NormanDunbar,
@NormanDunbar@mastodon.scot avatar

This scandal in the UK. I'm a retired DBA, I had access to everything in every database under my control.

I'm puzzled that anyone in IT would believe that "there's no way Fujitsu staff can access the individual post office accounts; or change values".

This is complete garbage! Any DBA looking after the database can do what they like with the data, and if they wished, cover their tracks too!

It beggars belief that anyone would believe otherwise!

gadgetoid,
@gadgetoid@fosstodon.org avatar

@NormanDunbar honestly I don’t think anyone does believe otherwise- but the implications of admitting “oh yeah, sure, Fujitsu staff are literally god on this system” in any formal, much less legal, capacity are probably pretty severe.

That’s the crux of technology and privacy- we know the sys admin or db admin has god level access, they know they have god level access, but it remains unspoken because it’s too spicy to think about and too costly to fix 😬

NormanDunbar,
@NormanDunbar@mastodon.scot avatar

@gadgetoid We all know this, but the PO continued to believe it wasn't the case! And the layers they had under their control didn't know?

In any system, that I'm aware of, someone has god level privileges and can do anything at all. 😉

gadgetoid,
@gadgetoid@fosstodon.org avatar

@NormanDunbar believe because they sincerely believe, or believe because if they admit otherwise - even to themselves - they've just achknowledged a critical security oversight? 😆

Didn't know because they didn't know. Or didn't know because admitting they did know, implies they are culpable for not blowing the whistle.

I mean we all know, right, we've all been the admin getting the user out of a bind, or the user calling the admin for some workaround? 😆

NormanDunbar,
@NormanDunbar@mastodon.scot avatar

@gadgetoid Too true!

Wen,
@Wen@mastodon.scot avatar

@NormanDunbar @JackTheCat audit trails can be made foolproof though, with only destruction enabling a coverup.

NormanDunbar,
@NormanDunbar@mastodon.scot avatar

@Wen @JackTheCat I'm aware, yes. We used to have the database send the audit trail off to a secure server which the DBAs did not have any accounts on.

Collusion between different departments though, might have got round that. I never tried to cover anything up myself. 🙂

Wen,
@Wen@mastodon.scot avatar

@NormanDunbar @JackTheCat I am not and never have been a DBA. Hwever I am an applied mathematician who has developed and deployed validation technologies I. A number of areas, security, finance, defence and can guarantee that only destruction can hide tampering if it is done properly.

That then raises suspicions…

We flog the technologies.

NormanDunbar,
@NormanDunbar@mastodon.scot avatar

@Wen @JackTheCat Nice!

I wonder if you're auditing the auditors!!

Wen,
@Wen@mastodon.scot avatar

@NormanDunbar @JackTheCat auditing these trails is not our job but I have as have my colleagues been used in a number of fraud cases across Europe. Dull publicly, but the fringe benefits can be great…

NormanDunbar,
@NormanDunbar@mastodon.scot avatar

@Wen @JackTheCat Sounds like fun. For certain values of "fun". In a couple of contracts I was on, I was told that I bullshit so well, that I should be the one to deal with the (internal) auditors. So I did.

Once I sussed them out as to whether or not the knew the tech details, I was up front honest with them. Never had a bad report! 😁 Honesty definitely pays.

steenhive,
@steenhive@mastodon.scot avatar

@NormanDunbar having worked in partnerships with so many of these eejits through the years I'd be surprised it wasn't
user "sa", password: ""

NormanDunbar,
@NormanDunbar@mastodon.scot avatar

@steenhive Used to be System/manager!

NormanDunbar,
@NormanDunbar@mastodon.scot avatar

@steenhive But I was an Oracle DBA. I think SA is SQL Server?

steenhive,
@steenhive@mastodon.scot avatar

@NormanDunbar yes MSSql. Oracle have there own doozies though: sometimes all the default users have "oracle" as the password , or sometimes might have "adminstrator/adminstrator" "default/default" 😂

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • InstantRegret
  • ngwrru68w68
  • everett
  • mdbf
  • modclub
  • rosin
  • khanakhh
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Youngstown
  • GTA5RPClips
  • slotface
  • kavyap
  • JUstTest
  • ethstaker
  • osvaldo12
  • normalnudes
  • tacticalgear
  • cisconetworking
  • cubers
  • Durango
  • Leos
  • anitta
  • tester
  • megavids
  • provamag3
  • lostlight
  • All magazines