On CBS MoneyWatch: Dumbest Things You Do With Money
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 12 of 12:
« Previous
Selective data
This article really goes out of it's way to select only certain data points to try to prove it's case.

For example:
" On its Web site, eEye lists flaws in Microsoft, RealNetworks and Macromedia products that it believes should have been put right by now. "But Oracle is definitely worse," Manzuik said. "They have taken over 600 days to release patches. The worst we have seen Microsoft do is in the 300-day range.""

If Microsoft has way more bugs and they are much more critical, then I would EXPECT them to have a much faster turn-around time. Why would they expect a minor inconvenice in a database program to be turned around in the same amount of time as a significant security hole? The Microsoft flaws I hear about always seem much more significant than the Oracle flaws. Even the Oracle flaws specifically linked to in this article are fairly minor in nature compared to the junk Microsoft puts out.

I had to analyze the set of recently reported Oracle "flaws". One of them required a valid username/password account on the database. The other required FTP access directly to the application servers. If a hacker gets hold of a valid username/password, or FTP access DIRECTLY to the application servers, then they can do FAR worse stuff than exploit a few minor security holes in the database. Compare that to Microsoft security flaws that allow people to take control of your PC for doing virtually nothing and you see the difference.

I hear about a significant new virus or security hole in Microsoft almost every single week. I can't remember the last time I actually heard about someone truly hacking Oracle or using Oracle to do damage.
Posted by: joesmoe25   Posted on: 10/27/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

I am shocked  BXLE | 10/27/05
The problem is with...  cburgess | 10/27/05
Article is spot-on  mikerault | 10/27/05
Unbreakable? Yeah...in a vacuum.  lawryll@... | 10/27/05
get real  squeezebox | 10/27/05
USAF Database Hacked...  cburgess | 10/27/05
one man's hack  squeezebox | 10/27/05
the essence of hacking....  cburgess | 10/27/05
If you have the access Oracle is simple to hack  voska | 10/27/05
Published vs Unpublished Exploits  cburgess | 10/27/05
Oracle is a Patch always under development  kelmark2180 | 10/27/05
Selective data  joesmoe25 | 10/27/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement