The company improves its relationship with security researchers by communicating more openly.
endif; ?>Oracle once marketed its database as “unbreakable,” but security researcher David Litchfield has a lesser opinion of the software. “God forbid that any of our critical national infrastructure runs on this product,” he said recently on the widely read Bugtraq security mailing list. “Oops, it does.”
And while this can put them at odds with software makers, the relationship between Oracle and people like Litchfield has been particularly bad.
In Litchfield’s case, the problems go back to 2004, when he published details of an unpatched Oracle vulnerability in a presentation written for the Black Hat security conference. According to Litchfield’s account, Oracle had given him the go-ahead to discuss the vulnerability but changed its mind at the last minute. Litchfield changed the topic of his presentation, but he was unable to remove his slides from the conference hand-out.
Tense relationship
The next day, The Wall Street Journal wrote about the flaws, and, ever since, the relationship between Oracle and the tight network of security researchers who hack its products has been tense.
This antagonism has prevented Oracle from receiving independent testing and security advice that could improve its products, says Cesar Cerrudo, CEO of security research firm Argeniss. “Oracle has ignored researchers and also attacked them, saying that researchers are the problem,” he says. “The problem is Oracle’s flawed software and Oracle’s amateur handling of security-related issues.”
From Oracle’s perspective, researchers such as Litchfield profit from the publicity they get for exposing Oracle’s security flaws, but that exposure comes at a price: more risk for Oracle’s customers.
There is often little upside to cooperating with companies that do not understand Oracle and profit from publishing security vulnerabilities, according to Oracle CSO Mary Ann Davidson.
“What I really want is a world where there can be fair and accurate criticisms,” she says. “I’m all for dialogue, but you have to establish trust.”
However, in the past few months, there have been some signs that things may be changing at Oracle.
The company is becoming better at communicating with the research community, says Darius Wiles, manager of Oracle Security Alerts.
Wiles’ team is working out a new bug system that will let bug reporters outside the company know they are not being ignored. “Once a month, going forward, we’ll provide them with a list of everything that has not yet been fixed and indicate whether it’s still under investigation or whether it’s been fixed,” he says.
Taking a cue from Microsoft, Oracle has launched its own security blog.
And Oracle no longer talks about its products as unbreakable. Recently, Davidson said that the first time she heard the marketing slogan, she thought, “What idiot dreamed this up?”
This outreach is starting to pay off. Earlier this month, Litchfield wrote an uncharacteristically positive Bugtraq posting about the company.
He said that he believes Oracle’s products are becoming more secure and even had some praise for his longtime nemesis Davidson. “Another thing that struck me was the amount of effort and time that it must have taken to get a lumbering stegosaurus of a beast like Oracle to turn around,” he wrote. “Dare I say it, well done Mary.”
Still, the database giant is unwilling to go as far as its competitor Microsoft in embracing the “white hat” hackers. Microsoft has invited researchers, including Litchfield and Cerrudo to its Redmond, Wash., campus for twice-yearly hacker conferences, called Blue Hat.
Microsoft says Blue Hat helps it make its products more secure, but don’t expect Oracle to invite hackers over to its headquarters in Redwood Shores, Calif., anytime soon. Such an event is really not necessary, Davidson says. “Microsoft had to go with the hacker love-fest model because they’re a big target,” she says.
Davidson says Oracle and Microsoft have very different pedigrees when it comes to security, noting that security has been built into the development of Oracle’s products for years, a byproduct of its long history of government use. The CIA was one of Oracle’s first customers, she says.
Oracle’s security team doesn’t simply fix bugs. When a new flaw is discovered, researchers make sure that what they’ve learned also translates into secure coding practices for the development team.
While Oracle has improved the security of some products, such as the Oracle 10g Release 2 database, the company still has a lot of work to do, Argeniss’ Cerrudo says.
“They said recently that they will change the way they communicate with researchers giving more feedback information, but nothing has happened yet,” he says.
No widespread attacks
For all the Oracle bugs that have been found, it has never suffered a widespread attack, like the Slammer worm, which disabled Microsoft SQL Server machines worldwide in 2003.
But some observers say Oracle’s reputation for security has more to do with the fact that the database typically is buried in the bowels of data centers and hidden behind corporate firewalls, far from the prying eyes of hackers. And while users who have not exposed their databases to queries from outside partners or customers may not stay up late at night worrying about Oracle’s security, they do have concerns about the future.
“We’re in a nervous state, but we think it’s manageable risk,” says Hal Kuff, a technology services manager with Tessco Technologies in Hunt Valley, Md.
Users must first be inside Tessco’s LAN in order to query the database, Kuff says. “If we were to pursue an Oracle environment where we invited direct connectivity from outside partners, we would reconsider our security posture,” he says.
As these outside connections become more common, thanks to grid computing and Internet applications, outside experts such as Litchfield could become important allies to Oracle, Kuff says.
The pervasiveness Kuff talks about may be closer than many people realize. Late last year, Litchfield conducted a survey of nearly a half-million computer systems on the Internet and found nearly as many Oracle databases exposed as he did Microsoft SQL server systems.
Extrapolating from his data, Litchfield estimated about 140,000 Oracle servers not firewalled on the Internet. There are about 210,000 Microsoft SQL Servers similarly unprotected, he says.




