• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that

2

Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI

3

The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises

1

Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that

2

Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI

3

The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
TechChanging Face of Security

Oracle’s security chief posted a crazy ranting tirade. Then Oracle deleted it.

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
August 11, 2015, 7:41 PM ET
Oracle To Report Quarterly Earnings
REDWOOD CITY, CA - DECEMBER 16: A traffic sign with the Oracle logo is displayed outside of the Oracle headquarters on December 16, 2014 in Redwood City, California. Oracle will report second quarter earnings on Wednesday. (Photo by Justin Sullivan/Getty Images)Photograph by Justin Sullivan — Getty Images

Take note: If your job is to protect software, it’s probably not a good idea to tick off hackers.

Mary Ann Davidson, the chief security officer of Oracle (ORCL), the world’s second-largest software maker, has said she’s been irritated by how often she’s had to have a particular conversation with computer crackers. While the hackers like to point out what they deem to be security flaws in Oracle software—in the hopes of winning compensation and credit—she has to keep telling them that they’re violating their licenses by engaging in such research.

The volume and generally poor quality of the findings have been distracting and frustrating for her team, she has said.

So to hell with it, she decided on Monday. In a state of apparent exasperation, she penned a long, ranting tirade against vulnerability-hunting security researchers. The post didn’t last long on the company’s corporate blog, however, before Oracle pulled it down. (You can read an archived version here.)

Rather than welcoming a helping hand from the hacker community (or even politely demurring), Davidson smacked the living bejesus out of it. “Please Stop It Already,” Davidson wrote, exhorting computer bug hunters who reverse engineer Oracle source code in the hopes of finding flaws to quit the practice. In so doing, researchers often break the terms of the company’s end user license agreements, she noted. “Please don’t go there,” she said. “Don’t. Just—don’t.”

 

“I’m not beating people up over this merely because of the license agreement,” she continued, citing a prevalence of false positives turned up by security consultants and scanning tools as an unwelcome nuisance. “(P)lease do not waste our time on reporting little green men in our code. I am not running away from our responsibilities to customers, merely trying to avoid a painful, annoying, and mutually-time wasting exercise.”

To paraphrase: We can handle our security ourselves, thank you very much.

Oracle deleted the blog post shortly after it appeared. “We removed the post as it does not reflect our beliefs or our relationship with our customer,” read a statement provided to Fortune by a company spokesperson, attributed to Edward Screven, Oracle executive vice president and chief corporate architect.

But Davidson’s screed had already struck a nerve in the security community. (Search the hashtag #oraclefanfic on Twitter, for instance.)

“I understand what Mary Ann was trying to achieve with this post, but what they really need is a way to control the flow of information without simply saying ‘Don’t… Just don’t,'” commented the co-founder and CEO of bug bounty startup BugCrowd, via email. “All that being said, I’m really glad that they took the post down. This means, in spite of the tone of the email, she’s listening to the community (who had a unanimously bad reaction).”

Chris Wysopal, chief technology and information security officer at the application security firm Veracode, weighed in via email, too. He described Davidson’s “discouraging” remarks as “an attempt to turn back the progress made to improve software security.”

In a mock Q&A, Davidson explained what would happen in the event that a researcher did find a true bug. In short: her team would fix it quietly, begrudgingly, without thanks, and move on.

Q. What does Oracle do if there is an actual security vulnerability?

A. I almost hate to answer this question because I want to reiterate that customers Should Not and Must Not reverse engineer our code. However, if there is an actual security vulnerability, we will fix it. We may not like how it was found but we aren’t going to ignore a real problem – that would be a disservice to our customers. We will, however, fix it to protect all our customers, meaning everybody will get the fix at the same time. However, we will not give a customer reporting such an issue (that they found through reverse engineering) a special (one-off) patch for the problem. We will also not provide credit in any advisories we might issue. You can’t really expect us to say “thank you for breaking the license agreement.”

There is, of course, a danger in alienating bug hunters. Code has flaws. And laying down a prohibition against finding them will not stop security researchers from continuing to poke around. Without an alternative option, those researchers might simply choose sell their findings to the highest bidder. Say, an unfriendly nation state.

Perhaps Oracle might benefit from a policy update, one that does not forbid vulnerability-seeking and one that clearly delineates what counts as a valid bug and what does not. Already, big tech companies ranging from Google (GOOG) to Microsoft (MSFT) sponsor bug bounty programs. More recently, United Airlines (UAL) and Tesla (TSLA) have hopped on board with programs of their own.

According to Josh Corman, founder of the security advocacy group I am the Cavalry, not attacking bug hunters and those that approach companies with vulnerabilities is a best practice.

There might be fewer erroneous submissions and ticked off hackers that way—and more importantly, better security.

[fortune-brightcove videoid=4414732304001]

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

SpaceX heads into a record-shattering IPO with the ‘deepest moat that exists today’ as investors vow to ‘never bet against Elon’
InnovationIPOs
SpaceX heads into a record-shattering IPO with the ‘deepest moat that exists today’ as investors vow to ‘never bet against Elon’
By Jason MaMay 16, 2026
3 hours ago
tarot
AICulture
We talked to 12 tarot card readers who are using AI. They split in 2 camps, with big implications for the technology
By Ziv Epstein, Farnaz Jahanbakhsh, Vana Goblot and The ConversationMay 16, 2026
5 hours ago
liberman
Commentarystart-ups
We watched social media concentrate. The same thing is happening in AI, only at a deeper layer
By David Liberman and Daniil LibermanMay 16, 2026
6 hours ago
mustafa suleyman
AIMicrosoft
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
By Jake AngeloMay 16, 2026
7 hours ago
olivier
CommentaryAnthropic
I’ve been studying Big Tech for a long time. What just happened with Anthropic and the Pentagon terrifies me
By Olivier SylvainMay 16, 2026
7 hours ago
bhaskar
Economydisruption
The prophet of the ‘Wired Belt’ says capitalism is finally eating itself
By Bhaskar ChakravortiMay 16, 2026
9 hours ago

Most Popular

Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that
Success
Despite having a $165 million net worth, Scarlett Johansson says work-life balance doesn’t exist—and the first step to success is admitting that
By Preston ForeMay 13, 2026
3 days ago
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
AI
Microsoft AI chief gives it 18 months—for all white-collar work to be automated by AI
By Jake AngeloMay 16, 2026
7 hours ago
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
Politics
The Bezos family just donated $100 million to help achieve one of Mayor Zohran Mamdani’s top campaign promises
By Jake AngeloMay 12, 2026
4 days ago
Current price of oil as of May 15, 2026
Personal Finance
Current price of oil as of May 15, 2026
By Joseph HostetlerMay 15, 2026
1 day ago
Meet the 20-year-old CEO who launched a company in high school to solve Gen Z's entry-level job crisis
Future of Work
Meet the 20-year-old CEO who launched a company in high school to solve Gen Z's entry-level job crisis
By Jake AngeloMay 16, 2026
11 hours ago
Debbie Gibson, Geezer Butler of Black Sabbath want you to adopt a beagle rescued from an experimental lab in Wisconsin
North America
Debbie Gibson, Geezer Butler of Black Sabbath want you to adopt a beagle rescued from an experimental lab in Wisconsin
By Scott Bauer and The Associated PressMay 13, 2026
3 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.