Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.os.development > #9337

Re: The morality of operating system security

From Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm>
Newsgroups alt.os.development
Subject Re: The morality of operating system security
Date 2016-03-30 23:18 -0400
Organization Aioe.org NNTP Server
Message-ID <20160330231852.794ac607@_> (permalink)
References <nde25k$bkn$1@dont-email.me> <20160329173929.65060450@_> <ndhme3$9p5$1@dont-email.me>

Show all headers | View raw


On Thu, 31 Mar 2016 00:13:49 +0100
James Harris <james.harris.1@gmail.com> wrote:

> On 29/03/2016 22:39, Rod Pemberton wrote:
> > On Tue, 29 Mar 2016 15:09:35 +0100
> > James Harris <james.harris.1@gmail.com> wrote:  

> >> Consequentially, Apple have been somewhat embarrassed that their
> >> security has been broken.  
> >
> > I don't know if they're embarrassed, yet.  
> 
> Well, their argument was that they wanted their phone encryption to
> be (known as) unbreakable. But someone broke it.

I'm still not sure that the encryption was broken, only
that the data was accessed through indirect means.

> Yes, except that, to me the question is not so much one of open or 
> closed but restricting who can have access to certain information.
> 
> To illustrate, there was a story of some admin person burning the 
> records of thousands of people onto two CDs and then popping them in
> the post. :-( That was a stupid thing to do and the CDs went missing.
> The problem, IMO, was permitting that admin person to see the data in
> the first place, and allowing any kind of copy to be made.

1) how exactly does one administrate a computer system without
also having access to user/customer/patient data?

In order for the administrator of the computer systems
to not have access to customer data, the data would have
to be encrypted, that administrator would have to not have
access to those encryption keys.  This implies that there
would need to be a second "administrator" for controlling
the encryption keys for the restricted data and perhaps
passwords for the account that could decrypt the data.
Needing an extra employee is an extra expense, unless some
other employee is given the duty. Most systems are not set
up this way, i.e., the sole administrator usually has full
access to everything.  Apparently, the system Edward Snowden
accessed was set up similarly, i.e., even the administrator
was restricted as to what he could access, but he conned
people into giving up their passwords, allowing decrypted
access, whenever they had a computer problem.

The brokerage I worked for had to set up two computer systems
to mostly keep user data separate, but that only worked to
ensure customer privacy from most employees, not everyone,
Perhaps, 70% to 90% of the employees were blocked, I don't have
exact figures.  The people administering the customer account
computer system, and the employees managing the customer accounts
on behalf of customers, or those handling customer account
problems had access to the customer's personal and account
information.  Some employees have to be trusted, typically many.


2) how do you prevent CDs or backups from being made?

Most computers have CDs in them.  Those same computers use the CDs,
or laser-discs, or tape, etc, to make backups.  It's usually the
admin's job to make those backups.  I'm not familiar with the
particulars of the example you cite, but it was probably his job
to do that, and then mail them to secure storage.  He could
have diverted the CDs, or they could have been lost, misplaced,
or stolen.  It's up to authorities to find out.

> Another story was of admin workers - in India, IIRC - who acquired 
> customer details and built up their own database. They then sold this 
> info on the black market.

All industries have these problems.  Bank employees have access
to your personal info and financial info.  Hospitals have access
to your personal info and health records.  The human resources or
personnel department at work has all your personal info, employment
info, some insurance info and some health info.  The government
has access to all your personal info and tax records.  This is
an employee trust issue, and/or a process trust issue.  Society
needs way, way too many people in the loop of trust.  :-(

AISI, the real problem is either:
1) company's aren't willing to pay for good security
2) company's are ignorant of the ease with which computer
security is breached by otherwise unskilled individuals

> My view is I don't mind specific security services accessing
> anything on my computers if it saves my life and that of my
> family from terrorism

Why would you be a target of terrorism?  I mean, other than
a random event, you wouldn't likely be targeted in advance
by terrorists.  You might be targeted in advance by criminals.
So, why would your computer have anything related to terrorism
on it which could be used by law enforcement to save your life?
This is a "non sequitur" for me.  Explain please.

While in college, I roomed with a friend.  We were in a large
apartment complex, multiple buildings with many floors.  In
one of the adjacent buildings, one criminal found out where
another lived and murdered him.  My roommate immediately
freaked out and decided he was going to move as soon as possible.
The event had nothing to do with him or me.  It wasn't even in
our building.  It was nearby in the same complex.  It was a
completely random event. I pointed this out to him.  He still
moved.  Reason couldn't break his fear.  From my perspective,
this was an overreaction, but people respond to nearby terrorism
in much the same way.

What is the likelihood that a train station will have a repeat
terrorist attack after law enforcement enhances their presence?
It's slim to none.  How long is it before people become
comfortable with visiting that train station?  Many years ...

I had an an airplane flight just a couple of weeks after 9/11.
I think there were maybe five or six people on the plane, not
including the crew.  I wouldn't doubt it if half the passengers
were law enforcement.  That flight would've been packed weeks
earlier with hundreds of people.  What was the probability that
terrorists managed to attack a plane immediately after 9/11?
It was slim to none.  There are about 350 million people in the
U.S.  Look at the response of the U.S. government for only a
few thousand killed.  Homicide in the U.S. had four times as
many deaths in 2001 as the 9/11 attacks.  Homicide ranked as
the 19th cause of death in 2001, well below the 1st ranked heart
disease of 610,638.  I'm not trivializing the 9/11 tragedy, loss
of life, loss of loved ones, or that America was attacked, but
we spent billions and lost as many or more soldiers as the
terrorists killed.  If that's not an overreaction, I don't know
what is.  And, we're financially responsible for rebuilding the
countries we invaded in response to 9/11.  And, those that
survived our onslaught in the middle east will be our lethal
enemies for generations.  I don't see how this benefits the U.S.

> but I don't want my info to be seen by anyone else.

Don't encrypt the home computer.  Don't put a password on it.
Then, law enforcement can access it in an emergency situation.

However, criminals would have full access too, if you were
the victim of a break in.  But, why they would steal the home
computer is beyond me.  They want stuff which is non-traceable,
liquid, and easily salable, e.g., cash, credit cards, common
jewelry, smartphones, GPS devices.  In general, they don't want
gold coin, rare coins, stamps, gold bars, exquisite jewelry,
because all that stuff is unique, sometimes marked with a serial
number, and is easily tracked by law enforcement via pawn shops
or jewelry stores.  Recent legal changes here even require
people selling scrap for cash to provide their personal info
on a form to the state to help prevent or reduce thefts.
It's big brother.  Everybody and everything will be tracked.
After Brussels, they're trying to prohibit buying or using
a smartphone without providing your personal information, i.e.,
no "burner" smartphones or pre-paid cash cellphones.  Big
Brother.  Total government surveillance and tracking.

> I would not even want the head of the government to
> see it without a court order.

Good choice.  Can you enforce it?  We found out we couldn't.
I.e., rights of ordinary U.S. civilians were violated by
a secret court, with the good intent of chasing terrorists,
but the government still violated our rights in the process.
The U.S. people have not, and probably will never, see any
redress.

> But there are people whose job it is to prevent terrorist
> attacks and one main reason they foil plots is because of
> accessing sensitive information.

Didn't the Nazi's use similar rationale when they got
everyone to snitch on the Jews in hiding?  I.e., the
Jews were a threat and it was the Nazi's job to get
the information to prevent the threat?  Or somesuch, ...
Governments can rationalize anything.  We see China
as being authoritarian and oppressive, much like Nazi
Germany.  China sees themselves as enforcing the laws.


Rod Pemberton

Back to alt.os.development | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-29 15:09 +0100
  Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-30 00:03 +0700
    Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 19:39 +0200
    Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:54 +0100
      Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-31 06:16 +0700
  Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 20:01 +0200
    Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:59 +0100
      Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-03-31 17:47 +0200
        Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 08:11 +0100
          Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-01 18:25 +0200
            Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 23:10 +0100
              Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-02 14:18 +0200
      Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-04-01 09:58 +0200
        Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 10:06 +0100
  Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-29 17:39 -0400
    Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-31 00:13 +0100
      Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-30 23:18 -0400
        Re: The morality of operating system security "Alexei A. Frounze" <alexfrunews@gmail.com> - 2016-03-31 00:31 -0700
          Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-31 16:57 -0400
        Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 09:22 +0100
          Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-01 20:24 -0400
            Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-09 18:25 +0100
              Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-09 18:57 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-26 09:07 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-26 23:58 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:01 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-27 05:42 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-03 00:05 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-03 16:55 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-04 09:00 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-04 17:22 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-05 17:02 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-05 17:55 -0400
                Re: The morality of operating system security "Kerr Mudd-John" <admin@127.0.0.1> - 2016-05-09 14:58 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-12 17:46 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-15 00:11 +0100
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:44 +0100

csiph-web