5 ms·
In part, I think you're overestimating how difficult it would be for you to gain access to customer data covertly, given root access to all the servers at your
by GunboatDiplomat 10y ago
In part, I think you're overestimating how difficult it would be for you to gain access to customer data covertly, given root access to all the servers at your company.
- beachstartup 10y agoi agree. to some people root still means root which means you can do anything local undetected if you're smart enough (most people aren't). apparently these days it means something else. who knew.
- SixSigma 10y ago"full admin rights"
- Johnny555 10y agoWhen audit logs go to an audit server, you can't do anything undetected, even as root - the initial login, sudo to root and subsequent activity are logged, so even if I log in and kill the audit daemon, that will be detected and tied back to me. If I even log on to one of the audit servers without prior approval, it will page the security team. And if they can't validate why I've logged in there, they'll lock out my account.
- emmelaich 10y agoUhm, you're not using your imagination to put it mildly. There's many ways of getting a plausible deniability. Plus, breaks are never done through the strongest part of the wall. Computers can be made totally secure in management minds, and in the minds of the broader public. We know from stories of break-in after break-in to some of the worlds top companies, that that is a dangerous lie. Most of these break-ins were done without the conscious cooperation of anyone inside who had admin rights. Now, just imagine what can be done calculatedly with admin rights. It comes down to trusting people eventually. It's always about people.
- Johnny555 10y agoIf I could find a zero day exploit that would give me root, that might get me in, but network accesses are logged too, so even if I found a back door way into the server, I'd still be discovered "Johnny, someone altered binaries on our server yesterday, there were no SSH logins, but your VPN session hit our application server port at the exact time the application daemon crashed. Explain?" Even though I have server admin rights, I can't touch the network so I can't open an unaudited path to the server. It's not that the server security will keep me from accessing the data, but it will keep me from accessing it without being discovered.
- Steel_Phoenix 10y agoBeing able to tell who grabbed the data and when is nice, but what's to stop someone who is willing to grab the data and run/leak?
- beachstartup 10y ago"my new home alarm system will tell you with 100% certainty after you get robbed, that you were robbed!"