Re: Installing PostgreSQL as "postgress" versus "root" Debate!

Поиск
Список
Период
Сортировка
От Doug Quale
Тема Re: Installing PostgreSQL as "postgress" versus "root" Debate!
Дата
Msg-id 87k6qh2rq5.fsf@charter.net
обсуждение исходный текст
Ответ на Re: Installing PostgreSQL as "postgress" versus "root" Debate!  ("Goulet, Dick" <DGoulet@vicr.com>)
Ответы Re: Installing PostgreSQL as "postgress" versus "root" Debate!
Список pgsql-admin
"Goulet, Dick" <DGoulet@vicr.com> writes:

> to Postgres install as well.  I as the DBA should be able to install,
> upgrade, etc the software without access to the root account.  Simply
> put the fewer people who know the root password the fewer who can
> destroy the system and the fewer who have to be told when the password
> changes.  And the fewer people who know anything, the more secure it is.

This analysis is incomplete.  Under this scheme, if someone cracks
your account they can install trojaned or malicious executables owned
by you without cracking root.  The flaw is in believing that this
scheme requires an intruder to crack two accounts to defeat your
security.  In fact, you have doubled the number of targets but left
the amount of work required of the bad guys to compromise your system
the same (crack one account).

Put all your eggs in one basket, and WATCH THAT BASKET.

В списке pgsql-admin по дате отправления:

Предыдущее
От: "Tomeh, Husam"
Дата:
Сообщение: Re: Installing PostgreSQL as "postgress" versus "root"
Следующее
От: David Bear
Дата:
Сообщение: syntax issue with insert statement