Reality : 1
Oracle: 0
Oracle Cloud's denial of a digital break-in is now in clear dispute. A infosec researcher working on validating claims that the cloud provider's login servers were compromised earlier this year says some customers have confirmed data allegedly stolen and leaked from the database giant is genuine. Since Oracle rubbished reports …
I used to be a customer of a DNS server service that Oracle bought out. Cancelled that account at least 8 years ago. I still receive updates from them warning about planned maintenance outages. I clicked the "unsubscribe" link, they kep on coming. I complained to "support", who gave me every assurance that my email had been removed from the databse. They kept on coming. I replied to the support email calling them liars, and they just stopped responding. It wouldn't surprise me at all if I was to find out they have blocked my email address for receiving.
And yet the emails keep on coming. Really tight internal IT department, this company. What's their business again? Oh, IT services? OK then.
Assuming you're in the UK or EU, you can use your Right to Erasure (yes, even in a business capacity if it relates to a person not a generic business address).
They are require by law to remove you. If they don't, you can complain, and they will be fined (and you'll also have the satisfaction that you caused them untold hours and cost of processing the complaint).
Even if you're not in the EU, big companies are generally so spooked by this that they'll blindly process any requests they get that fit the template.
You don't even need to do anything in this day and age, just get ChatGPT to bang out the request and email it to them.
I remember Larry going on stage at Oracle world some years back, it’s on you tube, and the dude literally spends 10 minutes attacking AWS security. Talking about how Oracle cloud 2.0 was vastly superior yada yada yada.
Why he was using his keynote to give airtime about AWS I don't know, but its kind of ironic rhat a few years later it turns out their security is crap.
"Why he was using his keynote to give airtime about AWS I don't know, but its kind of ironic rhat a few years later it turns out their security is crap."
Security is expensive and a constantly moving shield to keep in place. That severely impacts executive bonuses and earnings reports. Oracle AND AWS's customers are often operations a few orders of magnitude smaller. Complaints are the mews of a kitten in a box so the "good enough" bar winds up being set rather low.
My hypothesis is that the size ratio can lead to a real ambivalence about security, customer satisfaction or quality. My cable internet company has millions of subscribers nationwide. A complaint from me winds up in a dead letter box after the "don't reply to this email, this account is not monitored" form letter is sent. I was supposed to receive some new gubbins to take advantage of higher speeds. I called to make sure it would ship to the correct address (not the service address) and was assured it was all set. It was sent to the service address, claims to have been delivered and isn't anything I've seen remaining on the doorstep a few meters from the road in plain view (which is why nothing gets shipped to the house). I get letters reminding me to install said gear from email addresses that can't be replied to and signed by a VP of customer satisfaction that doesn't have a locateable email address on the company web site. No inquiries asking if I received the gear. The upside is that I never signed for anything so there's no proof I have it. Fat lot of good that will do when their lawyers come calling at some point demanding I pay for it.
Tried, Rose87168 asked for 100k Monero (approx. £20m) to disclose the details, fix it, and destroy the data, which Larry's Lawsuit House declined.
From the posting, Rose sounds like someone who is very green and lucked into an exploit on a big fish.
also possibly someone not entirely of an age to benefit from a work contract with Big Red.
Reduce your cloud footprint.
Unless you really, really need your data to be on a[ny] cloud, archive it on those very cheap multi-Tb HDDs you can now buy for peanuts, with as many copies as you need, and store it somewhere safe. offline.
And don't store data for the sake of it. Only if you have a valid reason to store it. If you are never going to need it, you may as well be paying to archive and curate dust, collected each day by your cleaners.
"If you are never going to need it, you may as well be paying to archive and curate dust"
Every company has lots of data they are never going to use, but are required by law to keep - sometimes indefinitely.
(Of course, they can wind up the company; that eliminates the data retention obligation.)
"but are required by law to keep - sometimes indefinitely."
What would need to be archived indefinitely? Usually there are statutes of limitations for tax and employee records that don't go beyond 10 years. It's also a good idea to maintain historical data on products and could be contractual requirements to do so. As the records from my closed manufacturing company age, there's boxes of paperwork each year that can be run through the shredder and used for animal bedding. The bird boxes on my property get a refresh of shredded paper every season and the birds seem to like it as they don't kick it out during nest building.
There are a few things that have to be kept for what could be the entire lifetime of the corporate body - and even through the zombie period in case of resurrection.
But not many, and they're not large. Mostly contracts, tax and employment data.
Eg your contract of employment needs to be retained, provably unaltered, until several years after you leave, in case you decide to sue.
Most things can vanish though, and the vast majority of data so treasured has a negative real value, and should be destroyed almost immediately, or (better) never collected at all.
"Unless you really, really need your data to be on a[ny] cloud, archive it on those very cheap multi-Tb HDDs you can now buy for peanuts, with as many copies as you need, and store it somewhere safe. offline."
An aerospace company I worked for had a server onsite that backed up each night to two other company locations in widely separated locations across the US in addition to local backups performed at all three. We had to keep it in-house for ITAR reasons, but there was no point in paying some third party to store our data.
Tape, USB sticks, dusty HDDs — all fair game if you’ve got the discipline.
But for the rest of us who’ve seen one too many "Oops, we got encrypted" stories, going offline needs to be more than just cheap drives and wishful thinking.
There’s stuff out there now that gives you true air-gapped immutability without the babysitting — no firmware updates, no admin backdoors, no phoning home.
Think of it as tape’s revenge arc — minus the rewind button.
Most of those affected won't be directly using Oracle Cloud. They'll be using NetSuite, or another SaaS app (Zoom etc) that runs on Oracle Cloud. A quick look at the domains affected will show this - lots of SMEs .This needs to be called out in the article.
I assume the laws are different in the US. If this had happened in the UK then Oracle would have been legally required to report the breach to the ICO within 72 hours of becoming aware of it. Failure to do so would have exposed them to a fine of up to £8.7 million or 2% of global turnover.
oracle's state-of-the-art system/software has slightly less security than keeping your data on the desktop in a plaintext file called not_a_secret.txt
Seriously. Remotely...2-3mins to access ANY oracle subsystem. With local access, you're down to less than 30seconds to have full admin control of an entire database.