The Register® — Biting the hand that feeds IT

Feeds

Oracle security claim to be debunked – expert

Can Ellison redefine 'unbreakable' in time?

  • print
  • alert

Customer Success Testimonial: Recovery is Everything

An Oracle advertisement emailed last week to InfoWorld subscribers typifies the software company's newest marketing campaign. It begins with the unsettling assertion that annual computer security incidents have increased ten-fold since 1997, then lists the ways that the company's database products can defend the reader against hackers. The ad ends with a now-familiar claim, "Oracle9i. Unbreakable. Can't break it. Can't break in."

That simple bold message of invulnerability has grown into something of an IT cultural touchstone since Oracle CEO Larry Ellison unveiled the campaign at Comdex last November. The "unbreakable" claim is writ large on billboards, sent out in email ads, printed in the glossy pages of magazines, and displayed on Web banners. Type "unbreakable" into Google and a sponsored link to Oracle is likely to pop up on top. The campaign seems to touch a chord, implicitly promising safety from unseen attackers, and certainty in an uncertain time.

If the marketing message suffers from one flaw, it is this: It isn't exactly true. In December, U.K. security researcher David Litchfield revealed that a common programming error -- a buffer overflow -- was present in Oracle's application server, potentially allowing hackers to gain remote access to the system over the Internet. PenTest Limited and eEye Digital Security followed up with advisories of their own on less severe holes. Fixes are available for all three bugs on the Oracle Web site, but the damage to the company's "unbreakable" messaging isn't as easily patched.

"If to them 'unbreakable' doesn't even mean they eliminate buffer overflows, how can it possibly mean they've secured the hard stuff?," says Bruce Schneier, founder and CTO of Counterpane Internet Security. "Fixing buffer overflows is the price of admission."

Making matters worse for Oracle, it turns out that those holes were little more than a prelude to a suite of at least seven vulnerabilities currently in the company's patch pipeline -- all of them discovered by Litchfield last fall. Assuming fixes are available in time, Litchfield plans to present the holes at a security conference in early February, including details of serious bugs that allow attackers to both "break it" and "break in."

"They range from buffer overflows, to something in the way Oracle communicates with different components," says Litchfield, lead designer and developer at NGSSoftware. "We can actually interject ourselves in between that communications process and run commands as SYSTEM on Windows NT or 2000. If it's running on a Unix system, we can run commands as the Oracle user remotely... So it's obviously very serious."

While Oracle's vulnerabilities are no greater in number or severity than those found in other major software products, some experts charge that the steady stream of security holes transforms "unbreakable" from a harmless marketing gimmick into a potentially dangerous misstatement.

"The more people out there saying they have an unbreakable product, it gives customers a false sense of security," says David Dittrich, senior security engineer at the University of Washington. "I'd rather they boast about having a good programming team, or a good auditing process."

'Obvious' Hole in Database Server

"We all know it's breakable," says Tim Mullen, CIO of AnchorIS.Com, and a columnist for SecurityFocus. Mullen broke the news of the latest batch of Oracle holes in a recent column critical of the company. "The only people who don't know it's breakable, apparently, are Ellison, and the reportedly high numbers of businesses that have now chosen to purchase the product as a result of the 'Unbreakable' campaign," Mullen says.

But Oracle chief security officer Mary Ann Davidson says the criticism is unfair. In an emailed response to Mullen's commentary, Davidson wrote that Oracle is giving the holes reported by Litchfield the "highest priority," but suggested that everything depends on what your definition of "unbreakable" is.

Rather than representing a literal claim that Oracle's products are impregnable, the campaign "speaks to" fourteen independent security evaluations that Oracle's database server passed, Davidson wrote, and "represents Oracle's commitment to a secure product lifecycle for our entire product suite."

"We believe the market effect of the 'Unbreakable' campaign raises the security bar and therefore improves security overall, both in forcing us to live up to the statement, and forcing others in the industry to begin to do the same," wrote Davidson. "If our security today is imperfect but better than the competition, and if customers make a buying decision based on that criteria, than in the long term you will see all products in the market improve."

A company spokesperson declined to discuss any particular security holes, or how they can be reconciled with Oracle's "Unbreakable" and "Can't break in" claims. But in a written statement, the company emphasized that Oracle responds quickly to close newly-discovered vulnerabilities -- an assessment with which Litchfield agrees.

"The Oracle database server itself runs on some sixty odd different operating systems," says Litchfield. "They have to test each different operating system. A couple of months is a speedy response."

Litchfield discovered the slew of vulnerabilities while developing NGSSoftware's Oracle security scanner, planned for release next month. He issued an advisory on one of the holes in December, after Oracle made a fix available. Details on the other, more serious holes remain a closely held secret pending more patches, which Litchfield hopes to see the company deliver in time for a presentation he has planned for the Black Hat Windows Security conference in New Orleans on 7 February.

He says he's not aware of any of the holes being actively exploited by hackers, but offers that one of the more serious vulnerabilities has been in every revision of Oracle's database server since at least Oracle 8, which was released in 1999. "When this information goes public, you'll go, 'Oh my God, that's so obvious, why didn't anybody think of that before?," says Litchfield.

Litchfield says he isn't bothered by Oracle's "Unbreakable" claim -- he's satisfied with Davidson's explanation that the campaign is really just meant to underscore the software's lineup of security certifications. But Schneier, and other experts, say that security is too serious to be made the stuff of exaggerated marketing claims.

"I don't like it when marketing jargon takes over reality," says Schneier. "The word 'unbreakable' has a meaning in English. When they say their software is unbreakable, they're lying."

© 2001 SecurityFocus.com All rights reserved.

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

More from The Register

Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Apple: iOS7 dayglo Barbie makeover is UNFINISHED - report
Plus: You don't like the icons? Blame marketing
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry