Friday, March 19, 2010

Another example of Oracle not focusing on Best Practices

Look at Metalink Note 227010.1. This note is for "Script to check for Default Passwords being used for some common usernames."

Why just 'common' usernames? Why not all usernames? Why can't they maintain this document and the related test scripts for all known usernames? Would it be so difficult to put into their development QA process to update this document when a new schema is added or another type of default database user is added? It is ironic that this script published doesn't even take into account all the usernames suggested to monitor in their own "Best Practices" document - 189367.1 and 403537.1 which aren't being maintained (reference earlier blog).

Yet another example... Oracle, where is your Norman?

No comments: