Risky Business

Risky Business #786 -- Oracle is lying

16 snips
Apr 2, 2025
Tjaden Hess, a Principal Security Engineer at Trail of Bits specializing in cryptography and cryptocurrency exchange security, joins the discussion on recent cybersecurity events. He highlights the alarming breach at Oracle, casting a critical eye on their lack of transparency regarding the exposure of sensitive health data. Hess also emphasizes the essential practices for secure cryptocurrency exchanges, particularly the importance of cold wallets, and contrasts these with the vulnerabilities revealed in the Bybit incident. The conversation paints a vivid picture of the cybersecurity landscape's ongoing challenges.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Oracle Breaches

  • Oracle's security practices are under scrutiny after two breaches.
  • One involved Oracle Health, the other their cloud infrastructure.
INSIGHT

Oracle's Response

  • Oracle's breach response involves instructing customers to communicate only via phone with the CISO, not email.
  • This, along with downplaying data contents, raises concerns.
ANECDOTE

Outdated Systems on Oracle Cloud

  • Adam Boileau found outdated, end-of-life Oracle systems still running on Oracle Cloud.
  • These systems have questionable certificate names like "cloudadmin.us9" or "star.usgov".
Get the Snipd Podcast app to discover more snips from this episode
Get the app