Re: Increase Security
Posted in 1995
In article <ian.goddard.46.001612E5@geo2.poptel.org.uk>, ian.goddard@geo2.poptel.org.uk (Ian Goddard) writes: >In article <472v99$fak@flood.weeg.uiowa.edu> dshirazi@labyrnth.uhl.uiowa.edu (Dariush Shirazi) writes: >>Subject: Re: Increase Security >>From: dshirazi@labyrnth.uhl.uiowa.edu (Dariush Shirazi) >>Date: 30 Oct 1995 16:42:17 GMT > >>In article <ian.goddard.33.0015B6E5@geo2.poptel.org.uk>, >> ian.goddard@geo2.poptel.org.uk (Ian Goddard) writes: > >>> >>>It seems to me that we need the client/server protocols to enable a client >>>*program* to identify itself in a manner which will be proof against tampering >>>(as far as this is possible) and will let the server check the client against >>>an approved list. As a by-product this would also enable the server lock out >>>incorrect versions of the clients. Whilst it's easy to define the >>>requirement, however, it's less easy to see how it might be met. Anyone got >>>any ideas? >>> > >>Again, this can be done using the same thing. All you have to do is to make >>the program switch into another user once the first user is authenticated. >>I think newera can do this. > >But how do you know that the program which is switching the user ID is an >auhorised program? If the program is not authorized by root, then it can not switch user ids. Otherwise, you have bigger problems than database access. In client server, the same thing can be done using passwords. The program says "I am program X and this is my password". Now you can code the password such that a person can not find it by looking at the raw exe file. >... >How do we recognise that this is an unauthorised version? We cannot rely on >simply having the application simply say "I am program x" in plain text in the >source code. We need at least to have the identification provided by some >shrouded means. Some form of digital signature should be built into the >protocols. I reiterate "protocols" here because I think this should be a >standard means of client-server communication; what I am thinking of is a >secure CLI. > See above. >Bearing in mind that the executable program may have SQL strings which could >be altered with a debugger the signature mechanism should be sensitive to >changes in the executable - perhaps based on a checksum of the executable >itself. > If I can debug the program, then why can I not change the statement that says my checksum is 0x99485 to 0x99455 after I change the sql statement? >... >The requirement, therefore is for a means of authenticating the application, >difficult to fake and sensitive to changes in the applications. The >applications and users would them become dimensions of an authorisation >matrix. Perhaps the client workstation would also be included, making this a >3-dimensional matrix. > The keyword is difficult. I don't think you can make any security system that someone else can not break. > >If one were really concerned about security one might also require the server >to authenticate itself to the client. > I agree that we have to have better security (easier to use and admin.) than what is available now. However, I disagree that it currently can not be done. > >Ian -- Dari Shirazi | Internet: dshirazi@uhl.uiowa.edu The University of Iowa - Hygienic Lab | Voice: (319) 335-4500 Oakdale Research Campus, OH-E5B | Fax: (319) 335-4555 Iowa City, IA 52242 |