back to article Row rumbles on over figures in Oracle CSO’s anti-security rant

Security researchers picking through the entrails of a withdrawn blogpost by Oracle CSO Mary Ann Davidson reckon not even her figures add up. Oracle countered that only it had access to the raw figures, so there. Davidson's 3,000+ word diatribe against bug bounties, security researchers or customers hunting vulnerabilities in …

  1. SecretSonOfHG

    Oracle has a historically poor relationship with ....

    isn't this redundant? Apart from island and yatch vendors, is there any community with which Oracle has good relationships with?

    1. Fungus Bob

      Re: yatch

      You are in luck, SecretSonOfHG, "yatch" is the Creole word for yacht according to Google Translate.

      1. SecretSonOfHG

        Re: yatch

        god bless autocorrect

    2. Wzrd1 Silver badge

      Re: Oracle has a historically poor relationship with ....

      Still, could be worse. They could be Adobe.

  2. A. Lloyd Flanagan

    Does not reflect, my a**

    "does not reflect our beliefs or our relationship with our customers" Many years experience with Oracle says that rant was a perfect reflection of their attitude and relationship with customers. If you're a clueless VP who can override IT purchasing decisions, it's a different story, of course.

  3. leon clarke
    WTF?

    So, they're counting bugs found during development

    Oracle are counting bugs found during development! Arguably true, but not how anyone else in the universe counts security vulnerabilities.

    1. Anonymous Coward
      Anonymous Coward

      Today I fixed 63 security defects by staying in bed!

      Since otherwise I'd have written a few hundred lines of code and generally we reckon on a bug of some sort in every few lines and (until proven otherwise) let's regard them as insecurities.

      Armed with this new Oracle methodology I'll be sure to go to the pub later and heroically avert another few dozen. No need to thank me boss; picking up my bar tab will suffice...

  4. Your alien overlord - fear me

    Lies, damn lies and statistics.

    Did Adam Gowdiak count each individual bug reporter as a seperate entity. i.e. if I found 2 seperate bugs at different times is that 1 customer reported bug accreditation or 2? And how did Davidson count them?

    Perhaps they should put it in a database (take your pick, many out there!!!) and do a SQL SUM() on the bugs list?

    1. Pookietoo

      How do two bugs become one because they're reported by one customer? They're not considering bug-reporting customers versus total customers, but bugs reported by customers versus total bugs.

  5. Anonymous Coward
    Anonymous Coward

    Internally found and fixed bugs probably don't get added to the CVE database.

    Whether that's right or wrong...

    1. Michael Wojcik Silver badge

      That really doesn't help the picture.

      Oracle are claiming they find and fix thirty times as many security vulnerabilities as are revealed to the public. Even if that happens before the code in question is released, there's something very wrong with Oracle's development process, given the number of issues that are published.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like