• On GameSpot: And the best games of E3 were...
October 31, 2005 11:07 AM PST

Oracle: Policies can protect passwords

by Joris Evers

In response to criticism published by two researchers last week that the protection mechanism for Oracle database user passwords is weak, Oracle is reminding users to apply good password protection policies.

"We feel strongly that the issues noted in the paper can be addressed through good password policy management, which dramatically reduces the inherent security risks associated with any password-based authentication system, and through use of security features included with the Oracle database, such as facilities to enforce password complexity, account lockout after multiple login failures and password expiration," Oracle said in a statement sent via e-mail late Friday.

The experts called on the software maker to improve the mechanism used to secure passwords for database users. They said they found a way to recover the plain text password from even very strong, well-written Oracle database passwords within minutes. (Download PDF of their paper.)

"The paper published by SANS exposes the location in the Oracle data dictionary where the Oracle password hashes are stored. By default, access to this table is restricted to a limited number of highly privileged database users," Oracle said. "Good enterprise password policies will dramatically reduce the inherent security risks associated with any password-based authentication system."

The database password security is the latest critique of Oracle's security practices. The software maker is also under fire for tardiness in patching security flaws and delivering faulty security updates.

Recent posts from News Blog
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Was InfoWorld's CTO of the Year award a year late?
VMWare VI4 renamed to vSphere
advertisement

Making sense of Windows 7 upgrades

faq The basics and the fine print on Microsoft's options for those eyeing the next operating system from Redmond.
• Full Windows 7 coverage

Road Trip 2009: Big Sky Country

CNET News reporter Daniel Terdiman takes his car full of gadgets to the Rockies and the Great Plains in search of tech, science, nature, and more.
• America's Fortress: Cheyenne Mountain

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right