| frustration with declining quality, rather than being
| legendary high value hires. Unhirables that are
| completely ostracized? Of course not. But a black mark?
| Yes, probably.
| decimalenough wrote:
| Some people absolutely do judge people who work at those
| companies, especially Facebook. Google used to have a
| halo but that's pretty tarnished now, while Microsoft
| under Satya seems to have pulled off the unlikely trick
| of redeeming its reputation.
| psunavy03 wrote:
| > arms manufacturer in payroll or something: you're not
| directly responsible for killing millions of people, but
| by choosing to work there you're still kind of condoning
| it.
|
| It morbidly amuses me that this kind of argument can
| still be made given what's going on in Ukraine.
| Governments have militaries for a reason, and there's a
| reason Europe is now scrambling to re-arm itself.
| Hojojo wrote:
| You're also contributing to weapons that can be used to
| fight violent dictators like Putin when he invades yet
| another country (or the same one again).
|
| I'll never understand the West's public aversion to
| military R&D and manufacturing. How do you people think
| WW2 was won? Nice words, trade deals and hookers? At some
| point diplomacy fails and you need to be able to do
| something about it.
| neilv wrote:
| Coincidentally, I posted an Ask HN on that same question
| (actually prompted by a post on a different company today),
| but it hasn't gotten upvoted yet:
|
| _Ask HN: Do you penalize hiring candidates from companies
| that do shady things? | 1 point by neilv 1 hour ago| 3
| comments |_ https://news.ycombinator.com/item?id=43538530
| geodel wrote:
| > everyone who worked there has a black mark on their CV. Yet
| they persist, continue leeching off companies too scared to
| make the jump elsewhere.
|
| This is just your opinion. Most people I know who work there
| feel just fine if not very happy. Pay/benefits are good. Work
| is about same everywhere. In fact depending on group there
| maybe good, challenging technical work there.
|
| As far as CV is concerned working there is mostly positive or
| at best neutral in term of job change.
|
| > Nobody buys Oracle because they like them or their good
| reputation.
|
| Oracle is quite expensive but they have reputation of solid
| database for enterprise workloads.
|
| Also their cloud business is doing fine and growing and not
| irrelevant. One can see that from their quarterly results.
| sofixa wrote:
| > Work is about same everywhere
|
| Well, no. When a customer at my job makes a mistake, we
| don't send lawyers chasing after them because we're
| assholes. And when someone proposes something that will
| hurt those customers, people speak up and voice their
| disagreement.
| senderista wrote:
| I wonder if the senior engineering talent OCI poached from
| AWS (including the guy who introduced formal methods to
| AWS) is still there?
| lucianbr wrote:
| I'm guessing nobody chooses to work with Oracle anymore for
| reasons or in situations that we would consider reasonable.
| It's probably either governments contracts, with or without
| corruption, companies already locked in, contracts made by
| executives that don't really understand technology, that sort
| of thing.
| MPSFounder wrote:
| Actually, it is mostly companies who are too reluctant to
| change. If it works, keep it as is, even if better
| technologies are the norm nowadays. Maybe this will help them
| move away from this obsolete Larry Ellison crapshot
| wruza wrote:
| _If it works, keep it as is_
|
| That's a good principle though. It doesn't make the initial
| choice good today or even back then. But change is always a
| risk that may not be worth it, cause you have to make sure
| that the inevitable semi-chaos coming with it is at all
| times lower than what you have. And analyzing that may be
| hard.
|
| _Maybe this will help them move away from this obsolete
| Larry Ellison crapshot_
|
| This creates positive incentives, so yes.
|
| Iow, everything probably goes as it should, really.
| MPSFounder wrote:
| I somewhat agree. I think for tangible things (cars), you
| don't need to reinvent the wheel. But, tech moves fast.
| If a superior tech (for instance, more secure) is
| available but requires some discomfort (moving things
| around), then it is worth it to avoid this type of crap
| pixl97 wrote:
| Seemingly, most companies have a terrible ability to
| judge if a technology is superior, hell most of the time
| they lack the ability to judge if a technology is
| massively inferior. Companies may understand what _they
| do_ but they commonly have no understanding of what they
| do in relation to the abstraction layers between them and
| said technology.
|
| Often this technology has been in place for some time and
| the original creators are long gone for one reason or
| another. To migrate away from this system the business
| will need to spend a significant amount on
| contractors/consultants to understand both the system
| they have well enough, and the system they are moving to.
| It can be a huge expense and companies are very willing
| to push that off into the future.
| UltraSane wrote:
| I worked as a contractor for the Wisconsin state government
| and they had hundreds of Oracle databases that they were
| consolidating on the Oracle EXADATA11 servers. Insane having
| hardware that can only run Oracle but the Oracle DBA said
| that the Exadata was dozens of times faster than Oracle on
| VMware VMs.
| 3acctforcom wrote:
| Lies. Fucking lies. We were a three environment shop until
| we moved to Exa and the compute/$ ratio is so bad that we
| had to cut it down to two.
|
| But we're talking about Oracle here so that's par for the
| course.
| sylens wrote:
| Security incidents have become so common place that the fact
| that they happen is not the newsworthy event; rather, its how a
| company responds to them that is the newsworthy event. And
| Oracle flunked this test
| hdjjhhvvhga wrote:
| That's why in Europe there are strict laws regarding lax
| security of customer data and companies can be fined with a
| percentage of their turnover - which in the case of Oracle
| could hurt a bit.
| autoexec wrote:
| There are various state laws that require companies to notify
| their customers of security breaches, but they lack
| enforcement/teeth so they're routinely ignored. It'll never
| happen in our current environment but we really need a federal
| law that causes violators enough pain that companies will
| actually bother to follow the law.
| TrueDuality wrote:
| While that's true, many enterprise customers are going to have
| MSAs with notification requirements that have contractual
| punishments for failure to notify of material security
| incidents. Those are probably what Oracle is trying to avoid.
| asciii wrote:
| I believe enterprise customers are not going to care much
| unless it helps with lowering existing costs.
|
| OTOH, Oracle as part of BSA can demand an audit so they will
| inflict / make up reason to also punish (i.e. licensing or
| pull support). The business could invoke an MSA punishment
| clause and win temporarily but it will cause a headache going
| forward (further demands from Oracle, higher costs etc.)
|
| Either way, Oracle gets what they want.
| praptak wrote:
| Unless the customer already wants to ditch Oracle.
| stackskipton wrote:
| Very few companies want to business with Oracle (or IBM).
| Most are either stuck with either and costs of switching
| are too high for executive to greenlight.
| mentalgear wrote:
| Ah, another notch in the belt for Larry Elison's Oracle data
| security scandals.
|
| Matches Larry's other political and societal scandals.
| jjice wrote:
| Tangential, but there's an old interview with Ellison where he
| said that Amazon would never be able to get off of Oracle DB
| because it's too critical a piece of software. This was in
| response to Amazon announcing it was something they had
| planned.
|
| Amazon got it done ahead of schedule and there's a video of
| them popping champagne to celebrate when they shut the last
| server down.
|
| I'm not a big Amazon fan, but the enemy of my enemy is my
| friend.
| terom wrote:
| https://news.ycombinator.com/item?id=43486945 related
| islanderfun wrote:
| Post-truth era is wild. But this seems like standard Oracle
| behavior for a while now.
| 1970-01-01 wrote:
| I hear fines are up to thousands of dollars now..
| compootr wrote:
| tens*
| homiedk wrote:
| The troubling aspect is (besides the denials of course) is the
| absence of controls that should have sniffed this out ASAP.
| Apparently: - no passive network monitors showing an unknown
| IP/Mac/Location - no SOAR to kill off the attempts to gain a
| foothold/move laterally - no alerts on above or anything else in
| the SOC
| tmpz22 wrote:
| Its times like this Oracle needs to lean on its good reputation
| and ask for forgiveness from the customers they've been loyal to
| for so long.
| cptskippy wrote:
| > Oracle needs to lean on its good reputation
|
| It's what now?
| noodlesUK wrote:
| Something tells me parent implied the /s.
| edgineer wrote:
| > the customers they've been loyal to
|
| ...who?
| mrbluecoat wrote:
| > NetSuite will indemnify Customer up to an amount equal to five
| (5) times the equivalent of 12 months of license fees applicable
| at the time of the event, from and against any Losses incurred by
| Customer
|
| https://www.sec.gov/Archives/edgar/data/1428669/000119312508...
| legitster wrote:
| If you are already a customer of Oracle, I can't imagine this
| matters to you. You did not choose Oracle because it was a good
| product and they are a good company. You are a customer of Oracle
| because there was a backroom executive deal with the Devil. No
| one is surprised or outraged or even has any choices.
| noja wrote:
| If the tables were turned, Oracle would be taking advantage of
| the situation.
|
| Take note.
| redleggedfrog wrote:
| As my buddy from Oracle likes to say, "No one cares what we do
| as long as the flow of streak, coke, and strippers doesn't
| stop."
|
| He's a big Zed Shaw fan.
| xdavidliu wrote:
| what's "streak"? do you mean steak?
| bityard wrote:
| I thought it was some kind of trendy alcohol that I hadn't
| heard of, that probably comes in a brown bottle
| marcosdumay wrote:
| You can search for that word definition.
| legitster wrote:
| Anytime Oracle is brought up is a great time to repost the
| famous Lawnmower quote:
|
| > "As you know people, as you learn about things, you realize
| that these generalizations we have are, virtually to a
| generalization, false. Well, except for this one, as it turns
| out. What you think of Oracle, is even truer than you think
| it is. There has been no entity in human history with less
| complexity or nuance to it than Oracle. And I gotta say, as
| someone who has seen that complexity for my entire life, it's
| very hard to get used to that idea. It's like, 'surely this
| is more complicated!' but it's like: Wow, this is really
| simple! This company is very straightforward, in its defense.
| This company is about one man, his alter-ego, and what he
| wants to inflict upon humanity -- that's it! ...Ship
| mediocrity, inflict misery, lie our asses off, screw our
| customers, and make a whole shitload of money. Yeah... you
| talk to Oracle, it's like, 'no, we don't fucking make dreams
| happen -- we make money!' ...You need to think of Larry
| Ellison the way you think of a lawnmower. You don't
| anthropomorphize your lawnmower, the lawnmower just mows the
| lawn, you stick your hand in there and it'll chop it off, the
| end. You don't think 'oh, the lawnmower hates me' --
| lawnmower doesn't give a shit about you, lawnmower can't hate
| you. Don't anthropomorphize the lawnmower. Don't fall into
| that trap about Oracle." - Bryan Cantril
| A4ET8a8uTh0_v2 wrote:
| To be fair to Oracle: the lawnmower doesn't hate people...
| yet. This millennium is still young. And we keep adding
| connectivity and llms into everything.
| neilv wrote:
| https://www.youtube.com/watch?v=-zRN7XLCRhc&t=33m
| pedrocr wrote:
| You elided the most famous quote from that diatribe. The
| lawnmower comparison is the expansion on:
|
| "Do not fall into the trap of anthropomorphizing Larry
| Ellison"
| FlyingSnake wrote:
| I'm sorry but I don't get this Zed Shaw reference, what did I
| miss?
| decompiled_dev wrote:
| He's a popular blogger: https://zedshaw.com/
| bigiain wrote:
| Weapons grade infinte snark, probably.
|
| He seems to have stopped blogging a few years back. I kinda
| miss his epic rants and Learning $whatever The Hard Way
| stuff. Part of me hopes them and whoever used to run n-gate
| moved to Portland and are now running a bespoke hand made
| piano business together or something.
| _fat_santa wrote:
| I've started seeing ads for Oracle OCI in some podcasts I
| listen to so I think they are starting to see if they can
| attract customers outside of their "enterprise sales process".
|
| I'm not sure who those ads are supposed to appeal to besides
| the podcasts hosts raking in the ad dollars.
| brirec wrote:
| I haven't seen the ads, but Oracle Cloud is definitely the
| public cloud provider with the most generous free tier.
| That's not to say you should use and trust them, but I can
| see why many would.
| 999900000999 wrote:
| You pay in other ways.
|
| I understand if you have absolutely no money, but even then
| repeatedly trying to provision a server and getting a
| error- something like no capacity available - isn't a fun
| time.
|
| Whatever, I'll pay 7$ a month to not deal with that.
| nisa wrote:
| You can automate it using their API and some Python. It's
| like a puzzle game and I'm personally thankful for the
| free tier, it's pretty cool if you max it out you have
| multiple IPv4 addresses, IPv6 prefixes and so on - the
| machines boot via UEFI, you can run nixos and ZFS on
| them, you have a serial console via ssh/vnc and at least
| in Germany they have good connectivity and 10tb Traffic
| is plenty. Using it for something serious? Probably not.
| But for tinkering it's pretty cool and interesting if you
| enjoying some small quests. Running incus and some
| Kubernetes stuff on an arm box and 24gb memory and 200gb
| SSD is at least 10-20EUR elsewhere.
| bigfatkitten wrote:
| My personal multicloud strategy for many years was to make
| full use of the free tier on as many providers as
| necessary.
| LPisGood wrote:
| >"enterprise sales process"
|
| I'm sorry, is Oracle known to be some super sleazy sales org
| that plys enterprise decision makers with strippers and
| cocktails, and drugs?
| bigiain wrote:
| I have absolutely no idea if you are being facetious or
| naive there.
|
| Yes. Oracle is absolutely the tech vendor that's going to
| be dropped on the engineering team with zero input and no
| consideration for whether it fits the problems they have,
| after your CTO spends a a few days on the golf course and
| high end steak restaurants and, depending on how much money
| their enterprise sales team thinks they have, either high
| class escorts or sleazy strip joints. Given how common that
| story (or one very like it) is, I'm close to 100% certain
| those trips also include discreet photographers and hotel
| rooms wired with 4k video recording.
| sidewndr46 wrote:
| I imagine Larry Ellison gave this exact speech right after this
| incident became public.
| aurizon wrote:
| Create a 'Wicki-hacks.com', like Wikipedia, where incidents are
| listed in detail - anonymously and indexed akin to Wikipedia with
| editors that create and verify an incident is such a way that
| Horacle etc can not deny or get it taken down
| prdonahue wrote:
| We're primarily an AWS shop but some Oracle BDR assigned to cover
| us recently reached out on LinkedIn.
|
| I asked for an incident report and received this terse response:
|
| > There has been no breach of Oracle Cloud. The published
| credentials are not for the Oracle Cloud. No Oracle Cloud
| customers experienced a breach or lost any data.
| blast wrote:
| That exact statement is quoted in the OP too.
| prdonahue wrote:
| Yeah, they've clearly been given some minimal company line
| and aren't deviating from it. Not going to win any trust.
| decimalenough wrote:
| Per article, Oracle has hastily rebranded the breached service
| as "Oracle Classic", for the sole purpose of being able to
| claim with a straight face that "Oracle Cloud" was not
| impacted.
| xyst wrote:
| This is a deliberate attempt to cover up their incompetence. It
| should be criminal to deceive the public and your _paying_
| customers.
|
| Executives need to go to jail. People need to be fired.
|
| This won't happen though, definitely not under this current
| administration.
| LZ_Khan wrote:
| Annnnd this is why Google bought Wiz huh.
___________________________________________________________________
(page generated 2025-03-31 23:00 UTC)