Call: +44 (0)1904 557620 Call
Blog

Pete Finnigan's Oracle Security Weblog

This is the weblog for Pete Finnigan. Pete works in the area of Oracle security and he specialises in auditing Oracle databases for security issues. This weblog is aimed squarely at those interested in the security of their Oracle databases.

[Previous entry: "Alex Kornbrust has presented at Blackhat Amsterdam on Oracle Rootkits"] [Next entry: "Alex Kornbrusts repscan tested and added to oracle security tools page"]

identity theft and database security



I was browsing TheRegister website and saw an interesting post there by Thomas C Greene titled "ID theft is inescapable". This news item talks about the increase in identity theft disclosures from major concerns with March seeing an explosion in cases. Thomas wants to make a big point of the fact that none of the reported cases involved online transactions. The main problem is the fact that in the US merchants could sell information about you that is held in their databases from data captured during transactions etc. The problem is data is being leaked from databases, critical data. Some of the issues are related to good old dumpster diving and other manual techniques but some are related to the insecurity of the data in the database. This is an interesting news story and also one that should prompt, owners of companies, security admin's, DBA's and anyone else involved with data held in an Oracle database to consider the security of that Oracle database.