

Risky Business #786 -- Oracle is lying
16 snips Apr 2, 2025
Tjaden Hess, a Principal Security Engineer at Trail of Bits specializing in cryptography and cryptocurrency exchange security, joins the discussion on recent cybersecurity events. He highlights the alarming breach at Oracle, casting a critical eye on their lack of transparency regarding the exposure of sensitive health data. Hess also emphasizes the essential practices for secure cryptocurrency exchanges, particularly the importance of cold wallets, and contrasts these with the vulnerabilities revealed in the Bybit incident. The conversation paints a vivid picture of the cybersecurity landscape's ongoing challenges.
AI Snips
Chapters
Transcript
Episode notes
Oracle Breaches
- Oracle's security practices are under scrutiny after two breaches.
- One involved Oracle Health, the other their cloud infrastructure.
Oracle's Response
- Oracle's breach response involves instructing customers to communicate only via phone with the CISO, not email.
- This, along with downplaying data contents, raises concerns.
Outdated Systems on Oracle Cloud
- Adam Boileau found outdated, end-of-life Oracle systems still running on Oracle Cloud.
- These systems have questionable certificate names like "cloudadmin.us9" or "star.usgov".