The last day of the conference already... The day started with a presentation on Datamodelling using JDev . The presenter showed how JDev could replace Designer for modelling. Imho JDev doesn't support logical modelling at all (he misused Java class models to represent a logical model), there is no repository and no relation between a logical and physical model. For just physical modelling JDev is fine, because all 11g database options are included. This modelling option will become available in SQL Dev also.... After that I went to see my esteemed colleague Peter Lorentzen's talk on How to make your APEX Application Secure . He stated that APEX is secure, but developers make it unsecure . Nice statement Peter! One of his (many) good advices was not to use XE for an APEX (open) production environment as XE is not patched and you will be vulnerable to all kinds of attacks. He also showed a script attack by adding a small "Hello World" script as a value for a database v