Re: PG in cash till machines

Поиск
Список
Период
Сортировка
От John R Pierce
Тема Re: PG in cash till machines
Дата
Msg-id 518D6CC3.7070406@hogranch.com
обсуждение исходный текст
Ответ на Re: PG in cash till machines  (Bexley Hall <bexley401@yahoo.com>)
Ответы Re: PG in cash till machines  (Bexley Hall <bexley401@yahoo.com>)
Список pgsql-general
On 5/10/2013 2:11 PM, Bexley Hall wrote:
Having designed (regulated) gaming and "grey area" devices (each
handling hard currency), I can tell you that you have to have already
performed a pretty exhaustive threat analysis (e.g., red team, blue\
team) *before* you start the product's design.  If you can't imagine
*all* of the ways you can be targeted, then you can't determine
how/if you will be "secure" in each of those scenarios (e.g.,
I've incorporated features into the hardware designs to counter
certain types of physical attacks).

indeed, and there's always threat models that no one could foresee, witness the recent story of coordinated ATM withdrawals of $45,000,000 enabled by some back door hacking of the bank databases.



-- 
john r pierce                                      37N 122W
somewhere on the middle of the left coast

В списке pgsql-general по дате отправления:

Предыдущее
От: Steve Clark
Дата:
Сообщение: Re: Deploying PostgreSQL on CentOS with SSD and Hardware RAID
Следующее
От: Jasen Betts
Дата:
Сообщение: Re: authentication/privileges