Re: Use of Informix with Protegrity/Omnisecure Encryption
Posted in 2007
Ian Michael Gumby wrote: > > > >> From: Fernando Nunes <spam@domus.online.pt> >> >> My news server is sooooo bad... I've lost that message... >> > >> > The downside to using this encryption package is that it will kill >> > performance. Now that could be mitigated by either using a hardware >> >> A quick note... Currently there are a lot of things that kill >> performance... >> If you have to be SOX compliant, many times performance won't be your >> first priority... >> > Well so will writing piss poor queries. The point is that you kill > performance yet you do not increase security. > > >> So... you never had the chance to try mixing chunks from two >> instances? Or see somebody create a fs on top of your raw devices? >> Lucky guy :) >> > Well, thats because when I do my work, I document everything and I try > to work in tandem with the sysadmins so that they know which raw > partitions are mine. ;-) > > Also leave a set of laminated system documents so that there is no > excuse for writing on a chunk and also get the client's DBAs and > SysAdmins to agree upon proper policy and procedure so that "accidents" > like you mention don't happen and if they did, someone would be shot. ;-) > Ohh... Silly me... I thought that would be because "while Informix is up, it locks the chunks such that no one but the Informix process(es) can access them." :) It was this point I was trying to make... Someone with the necessary privileges could dd with an instance up and running. Obviously this would have to be root or a member of informix group, and I completely agree with you that in this case there a lot of other things they can do... > Typical IBMer. You've missed the point. We all do don't we? :) > Look, once someone has gained root access to any UNIX/LINUX machine > there isn't a lot that anyone can do to stop him/her from screwing > things up. If I may diverge, any thoughts that anybody has regarding this point (what, if any, can be done about the "root" problem) would be appreciated > The Original Poster said that they are implementing a solution that > encrypts/decrypts the io as it is written to the disk. If you think > about this, if someone were to steal the data in the database, > encrypting the physical disk does nothing for security. If you have a > compromised machine and that person knows the root password they can > then su - to anyone and gain access to the Informix database. Bypassing > the encryption entirely. > > Thus you degrade performance for zero gain! I understand this point, although I may have some doubts if in certain OS with certain conditions this couldn't work. I mean, if you have root you can do everything... but can you do it without being noticed? I'm not trying to make a discussion about this. I really have doubts... > Why IBM didn't do it remains a "mystery". Ok not a mystery. Just > something we can't talk about in polite company. ;-) Is this a company? For me it's just a crappy news server :) > The bottom line is that whomever made the decision to shackle the DBAs > to this Protegrity product didn't think things through. It does nothing > to secure your database data. That's a valid contribution for the discussion. It may not help the original poster if the decision is made... It would be great if we knew what they expect to gain from it... Regards. -- Fernando Nunes Portugal http://informix-technology.blogspot.com My email works... but I don't check it frequently...