Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: rarestia

Every database has its vulnerabilities. We tested on Oracle DB and had every password within 15 minutes. Security isn’t just passwords or encryption. They certainly help but it takes the whole picture to keep things locked up.

Key management applications help manage passwords and keepass is one. Sounds like a good system you have going there.


46 posted on 06/26/2012 1:20:45 PM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 44 | View Replies ]


To: driftdiver

I understand DB vulnerabilities but admittedly steer clear of them mostly out of ignorance but also out of a lack of need.

I don’t run any DBs on my home network anymore, esp. with all of the stories I hear and read about DB security.

In a domain environment, I force all DBAs to change the default ports to prevent script kiddies from banging on the door and enact two-factor authentication for administration (usually certs and complex passwords).

Authentication needs to be looked at with a fine-toothed comb. Passwords/phrases are old-tech. Smart cards, biometrics, and character/vision-based authentication make more sense, IMO.


50 posted on 06/26/2012 1:49:11 PM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 46 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson