Received: (qmail 28390 invoked from network); 5 May 2011 14:05:12 -0500
Received: from freelists-180.iquest.net (HELO turing.freelists.org) (206.53.239.180)
  by static-ip-85-25-126-90.inaddr.intergenia.de with SMTP; 5 May 2011 14:04:51 -0500
Received: from localhost (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id 4C193E11B7E;
 Thu,  5 May 2011 15:04:49 -0400 (EDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=freelists.org;
 s=turing; t=1304622289; bh=V0Qm+3RZBUvcUOU8lvc5oBRMTWoMHKtjBeVdhdci
 KZs=; h=MIME-Version:In-Reply-To:References:Date:Message-ID:Subject:
	 From:To:Cc:Content-Type:Sender:Reply-To:List-help:List-unsubscribe:
	 List-Id:List-subscribe:List-owner:List-post:List-archive; b=IwS0fc
 t4UorkNijCFXF/qIcF5mdiq/K+dRQXufOR9vnOWgnH1mqvQBGz4QuaL6b8WdcRRjBgo
 mRzUnwJBmpjlZyzIE44oNdGdrLJ31+OQ6W+iyPJ7x6AdSuKERGbN7TYKSM/IVx/hPIE
 mCsNOJOt9IJgUZnULRq67CmZLWU9TUc=
X-Virus-Scanned: Debian amavisd-new at localhost.localdomain
Received: from turing.freelists.org ([127.0.0.1])
 by localhost (turing.freelists.org [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id EBjz9abStd8Q; Thu,  5 May 2011 15:04:49 -0400 (EDT)
Received: from turing.freelists.org (localhost [127.0.0.1])
 by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id BCCC5E11AE0;
 Thu,  5 May 2011 15:04:05 -0400 (EDT)
Received: with ECARTIS (v1.0.0; list oracle-l); Thu, 05 May 2011 15:03:24 -0400 (EDT)
Received: from localhost (localhost [127.0.0.1])	by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id A37BCE11AB1	for <oracle-l@freelists.org>; Thu,  5 May 2011 15:03:23 -0400 (EDT)
Authentication-Results: turing.freelists.org; dkim=pass (1024-bit key) header.i=@gmail.com
Received: from turing.freelists.org ([127.0.0.1])	by localhost (turing.freelists.org [127.0.0.1]) (amavisd-new, port 10024)	with ESMTP id rAeHNXWvasSL for <oracle-l@freelists.org>;	Thu,  5 May 2011 15:03:23 -0400 (EDT)
Received: from mail-bw0-f51.google.com (mail-bw0-f51.google.com [209.85.214.51])	by turing.freelists.org (Avenir Technologies Mail Multiplex) with ESMTP id DFEC3E117CC	for <oracle-l@freelists.org>; Thu,  5 May 2011 15:03:22 -0400 (EDT)
Received: by bwz10 with SMTP id 10so2042394bwz.10        for <oracle-l@freelists.org>; Thu, 05 May 2011 12:03:21 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com; s=gamma;        h=domainkey-signature:mime-version:in-reply-to:references:date         :message-id:subject:from:to:cc:content-type;        bh=NtdtizDLEuTAnJmj0K03narvymBRXvpv/eT3hNbhOUA=;        b=uw+FrMqnWznPo/cMgNdk36HauQnOy1Bw0nnX+ovebN6cwWoDC+uRy87Mz/QT7JFnDA         473eTQJ0nbo8LTfGl21zC7XqHiCVnULmJIYFFcj2g3SWVAWjRCpM9COfWPD6ckMUtU3l         rr6MXUu5Ex7XC9+sMco4AZlRw7CYYF+P9t0Q8=
DomainKey-Signature: a=rsa-sha1; c=nofws;        d=gmail.com; s=gamma;        h=mime-version:in-reply-to:references:date:message-id:subject:from:to         :cc:content-type;        b=mdX565dBQFM2Sc3sd9adoT0/GCzPwyKWq4QINTj+PJ/M87Gru2kug8m7XCjSLAUdSG         +PgSFOumDNgEFO1Ogde2e+VOZja8sbL/NgQaIE3a8bKPI2GWMn3rRGp8ds0bSeths5GG         OlPzlZ3dEoG18CfTblJcCuIp2vExTaLVkTfKQ=
MIME-Version: 1.0
Received: by 10.204.19.80 with SMTP id z16mr73000bka.198.1304622019328; Thu, 05 May 2011 12:00:19 -0700 (PDT)
Received: by 10.204.62.66 with HTTP; Thu, 5 May 2011 12:00:19 -0700 (PDT)
In-Reply-To: <BANLkTiktZo32VBeTg+G8yJU+gpjDeiFB7w@mail.gmail.com>
References: <BANLkTimwPiD0t21Fn_Fgquo6dwKYT6d5SQ@mail.gmail.com>	<BANLkTinYzNGwcHGW_7Nn3j+q8OBfJcHnvQ@mail.gmail.com>	<BANLkTinTQqORQVma6REXKTc=TbXV3TVkRA@mail.gmail.com>	<BANLkTi=Aax+kMaFityf98w_dAiQB_Fr6fQ@mail.gmail.com>	<BANLkTinW3168XiydhYiMiZDbu7WEhYm97g@mail.gmail.com>	<BANLkTiktZo32VBeTg+G8yJU+gpjDeiFB7w@mail.gmail.com>
Date: Thu, 5 May 2011 15:00:19 -0400
Message-ID: <BANLkTikoB50bj4+S2NXjNL6rHOZ3q=6wDg@mail.gmail.com>
Subject: Re: Security Question - how do you deal with sensitive information hardcoded in SQL statements
From: Michael Wehrle <michaelw436@gmail.com>
To: Jared Still <jkstill@gmail.com>
Cc: Oracle-L Freelists <oracle-l@freelists.org>
Content-Type: multipart/alternative; boundary=000325557976073d0604a28bfc9f
X-archive-position: 36122
X-ecartis-version: Ecartis v1.0.0
Sender: oracle-l-bounce@freelists.org
Errors-to: oracle-l-bounce@freelists.org
X-original-sender: michaelw436@gmail.com
Precedence: normal
Reply-To: michaelw436@gmail.com
List-help: <mailto:ecartis@freelists.org?Subject=help>
List-unsubscribe: <oracle-l-request@freelists.org?Subject=unsubscribe>
List-software: Ecartis version 1.0.0
List-Id: oracle-l <oracle-l.freelists.org>
X-List-ID: oracle-l <oracle-l.freelists.org>
List-subscribe: <oracle-l-request@freelists.org?Subject=subscribe>
List-owner: <mailto:steve.adams@ixora.com.au>
List-post: <mailto:oracle-l@freelists.org>
List-archive: <http://www.freelists.org/archives/oracle-l>
X-list: oracle-l
--000325557976073d0604a28bfc9f
Content-Type: text/plain; charset=ISO-8859-1

Jared, I have not tested this issue in 11g. I agree, that it should have
been identified as a bug, once Oracle decided to give us a one-off patch.
Its possible that it was quietly fixed in the latest versions.

On Thu, May 5, 2011 at 11:06 AM, Jared Still <jkstill@gmail.com> wrote:

> On Wed, May 4, 2011 at 6:28 PM, Michael Wehrle <michaelw436@gmail.com>wrote:
>
>> Jared, sorry about the link. It looks like they have since moved the
>> Oracle By Example series into an Apex site that uses Single Sign On. Go to
>> www.oracle.com/technetwork/tutorials/index.html, then click on the link
>> at the bottom to access the "learning library". Once you have logged in, you
>> can search for "Using Transparent Data Encryption for Database 10g
>> Release 2".
>>
>>
> Thanks, I will look for that.
>
>
>> As far as the patch, it was a one-off for my previous employer. And it
>> took lots of support calls, involving VP level and above, finally involving
>> some backline engineers to fix the problem. I am not sure what they would do
>> if you asked for the same patch, since its not publicly searchable. It never
>> hurts to ask about it though, since its truly a security issue for everyone,
>> that is not easily worked around.
>>
>>
> Have you tried this in 11g?
>
> It seems to me that failure to encrypt the data in AWR is a bug.
>
>
> Jared Still
> Certifiable Oracle DBA and Part Time Perl Evangelist
> Oracle Blog: http://jkstill.blogspot.com
> Home Page: http://jaredstill.com
>

--000325557976073d0604a28bfc9f
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Jared, I have not tested this issue in 11g. I agree, that it should have be=
en identified as a bug, once Oracle decided to give us a one-off patch. Its=
 possible that it was quietly fixed in the latest versions.<br><br><div cla=
ss=3D"gmail_quote">
On Thu, May 5, 2011 at 11:06 AM, Jared Still <span dir=3D"ltr">&lt;<a href=
=3D"mailto:jkstill@gmail.com">jkstill@gmail.com</a>&gt;</span> wrote:<br><b=
lockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px =
#ccc solid;padding-left:1ex;">
<div class=3D"gmail_quote"><div class=3D"im">On Wed, May 4, 2011 at 6:28 PM=
, Michael Wehrle <span dir=3D"ltr">&lt;<a href=3D"mailto:michaelw436@gmail.=
com" target=3D"_blank">michaelw436@gmail.com</a>&gt;</span> wrote:<br><bloc=
kquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #cc=
c solid;padding-left:1ex">


Jared, sorry about the link. It looks like they have since moved the Oracle=
 By Example series into an Apex site that uses Single Sign On. Go to <a hre=
f=3D"http://www.oracle.com/technetwork/tutorials/index.html" target=3D"_bla=
nk">www.oracle.com/technetwork/tutorials/index.html</a>, then click on the =
link at the bottom to access the &quot;learning library&quot;. Once you hav=
e logged in, you can search for &quot;<span style=3D"font-family:Arial, san=
s-serif;font-size:14px;font-weight:bold;line-height:20px">Using Transparent=
 Data Encryption for Database 10g Release 2</span>&quot;.<div>



<br></div></blockquote><div><br></div></div><div>Thanks, I will look for th=
at.</div><div class=3D"im"><div>=A0</div><blockquote class=3D"gmail_quote" =
style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><di=
v></div>
<div>As far as the patch, it was a one-off for my previous employer. And it=
 took lots of support calls, involving VP level and above, finally involvin=
g some backline engineers to fix the problem. I am not sure what they would=
 do if you asked for the same patch, since its not=A0publicly searchable. I=
t never hurts to ask about it though, since its truly a security issue for =
everyone, that is not easily worked around.</div>


<div><div></div><div>
<div><br></div></div></div></blockquote><div><br></div></div><div>Have you =
tried this in 11g?</div><div><br></div><div>It seems to me that failure to =
encrypt the data in AWR is a bug.</div><div class=3D"im"><div>=A0</div><div=
>
<br clear=3D"all">Jared Still<br>

Certifiable Oracle DBA and Part Time Perl Evangelist<br>Oracle Blog: <a hre=
f=3D"http://jkstill.blogspot.com" target=3D"_blank">http://jkstill.blogspot=
.com</a><br>Home Page: <a href=3D"http://jaredstill.com" target=3D"_blank">=
http://jaredstill.com</a><br>
</div>
</div></div>
</blockquote></div><br>

--000325557976073d0604a28bfc9f--
--
http://www.freelists.org/webpage/oracle-l


