No secrete to a root account holder under Informix
Posted in 2000
Alex asked how to stop Unix root (often a shared admin account) from reaching sensitive Informix data, since Informix relies on OS authentication and has no per-user encryption, and wondered if Oracle is safer. Suggestions: use Role Separation (see the Trusted Facility Manual for 9.2x), and don't grant privileges to root or public. Jonathan Leffler argued that root must be trusted since it can read raw disks and plant trojans, so restrict root via su/sudo-style accounts and auditing. An Oracle advocate countered with encrypted passwords, VPD and column encryption; others noted root can simply 'su - user', and that truly sensitive data should be encrypted by the application. No single agreed resolution.
Auto-generated by DrWatson from the posts below — may be imperfect; read the full thread.
Topics: Security, Permissions & Auditing
Unlike Oracle, Informix doesn't have its own user authentication security scheme at the database level. Unlike Unix either, Informix doesn't have data encryption tool to protect data at the individual user level. In other words, Informix potentially grants an unlimited database access authority to the root user account, because root can behave on behalf of any other users within the Unix/Informix systems. The question is: does root have to be a trustworthy user account? Normally it is a shared Unix administrator account. I couldn't agree that an organization should allow a group of Unix system administrators to have the unlimited access to the company sensitive data, such as payroll system data, personnel system data, or any other security data under the Informix-based application systems. Wondering how FBI handles this issue - no secrete to a root user account holder. In this sense, at least, does Oracle appear more secure than Informix? Please help me with my puzzle on this issue. I hope my understanding to Informix security is wrong, because I need the solution so badly. Thank you in advance. Alex.
What version of Informix? Anyway, try using Role Separation. For 9.21 this is described in the "Trusted Facility Manual". HTH Brett Randall "Chen, Alex" wrote: > > Unlike Oracle, Informix doesn't have its own user authentication security > scheme at the database level. > Unlike Unix either, Informix doesn't have data encryption tool to protect > data at the individual user level. > In other words, Informix potentially grants an unlimited database access > authority to the root user account, > because root can behave on behalf of any other users within the > Unix/Informix systems. The question is: > does root have to be a trustworthy user account? Normally it is a shared > Unix administrator account. > I couldn't agree that an organization should allow a group of Unix system > administrators to have the > unlimited access to the company sensitive data, such as payroll system data, > personnel system data, > or any other security data under the Informix-based application systems. > Wondering how FBI handles > this issue - no secrete to a root user account holder. In this sense, at > least, does Oracle appear more > secure than Informix? Please help me with my puzzle on this issue. I hope my > understanding to Informix > security is wrong, because I need the solution so badly. Thank you in > advance. > > Alex.
We're having similar issues. At first I thought you just told him to RTFM; then I found it on the doc site. Thanks for the info. Brett Randall wrote: > What version of Informix? > > Anyway, try using Role Separation. For 9.21 this is described in the > "Trusted Facility Manual". > > HTH > > Brett Randall > > "Chen, Alex" wrote: > > > > Unlike Oracle, Informix doesn't have its own user authentication security > > scheme at the database level. > > Unlike Unix either, Informix doesn't have data encryption tool to protect > > data at the individual user level. > > In other words, Informix potentially grants an unlimited database access > > authority to the root user account, > > because root can behave on behalf of any other users within the > > Unix/Informix systems. The question is: > > does root have to be a trustworthy user account? Normally it is a shared > > Unix administrator account. > > I couldn't agree that an organization should allow a group of Unix system > > administrators to have the > > unlimited access to the company sensitive data, such as payroll system data, > > personnel system data, > > or any other security data under the Informix-based application systems. > > Wondering how FBI handles > > this issue - no secrete to a root user account holder. In this sense, at > > least, does Oracle appear more > > secure than Informix? Please help me with my puzzle on this issue. I hope my > > understanding to Informix > > security is wrong, because I need the solution so badly. Thank you in > > advance. > > > > Alex.
"Chen, Alex" wrote: > Unlike Oracle, Informix doesn't have its own user authentication security > scheme at the database level. Correct. > Unlike Unix either, Informix doesn't have data encryption tool to protect > data at the individual user level. I'm not sure how you think that would work, or how searches would work on encrypted data. > In other words, Informix potentially grants an unlimited database access > authority to the root user account, You can prevent root from having direct database access; don't give privileges to either root or public and root cannot access the database via the front door. > because root can behave on behalf of any other users within the > Unix/Informix systems. And root can access the raw disks, and can install trojan horses to snare passwords, and so on... > The question is: > does root have to be a trustworthy user account? Yes; if you can't trust root, you cannot trust anything on the machine. Period. Root can screw up anything, so if you cannot trust those who have root privileges, you cannot trust the machine. It might be that you trust that those with root privileges don't know enough to do any really sneaky damage, or it might be that trust those with root privileges to be honourable and not do anything really sneaky, but one way or another, you have to trust them. > Normally it is a shared Unix administrator account. Yes, which is bad news. You should probably be cleverer about handling root privileges than letting everyone use root directly. Probably, you should deny access as root to everyone. Those who should obtain root privileges should use an su command in some shape or form, so you can track who did what. It might be that the privileged user 'dmr' logs in as 'sudmr' to become a user with UID 0, and user 'rms' logs in as 'surms' to become a user with UID 0, for example. Only the most trusted users should know the actual 'root' password -- that is necessary for single-user access during a reboot to fix hardware problems or corrupted disk drives, for example. > I couldn't agree that an organization should allow a group of Unix system > administrators to have the > unlimited access to the company sensitive data, such as payroll system data, > personnel system data, > or any other security data under the Informix-based application systems. True, so those systems should be carefully isolated and carefully controlled by people who are trusted. > Wondering how FBI handles this issue - no secrete to a root user account holder. Don't allow people access as root? > In this sense, at least, does Oracle appear more secure than Informix? Only superficially. The root user can trawl through the Oracle files and find the password information, and either change it or decrypt it. Or they can infiltrate their own software to intercept the user names and passwords. Or any of a number of other things to find out how to log in as a privileged database user. You can't stop a sufficiently educated root user -- that's why you have to trust them. Unless you want to explain (in considerable detail) how Oracle prevents root from breaking into the database under all possible circumstances. > Please help me with my puzzle on this issue. I hope my understanding > to Informix security is wrong, because I need the solution so badly. The long and the short of the issue is -- if you can't trust those who know the root password or have access to root privileges, you cannot trust the machine or any data on the machine. -- Yours, Jonathan Leffler (Jonathan.Leffler@Informix.com) #include <disclaimer.h> Guardian of DBD::Informix v1.00.PC1 -- http://www.perl.com/CPAN "I don't suffer from insanity; I enjoy every minute of it!"
> From: Jonathan Leffler <jleffler@informix.com> > Organization: Informix Software Inc > Newsgroups: comp.databases.informix > Date: Fri, 08 Dec 2000 01:29:38 GMT > Subject: Re: No secrete to a root account holder under Informix > >> In this sense, at least, does Oracle appear more secure than Informix? > > Only superficially. Much more than just superficially > The root user can trawl through the Oracle files and find the password > information, and either change it or decrypt it. Oracle passwords are stored in encrypted form, and AFAIK have never yet been decrypted. And unless root can logon to the Oracle database with System privileges, they would have no way of determining what any given password would encrypt to in order to replace in the files. In addition, you can create users in Oracle that are not password authenticated, but use a digital certificate instead - hence there is no password to find. > Or they can infiltrate > their own software to intercept the user names and passwords. Sort of true - oracle passwords are also encrypted on the wire, so you can't intercept them there either. Note that it's an Oracle username that determines the database privileges a user gets - (either from the database directly, or from an LDAP directory) - so unless root has an oracle username/password, they simply can't logon to the database. When installing on Unix, you do need a Unix account, typically called Oracle, and for ease of use you can set up this account so that it can logon by default to an Oracle database with SYSTEM privileges - however this is quickly disabled, and later versions of Oracle8i actually come with this facility disabled by default. So even if root does su to oracle, they would still need a valid username/password combo to logon to the database. > Or any of > a number of other things to find out how to log in as a privileged > database user. You can't stop a sufficiently educated root user -- > that's why you have to trust them. This is interesting - some countries have very strict privacy laws on the collection and dissemination of electronically collected personal information. How does Informix prevent a system admnin type from reading sensitive patient information ? > Unless you want to explain (in considerable detail) how Oracle prevents > root from breaking into the database under all possible circumstances. Well, unless somebody gives root system or sys privileges on an Oracle database, they can't get in. There are also at least a couple of useful security features in Oracle that Informix doesn't have - Virtual Private Database security policies can be built into the server that prevent one user from accesing another users data even when both users have access to the same schema objects - this is very useful when you are sharing a common schema over a number of diverse groups - such as multiple companies sharing the same database in a hosting environment. Also useful in a rpivacy situation - a doctore can only see information abouth their own patients, for instance. Oracle also implements military label based security using the same capabilties - i.e Top Secret, General Clearacnjce. etc In additon, later versions of Oracle8i support column encryption - so even if the DBA can see the column, they can't actually read the content. Only users with the correct key sets can actually read the data stored in the encrypted columns. Useful when you are storing credit card numbers that you don't want the DBA to see.
"Mark Townsend" <markbtownsend@home.com> wrote in message news:B6570014.BD9%markbtownsend@home.com... > > Well, unless somebody gives root system or sys privileges on an Oracle > database, they can't get in. There are also at least a couple of useful > security features in Oracle that Informix doesn't have - Virtual Private > Database security policies can be built into the server that prevent one > user from accesing another users data even when both users have access to > the same schema objects - this is very useful when you are sharing a common > schema over a number of diverse groups - such as multiple companies sharing > the same database in a hosting environment. Also useful in a rpivacy > situation - a doctore can only see information abouth their own patients, > for instance. Oracle also implements military label based security using the > same capabilties - i.e Top Secret, General Clearacnjce. etc ... All this assumes that a person with root access, is not bright enough to have mastered the use of 'su - <userid>' ...
I would argue that the securing of critical data such as ssn's, credit card numbers, etc really needs to be done by the application accessing the database, rather than the database engine itself. Let's say I'm an end user generating reports of credit card transactions or of employee salaries. While the credit card data is protected from tampering by disgruntled dba's and sysadmins, what is protecting the plain-text credit card numbers being transmitted over the network? A secure application doesn't transmit critical data in the clear. Duff In article <B6570014.BD9%markbtownsend@home.com>, Mark Townsend <markbtownsend@home.com> wrote: > > > > From: Jonathan Leffler <jleffler@informix.com> > > Organization: Informix Software Inc > > Newsgroups: comp.databases.informix > > Date: Fri, 08 Dec 2000 01:29:38 GMT > > Subject: Re: No secrete to a root account holder under Informix > > > >> In this sense, at least, does Oracle appear more secure than Informix? > > > > Only superficially. > > Much more than just superficially > > > The root user can trawl through the Oracle files and find the password > > information, and either change it or decrypt it. > > Oracle passwords are stored in encrypted form, and AFAIK have never yet been > decrypted. And unless root can logon to the Oracle database with System > privileges, they would have no way of determining what any given password > would encrypt to in order to replace in the files. In addition, you can > create users in Oracle that are not password authenticated, but use a > digital certificate instead - hence there is no password to find. > > > Or they can infiltrate > > their own software to intercept the user names and passwords. > > Sort of true - oracle passwords are also encrypted on the wire, so you can't > intercept them there either. > > Note that it's an Oracle username that determines the database privileges a > user gets - (either from the database directly, or from an LDAP directory) - > so unless root has an oracle username/password, they simply can't logon to > the database. When installing on Unix, you do need a Unix account, typically > called Oracle, and for ease of use you can set up this account so that it > can logon by default to an Oracle database with SYSTEM privileges - however > this is quickly disabled, and later versions of Oracle8i actually come with > this facility disabled by default. So even if root does su to oracle, they > would still need a valid username/password combo to logon to the database. > > > Or any of > > a number of other things to find out how to log in as a privileged > > database user. You can't stop a sufficiently educated root user -- > > that's why you have to trust them. > > This is interesting - some countries have very strict privacy laws on the > collection and dissemination of electronically collected personal > information. How does Informix prevent a system admnin type from reading > sensitive patient information ? > > > Unless you want to explain (in considerable detail) how Oracle prevents > > root from breaking into the database under all possible circumstances. > > Well, unless somebody gives root system or sys privileges on an Oracle > database, they can't get in. There are also at least a couple of useful > security features in Oracle that Informix doesn't have - Virtual Private > Database security policies can be built into the server that prevent one > user from accesing another users data even when both users have access to > the same schema objects - this is very useful when you are sharing a common > schema over a number of diverse groups - such as multiple companies sharing > the same database in a hosting environment. Also useful in a rpivacy > situation - a doctore can only see information abouth their own patients, > for instance. Oracle also implements military label based security using the > same capabilties - i.e Top Secret, General Clearacnjce. etc > > In additon, later versions of Oracle8i support column encryption - so even > if the DBA can see the column, they can't actually read the content. Only > users with the correct key sets can actually read the data stored in the > encrypted columns. Useful when you are storing credit card numbers that you > don't want the DBA to see. > > Sent via Deja.com http://www.deja.com/ Before you buy.