On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 5 of 6:
Next »
« Previous
Sequential numbers are not the real problem
The real problem is that someone unauthorized could access the data at all.

If as a customer has a login which gives them total access to a database, this is where the security issue lies. A customers login should only give them access to the records in a database to which they have legitimate interest and no other. In this case sequential random or the names of the of the employees will have no more significance other than a way to access the records a client is entitled.

Relying on random numbers to secure data is no less foolish than sequential numbers. Even a simple script running a sequal number counter could access in time every record in the database no matter howmany didgits you use.

You have to put the security on the data not just the database. A smart programmer may also put in triggers which sound an alarm when someone attempts to access data outside of what they are entitled.

This case was clearly a disaster waiting to happen. I think the company has been fortunate that it wasn't discovered from an investigation of identity fraud. Maybe it's not a federal law just to be notified but a federal law making anyone who holds data on individuals and organizations responsible for that data, thay they must attempt to clearup any damage caused as a consequence and compensate the person or organization for any consequential losses.

No that would be a law with teeth, it's enforcable because the organization isn't going anywhere and if they allow data to be stolen they are at fault. That should make a great improvement in reducing identity theft.
Posted by: agottschald   Posted on: 03/22/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Simple security  vasanthm | 02/24/05
I guess they don't test software in India  BXLE | 02/24/05
I didn't see India in the text of the article.  agottschald | 03/22/05
Very poor website planning  Ironiclife | 02/24/05
Sequential numbers are not the real problem  agottschald | 03/22/05
I guess No one will read my postings  agottschald | 03/22/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

SmartPlanet

Click Here