RE: Note to IBM... Wuz Re: Informix Warehouse Accelerator Prerequisites
Posted in 2011
Sigh. Ok junior, lets get a few things straight. First, ever since Morris' worm, using .rhosts and /etc/hosts.equiv has been a very bad idea. Back in '88 one of my first tasks post Morris was to write a script that walked all of the user's home directories and report and log who had it, and then we deleted the file. Yes, its that serious. Use of /etc/hosts.equiv required a lot of forethought as to what went in and why. The way Informix used it was never a good idea, considering that Turbo was the first and hit the market back in '90. The fact that it took 20 years to fix does in fact show that Informix and then IBM didn't care much about security. Yeah that's a pretty blatant slap in the face when it comes to Informix. At the same time, resource allocation is spend on fixing bugs or making enhancements based on what will get you the most bang for the buck. That's standard operating procedure for any company that is trying to stay afloat and make money. I don't have a problem with that. Its software development econ 101. What I do have a problem with is that whomever reviewed the list of bugs (this was one of them...) didn't assign it a high enough priority to get it the attention that it needed. Getting it fixed was a good thing. The fact that it took 20 years is something to chuckle about and tap the backside of certain product managers on the backside of the head. With respect to telnet... Yes, I know how you (Informix) is using it. We use telnet as a way to test connections to ports on the local host, however we don't embed it in our scripts. Going some other route is preferred. But again, this is Informix that we're talking about who well after the fact of knowing the security issues of .rhosts routinely told customers to use it. But you're right. I've already mentioned that... ;-) Again, you seem to not comprehend the magnitude of the problem that .rhosts and hosts.equiv bring. You're right in today's internet, its a moot point. Why? Because *only* Informix took 20 years to stop using it. Look, unless you lived through the panic, the lessons learned don't carry the same weight. I haven't looked to see what's on Wikipedia about Morris' worm. If you understood what it did and how it did it, you wouldn't be having this conversation about telnetd. (Besides the whole unencrypted password thing, there were other issues that may or may not have been fixed.) Telnet had been replaced with more secure things like ssh. So I wonder how long it is before Informix err now IBM gets on the bandwagon and starts using SSH. ;-) On to your comments about IWA... IWA was designed to provide 'data warehouse' like capabilities to IDS. In fact it was billed and hyped as a 'big data' solution. (I did attend Carlton Doe's presentation until I got called away for some real work.) Of course how one define's 'Big Data' will help determine what products fall in to that category. And if you read my mini-rant, you'd understand that IWA doesn't scale. So how do you classify IWA? Is it an appliance? (Ok, so doesn't IBM have Netezza for that? [lets not talk about it getting its butt kicked by Hadoop, I don't want to embarrass you...]) Is it an in-memory solution? (Hmmm. Didn't IBM buy SolidDB for that and it was tied to both DB2 and IDS via the DRDA gateway that is now embedded in to IDS?) You start to see the issue. IBM already has 'go to market' products and strategies outside of IWA already. Netezza has a market. Then you have some issues. Like who can use IWA? Answer: IWA is an Informix only solution. So to use IWA you have to have an install of IDS in place. So if you bothered to put down the blue cup of cool-aid, and looked at it from the outside world. What's the use case for IWA? Speed up queries for analytics? (Thats the same for SolidDB, right?) Then we get to the price tag of the machine. How much memory can you fit on a box. Care to price it out? Not cheap. Then you have the cost of the IWA license. Again, not cheap. Go check out... http://www.kognitio.com/ That's your competition. I have no affiliation and I haven't reviewed their product. But they claim to scale and they claim to be fully distributed, which means you're not limited to a single machine like you are in IWA. So from a product management perspective, you have a limited market to start with and you're only a niche of that. With its list price, IWA is a non-starter with customers when you consider that there are more economically viable products on the market. The only advantage is if you have an Informix shop who wants to be able to use their existing SQL against the data within an in-memory solution to speed things up. Now if you want to talk about IDS being an excellent OLTP engine with world class HA/DR replication? Yeah. That's a no brainer. But IWA isn't IDS, now is it? Date: Mon, 22 Aug 2011 15:06:52 +0100 Subject: Re: Note to IBM... Wuz Re: Informix Warehouse Accelerator Prerequisites From: domusonline@gmail.com To: im_gumby@hotmail.com CC: informix-list@iiug.org Ok Ian. I can take some time, since you insist. Writing wrong things to me is irrelevant, but to the community makes a difference. On Mon, Aug 22, 2011 at 1:18 PM, Ian Michael Gumby <im_gumby@hotmail.com> wrote: So it took 20 years for this security hole to get fixed? Kinda shows how certain product managers treat security. Oooh Snap! Sorry Jerry, I guess closing security holes just aren't high on the customer's wish list so that they take a back seat to a failed product. I can easily agree with you. 20 years to fix this is too much. But again, and I wrote this to you, to this forum and on my blog: using /etc/hosts.equiv and .rhost is only insecure IF you use them for anything else beside Informix. And I really doubt someone who cares about security does it. And as usual, beside you fix something you get hammered because you don't fix it, once you fix it, you still get hammered because you took too long. it makes you wonder if it's worth doing it, and I'm glad our R&D team decided to do it. And comparing this to other "trivial" things that are being done, you easily understand that customers were not pushing to hard for this. Ok, sorry, that was unfair. Really? But once written, it's out there you know... Red's comments are valid because he is questioning what is written on IBM's site. They say it's a prerequisite and frankly changing to ssh is *trivial*. He's comments mentioned telnetd and how telnet itself was insecure because it's not encrypted. It missed the point that no telnetd service was needed, and the purpose of using "telnet" command. Someone else already explained this. As usual you ignore the parts that may contradict your points. Getting back to Fernando and the Morris worm. Not everything was made public so it wasn't captured in Wikipedia. In order to use .rhosts as an attack vector you already need access to the machine as root. So the question is... How did the worm get on the machine in the first place? I think that was made public... But don't feel too bad. It tok 8-10 years for Sun to fix it... All that is on the net. Just don't see the point and how it connects to this. The point relevant here, is that rservices are insecure. So you'd better not use them. After that the so called "Informix issue with .rhosts" is pretty irrelevant. I just wished we had fixed this sooner because it would save a lot of useless disc