The most striking lesson I think that anyone can take from the recent apache compromise is this:
The more secure zone should have credentials for the less secure one, not the other way round, and the more secure zone should be responsible for controlling the processes that it is involved in.
This way the less secure zone doesn't have any influence over your more secure stuff.
If you, like me, spend your days making systems interact with one another this is reasonably fundamental stuff. But for those who aren't so paranoid its a lesson well worth heeding.
Danny Angus
blog.killerbees.co.uk
Danny Angus
Independent IT Consultant
"start apache anyway. There's stuff, yeah, apparently"Labels
Friday, August 28, 2009
Don't invert your security!
Further Reading
-
-
-
Keyhole, of sorts2 days ago
-
-
-
Phish or Fair?1 week ago
-
-
-
-
We’re all dead3 weeks ago
-
ApacheCon NA 2011 – Friday1 month ago
-
A bacon spin on sushi: ikura baciri3 months ago
-
Twitter4 months ago
-
Worship me, for I am a xoogler7 months ago
-
-
Westin Tower - Atlanta1 year ago
-
-
Baseline 1.52 years ago
-
Boat For Sale5 years ago
I know nothing, I'm not a fortune teller, and you'd be insane to think that I am. This disclaimer was cribbed from an email footer I once received. It is so ridiculous I had to have it for myself.
Statements in this blog that are not purely historical are forward-looking statements including, without limitation, statements regarding my expectations, objectives, anticipations, plans, hopes, beliefs, intentions or strategies regarding the future. Factors that could cause actual results to differ materially from the forward looking statements include risks and uncertainties such as any unforeseen event or any unforeseen system failures, and other risks. It is important to note that actual outcomes could differ materially from those in such forward-looking statements.
Danny Angus Copyright © 2006-2010 (OMG that's four years of this nonsense)

Comments:
Post a Comment
blog comments powered by Disqus