Re: Complex security requirement: user + computer
Posted in 1997
Peter A. Richardson wrote: > > "Paul Marks" <sessec01.pmarks@eds.com> wrote: > First, this is not a flame, but someone playing devil's advocate: > As with user restrictions, you can completely restrict the table and > only access data through queries. True, depending on the database. However, authenticating the user represents some problems. > You can use a win32 API call to > find out the machine name and use that as a condition of the queries. > This is obviously not a total solution. I could easily change the > name of my machine to one that is supposedly secure and you would not > know it. I would class this as about a 75% solution. I think that > you can set the machine security so that only an administrator can > change the name. Yes, changing the name, IP address is possible. Anything short of a NC or X-Windows Terminal which does not allow the user any option in set up. (TFTP Boot). >If it is an 90+% solution you are looking for, it > should not be too hard to write a function that gets the ethernet > board address. This is the NIC address of the card, and it is unique! IP addresses may not be unique if misconfigured. THis is why there are tools like HP's OPENVIEW. >This is supposed to be unique, but I know of cases of > duplicates. I also don't know if it would be possible to do this > under NT. > > I have a system that uses the machine name security. It is a pretty > simple API call to get. > > Peter Richardson Again, your solution isn't even %50 of the total solution required. Not that I am trying to rip you personally apart, just that you seem to also forget about PC/Server communication. Does it need to be encrypted? Physical access points? User identification? Smart Cards? Tokens? Biometrics? Sever security. Outside access points? Virus protection. etc ..... -Mikey -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** Due to AGIS's Refusal to Act Responsibly We are blocking all of their domains at the packet level. This block will exist until AGIS modifies their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************