Compare that to recent Microsoft attitude towards serious security issues, especially 0-day. They typically publish bulletins within hours just to let their customers know they take the matter seriously. Every such issue damages their reputation and affects their bottom line. Sure, impact of any Microsoft security bug is very wide - and they accepted the responsibility. But impact of an enterprise database bug of such magnitude is probably even more devastating because it hits right in the heart of an enterprise. How they can remain quiet and pretend nothing happens is beyond me. But thanks to David, now I'm forewarned and thus forearmed.

M-A.D. seems to be more concerned with the process than with deliverables I.M.O... She will probably start ranting about how irresponsible it was of David to disclose the issue without giving them time to cook a fix, and how this doesn't help security community and how damaging such disclosures are to Oracle customers, etc. I have a feeling she truly believes in security by obscurity.

She sure has her back covered, but I am not so sure about mine... David's presentation starts with some figures and rates - well, that wasn't new to me, but it's sad to see nothing changed over the last few years. The attitude didn't change. No SCS, laws or education can fix that.


