Oracle lags on patch management
Oracle needs to improve
patch management, an area where it's currently lagging five years behind Microsoft,
according to database expert Karel Miko at Czech consultancy DCIT.
"When Microsoft announced Trustworthy Computing a lot of people laughed,
but now you see a real difference," said Miko, who spoke at the European
Computer Audit Control and Security Conference in Stockholm.
"I don't like Microsoft, but Oracle definitely has something to learn,"
he said.
Microsoft offers central patch management tools that allow customers to see
what patches are missing and so on, whereas Oracle doesn't.
Oracle also doesn't make life easier for companies who want to keep their databases
secure, according to Miko, making it complex to download and install patches.
It also has a strange approach to new vulnerabilities, he said.
"An independent consultant announces a vulnerability to Oracle. Three
months go by, and nothing happens, six months, a year and still nothing. Oracle
puts it in a queue and will solve it sometime, maybe," said Miko.
If customers put pressure on Oracle it might be prompted to improve, but Miko
isn't holding his breath.
"Customers are very dependent on Oracle -- its database is number one.
If you have an application based on an Oracle's database there is no way to
change, in maybe 90 percent of all cases," he said.
Databases are one of the hottest topics at EuroCacs; no other product category
has more sessions.
That's good because database security is lagging behind. Even though Oracle
has been adding new security features customers aren't taking advantage of them.
"To be honest a lot of companies aren't even using the basic stuff that
has been there since version 8," said Miko.
In the end database security is all about people.
"In my experience even some small enterprises have better administrators
than large banks, and do a better job," said Miko.
IDG News Service
Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.
Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.
Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.
Crimeware: Understanding New Attacks and Defenses
By Markus Jakobsson, Zulfikar Ramzan
Published Apr 6, 2008 by Addison-Wesley Professional. Part of the Symantec Press series.
Enter now! | Official rules | Sample chapter
Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures
By Peter Thermos, Ari Takanen
Published Aug 1, 2007 by Addison-Wesley Professional.
Enter now! | Official rules | Sample chapter







