Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > alt.os.development > #9457
| From | Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> |
|---|---|
| Newsgroups | alt.os.development |
| Subject | Re: The morality of operating system security |
| Date | 2016-04-26 23:58 -0400 |
| Organization | Aioe.org NNTP Server |
| Message-ID | <20160426235820.1cd18000@_> (permalink) |
| References | (4 earlier) <ndlavp$85d$1@dont-email.me> <20160401202426.293af50b@_> <nebdns$k1m$1@dont-email.me> <20160409185740.51c7ed6d@_> <nfn7e8$tqn$1@dont-email.me> |
On Tue, 26 Apr 2016 09:07:43 +0100 James Harris <james.harris.1@gmail.com> wrote: > On 09/04/2016 23:57, Rod Pemberton wrote: > > On Sat, 9 Apr 2016 18:25:19 +0100 > > James Harris <james.harris.1@gmail.com> wrote: > Re. the encryption issues, rather than the user forgetting the key > wouldn't the OS have to know how to decrypt the stored data, and to > have the decryption key? If so, then the OS would have to ensure that > it only decrypted the data for the correct userids. I don't see encryption and decryption as something inherent to the OS, if that is what you meant. The specific OS in question would need to have the ability to encrypt or decrypt the specific protocol that was used, e.g., if someone deleted the encrypt/decrypt application, you'd have a problem until the apps were restored. Encryption and decryption can be supported on any platform that can compile said application. This implies that other systems can decrypt your OS' data, if they possess your data and also an appropriate encrypt/decrypt program. The exception is if the OS uses a unique encryption protocol, specific to that OS. I'd doubt any business would use a proprietary encryption protocol due to either time or expense. Various government entities or a military might do so, though. > > What do you to do prevent the need to delete inactive accounts? > > An organisation would have its own procedures to follow when people > leave. Account deletion should be part of that, I would think. > > In reality it might be best to mothball accounts rather than deleting > them. The owner might come back to the company. Or there may be some > other reason to reactivate an inactive account. As mentioned previously, a skilled hacker could re-activate the "mothballed" accounts. Think of a mothballed account as a backdoor to your house which uses a different key than the front door, but where you've also lost the key. The lock can still be picked, as long as it's still present and accessible. More accounts equals more doors to try. To a hacker, it doesn't matter that they're locked. If they know they're there, they'll attempt to pick them. > >> AISI the system admins could set up the structures but not be > >> allowed to see all the data. > > > > If they control whom has which privileges, how does that work? ... > > Privilege escalation is a serious problem if someone has privilege. > > How do you prevent self-dealing of privileges to the privileged? > > Raw trust? Bad choice. I think that's true whether discussing > > computer admins, or law enforcement, or government agencies. > > Even the most trustworthy people are not perfectly trustworthy. > > Trust-but-verify? Ok, I just verified that they stole > > everything ... > > Again, good questions. Could the organisation have someone senior - > even a board member or every member of the board - designated to see > a report every day, such that the report could be a single line > confirming that there were no suspicious privilege escalations or > attempts to interfere with auditing etc? > > The guard against misuse would be the inability to hide misuse from > the audit log, and the report that a senior person or persons would > see. As you say, it would not prevent misuse, only highlight it. But > that in itself would be a good deterrent. Reports can be tampered with. How do you know in advance what to monitor for suspicious activity? Do you assume the hacker will set off some randomly chosen alarm, or should you assume the hacker is skilled enough to avoid 98% of your traps? If the hacker is in the 2%, "extra-devious," then he is in your system without detection. Most good people, like those you'd trust to do your security, simply aren't devious enough to entrap someone who is devious and is experienced too. So, you need to be prepared to clean up the mess such people make. > Thank you for the courtesy of translating! But no need. I am used to > reading AmE! Ok, what are the BrE words that AmE speakers should know but don't? BrE seems to have many more words not in use in AmE. Rod Pemberton
Back to alt.os.development | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-29 15:09 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-30 00:03 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 19:39 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:54 +0100
Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-31 06:16 +0700
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 20:01 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:59 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-03-31 17:47 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 08:11 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-01 18:25 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 23:10 +0100
Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-02 14:18 +0200
Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-04-01 09:58 +0200
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 10:06 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-29 17:39 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-31 00:13 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-30 23:18 -0400
Re: The morality of operating system security "Alexei A. Frounze" <alexfrunews@gmail.com> - 2016-03-31 00:31 -0700
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-31 16:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 09:22 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-01 20:24 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-09 18:25 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-09 18:57 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-26 09:07 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-26 23:58 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:01 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-27 05:42 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-03 00:05 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-03 16:55 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-04 09:00 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-04 17:22 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-05 17:02 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-05 17:55 -0400
Re: The morality of operating system security "Kerr Mudd-John" <admin@127.0.0.1> - 2016-05-09 14:58 +0100
Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-12 17:46 -0400
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-15 00:11 +0100
Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:44 +0100
csiph-web