Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > alt.os.development > #9347

Re: The morality of operating system security

From James Harris <james.harris.1@gmail.com>
Newsgroups alt.os.development
Subject Re: The morality of operating system security
Date 2016-04-01 09:22 +0100
Organization A noiseless patient Spider
Message-ID <ndlavp$85d$1@dont-email.me> (permalink)
References <nde25k$bkn$1@dont-email.me> <20160329173929.65060450@_> <ndhme3$9p5$1@dont-email.me> <20160330231852.794ac607@_>

Show all headers | View raw


On 31/03/2016 04:18, Rod Pemberton wrote:
> On Thu, 31 Mar 2016 00:13:49 +0100
> James Harris <james.harris.1@gmail.com> wrote:
>
>> On 29/03/2016 22:39, Rod Pemberton wrote:
>>> On Tue, 29 Mar 2016 15:09:35 +0100
>>> James Harris <james.harris.1@gmail.com> wrote:
>
>>>> Consequentially, Apple have been somewhat embarrassed that their
>>>> security has been broken.
>>>
>>> I don't know if they're embarrassed, yet.
>>
>> Well, their argument was that they wanted their phone encryption to
>> be (known as) unbreakable. But someone broke it.
>
> I'm still not sure that the encryption was broken, only
> that the data was accessed through indirect means.

OK.

>> Yes, except that, to me the question is not so much one of open or
>> closed but restricting who can have access to certain information.
>>
>> To illustrate, there was a story of some admin person burning the
>> records of thousands of people onto two CDs and then popping them in
>> the post. :-( That was a stupid thing to do and the CDs went missing.
>> The problem, IMO, was permitting that admin person to see the data in
>> the first place, and allowing any kind of copy to be made.
>
> 1) how exactly does one administrate a computer system without
> also having access to user/customer/patient data?

I don't know. I have a nebulous idea but I don't know how practical it 
is. More below.

> In order for the administrator of the computer systems
> to not have access to customer data, the data would have
> to be encrypted, that administrator would have to not have
> access to those encryption keys.

Administrators don't supply keys on demand but they interact with data 
by means of software. If anything, a program which had to display the 
data would have to have the key(s).

Wouldn't it be feasible to say that a certain administrator, using a 
certain terminal and a particular program, could access a specific piece 
of data in a limited way? That way, access to the data could be limited 
by login id, terminal authorisation and accessing program.

Then the terminal could be authorised by some means that suited the 
company, the program could be authorised by testing, and the data could 
thus be kept secure.

Anyone accessing the data without authorisation would get gibberish.

> This implies that there
> would need to be a second "administrator" for controlling
> the encryption keys for the restricted data and perhaps
> passwords for the account that could decrypt the data.

There would, at least, need to be someone to oversee the 
permissions-approval process but once approvals had been given and 
accesses were set up to be audited, normal operations could proceed 
without needing another person's input.

> Needing an extra employee is an extra expense, unless some
> other employee is given the duty. Most systems are not set
> up this way, i.e., the sole administrator usually has full
> access to everything.  Apparently, the system Edward Snowden
> accessed was set up similarly, i.e., even the administrator
> was restricted as to what he could access, but he conned
> people into giving up their passwords, allowing decrypted
> access, whenever they had a computer problem.

OK. I don't think any of is know whether Snowden's claims were real or 
false. The security services have a policy of neither confirming nor 
denying reports of what they can do. Snowden may have been making it up.

> The brokerage I worked for had to set up two computer systems
> to mostly keep user data separate, but that only worked to
> ensure customer privacy from most employees, not everyone,
> Perhaps, 70% to 90% of the employees were blocked, I don't have
> exact figures.  The people administering the customer account
> computer system, and the employees managing the customer accounts
> on behalf of customers, or those handling customer account
> problems had access to the customer's personal and account
> information.  Some employees have to be trusted, typically many.
 >
 >
> 2) how do you prevent CDs or backups from being made?
>
> Most computers have CDs in them.  Those same computers use the CDs,
> or laser-discs, or tape, etc, to make backups.  It's usually the
> admin's job to make those backups.  I'm not familiar with the
> particulars of the example you cite, but it was probably his job
> to do that, and then mail them to secure storage.  He could
> have diverted the CDs, or they could have been lost, misplaced,
> or stolen.  It's up to authorities to find out.

That illustrates that people who "need" access generally get access to 
entire files of information - and that there is no restriction on what 
they can do with those files. OSes have file permissions and that is 
simply not adequate.

IMO it would be better to give people permission to specific fields of 
data. And, as above, if the program accessing the data has to be 
authorised to do so, that program can limit itself to, say, displaying 
data on a screen, and not provide an option to do anything else with the 
data. That would prevent administrators making copies.

When info that has been certified to be publicly readable is stored on 
disc it can be stored unencrypted. All other info should be stored in an 
encrypted form.

...

> AISI, the real problem is either:
> 1) company's aren't willing to pay for good security

How would they spend more money to improve security?

> 2) company's are ignorant of the ease with which computer
> security is breached by otherwise unskilled individuals

Definitely.

>> My view is I don't mind specific security services accessing
>> anything on my computers if it saves my life and that of my
>> family from terrorism
>
> Why would you be a target of terrorism?  I mean, other than
> a random event, you wouldn't likely be targeted in advance
> by terrorists.  You might be targeted in advance by criminals.
> So, why would your computer have anything related to terrorism
> on it which could be used by law enforcement to save your life?
> This is a "non sequitur" for me.  Explain please.

Sorry, I don't mean me specifically. I was using "my" as a proxy for us 
as a population. To rephrase, I don't mind security services accessing 
our computers if it saves our lives from terrorism.

I cannot actually think of a negative effect of allowing security 
services access to our computers. They would not be interested in most 
of us, only of people who might be a threat.

I don't mind a limited group of people seeing my web browsing history or 
my emails or my texts etc. What I don't want is that info to escape and 
become visible to the wider public.

> While in college, I roomed with a friend.  We were in a large
> apartment complex, multiple buildings with many floors.  In
> one of the adjacent buildings, one criminal found out where
> another lived and murdered him.  My roommate immediately
> freaked out and decided he was going to move as soon as possible.
> The event had nothing to do with him or me.  It wasn't even in
> our building.  It was nearby in the same complex.  It was a
> completely random event. I pointed this out to him.  He still
> moved.  Reason couldn't break his fear.  From my perspective,
> this was an overreaction, but people respond to nearby terrorism
> in much the same way.
>
> What is the likelihood that a train station will have a repeat
> terrorist attack after law enforcement enhances their presence?
> It's slim to none.  How long is it before people become
> comfortable with visiting that train station?  Many years ...

Yes. It annoys me a little that security is visibly beefed-up _after_ a 
terrorist incident. I know they want to reassure. I suspect they also 
want to be seen to be doing something. But by then it is too late.

Unfortunately, there have recently apparently been _thousands_ of jihadi 
fighters brought into Europe mixed in with other migrants. That concerns 
me far more.

> I had an an airplane flight just a couple of weeks after 9/11.
> I think there were maybe five or six people on the plane, not
> including the crew.  I wouldn't doubt it if half the passengers
> were law enforcement.  That flight would've been packed weeks
> earlier with hundreds of people.  What was the probability that
> terrorists managed to attack a plane immediately after 9/11?
> It was slim to none.

Agreed, completely.

> There are about 350 million people in the
> U.S.  Look at the response of the U.S. government for only a
> few thousand killed.  Homicide in the U.S. had four times as
> many deaths in 2001 as the 9/11 attacks.  Homicide ranked as
> the 19th cause of death in 2001, well below the 1st ranked heart
> disease of 610,638.  I'm not trivializing the 9/11 tragedy, loss
> of life, loss of loved ones, or that America was attacked, but
> we spent billions and lost as many or more soldiers as the
> terrorists killed.  If that's not an overreaction, I don't know
> what is.  And, we're financially responsible for rebuilding the
> countries we invaded in response to 9/11.  And, those that
> survived our onslaught in the middle east will be our lethal
> enemies for generations.  I don't see how this benefits the U.S.

IMV the wars themselves are not to blame as much as people say. The 
problems were caused principally by the barbarous teachings within 
Islam. And secondarily by the West's lack of appreciation of the Islamic 
problems and what to do more than just win the battles.

...

>> But there are people whose job it is to prevent terrorist
>> attacks and one main reason they foil plots is because of
>> accessing sensitive information.
>
> Didn't the Nazi's use similar rationale when they got
> everyone to snitch on the Jews in hiding?  I.e., the
> Jews were a threat and it was the Nazi's job to get
> the information to prevent the threat?  Or somesuch, ...
> Governments can rationalize anything.  We see China
> as being authoritarian and oppressive, much like Nazi
> Germany.  China sees themselves as enforcing the laws.

Yes, good point. If one government's designated security services can 
access data what about the security services of another government? It 
would be difficult for an OS provider to have to decide which 
governments could have access!

Actually, I am surprised that Apple is not subject to US laws which make 
it compulsory for them to allow the US security services to access their 
products. AIUI no one can export strong encryption from the US.

Maybe that also gives the lie to Edward Snowden's claims about the 
Smurfs he alleges to be contained within people's phones...?

-- 
James

Back to alt.os.development | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-29 15:09 +0100
  Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-30 00:03 +0700
    Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 19:39 +0200
    Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:54 +0100
      Re: The morality of operating system security JJ <jj4public@vfemail.net> - 2016-03-31 06:16 +0700
  Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-03-29 20:01 +0200
    Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-30 23:59 +0100
      Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-03-31 17:47 +0200
        Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 08:11 +0100
          Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-01 18:25 +0200
            Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 23:10 +0100
              Re: The morality of operating system security Bernhard Schornak <schornak@web.de> - 2016-04-02 14:18 +0200
      Re: The morality of operating system security "wolfgang kern" <nowhere@never.at> - 2016-04-01 09:58 +0200
        Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 10:06 +0100
  Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-29 17:39 -0400
    Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-03-31 00:13 +0100
      Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-30 23:18 -0400
        Re: The morality of operating system security "Alexei A. Frounze" <alexfrunews@gmail.com> - 2016-03-31 00:31 -0700
          Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-03-31 16:57 -0400
        Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-01 09:22 +0100
          Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-01 20:24 -0400
            Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-09 18:25 +0100
              Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-09 18:57 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-26 09:07 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-26 23:58 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:01 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-04-27 05:42 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-03 00:05 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-03 16:55 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-04 09:00 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-04 17:22 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-05 17:02 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-05 17:55 -0400
                Re: The morality of operating system security "Kerr Mudd-John" <admin@127.0.0.1> - 2016-05-09 14:58 +0100
                Re: The morality of operating system security Rod Pemberton <NoHaveNotOne@bcczxcfre.cmm> - 2016-05-12 17:46 -0400
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-05-15 00:11 +0100
                Re: The morality of operating system security James Harris <james.harris.1@gmail.com> - 2016-04-27 07:44 +0100

csiph-web