Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When Oracle were originally informed about it in April it wasn't a zero day. They could have rolled out a fix on their next scheduled update and it would have been patched for everyone before it became public.


Hearing "Oracle ignored a critical security flaw" is so extremely ordinary that I almost just skipped this post. The only new thing is that they have found a new product for which they can neglect to provide security updates.

They have one of the worst records on this. (Is SGI still is business?)


> (Is SGI still is business?)

It's merged with Rackable (and called SGI), but I don't think they still support IRIX.


Old-SGI (Silicon Graphics, Inc.) went bankrupt. The assets were sold to Rackable. Which then renamed itself as "Silicon Graphics International", or new-SGI.

Despite sale of assets and similar names, they're separate companies.


Yes, SGI is still in business. I use two of their large storage clusters. One CXFS, the other DMF.


No, but it could have been without them knowing it. Just because an exploit hasn't been found and publicized by a security firm, doesn't mean black hats couldn't have found the bug and been using it without it being widely known.


So should we expect vendors to immediately fix all vulnerabilities and release the fixes immediately?

That creates a near-constant stream of updates which is difficult for users & sysadmins to manage, and is why Microsoft and others have a "Patch Tuesday".

(I know that Oracle didn't do that here, but that's what the GP post was talking about)


I don't think immediate fixes are reasonable, but expecting a <3mo rollout for critical vulnerabilities (such as this one) isn't unreasonable at all. If they plan to fix this in October, that's 6 months; regardless of a 0-day being out or not, that's pretty abysmal. Of course, Oracle is not the only company that does this, but that doesn't make it okay.


Why can't the sysadmin wait for a week and let the patches accumulate?


Usually (and hopefully) the exploit isn't public yet. But as soon as the patch is released the bad guys can figure out what the exploit is and start attacking unpatched machines.

If the sysadmins know when the patches are coming out then they can schedule downtime in advance and get things patched very soon after they're released.


Interesting, I was under the impression that most of the time the exploit was known before the patch release. But of course the patch gives away everything. Live an' learn.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: