Slashdot Mirror


User: mcpkaaos

mcpkaaos's activity in the archive.

Stories
0
Comments
913
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 913

  1. Re:Indicitive of a larger problem on Trojan Compromises Oregon Taxpayers · · Score: 1
    Say you are an auditor at this department.


    One good method of auditing is to use the Internet.


    Why wouldn't that auditor have direct, physical access to an authorized network inside the same building? Is the risk of sending sensitive data over the very public Internet worth having the convenience to do the job off-site?

    However, you find some good pages with safe looking names that aren't apparently in a filter yet.


    How is that going to happen when the auditor is on a workstation with no access to outside networks and no means to copy the data to a portable device? That's even easier to arrange than encryption and firewalls.
  2. Re:Likely a reporting wonk on Trojan Compromises Oregon Taxpayers · · Score: 1

    You could write a script (or scripts) to output pseudo-randomized data in a clean, parseable format. Create a database using the same schema as your production database and populate it with the output from your script(s). Simple and boring, but it's easy and it works. Even if you want to generate a massive database it's simply a matter of running the script over and over again with incremental data. Or, just create very simple scripts to generate a basic dataset and do the rest with queries.

    To me, the extra work is worth it. I'd rather eliminate the risk than minimize it.

    Plus, I just happen to believe that controlled datasets make for better testing. It's really no more difficult to write a script that generates random, re-occuring errors than it is to write one that doesn't, so you can pretty much attack your code/database/whatever from any angle you can think of. And for those you can't think of, just loosen the parameters and generate more random tests. You are only limited by the thought and time you want to put into it. With real data, scrambled or not, you are simply stuck with whatever happens to be in the tables at the time you grabbed it. Also, real data would already have been normalized and, in my opinion, not well suited for testing.

  3. Re:Indicitive of a larger problem on Trojan Compromises Oregon Taxpayers · · Score: 1
    Just be glad there's so many so that you know your data is drowned out... you know, safety in numbers.


    Actually, it's just the opposite. For one, the thief will get through all of the records eventually. If they don't, a buyer will.

    Also, the bigger the leak, the more complicated it becomes to account for every potentially compromised individual and notfiy them.

    You're right, but in the real world things are a tad different. I used to work for a college...


    Forgive me if I offend, but I had a good chuckle at that. :)
  4. Re:Likely a reporting wonk on Trojan Compromises Oregon Taxpayers · · Score: 3, Insightful
    My guess is they had the data locally in Excel spreadsheets, fiddling with things.


    Dummy data. In all my years as a software engineer I have never worked with real or production data. There is never a reason for it, so just dummy something up and use that. Then situations like this are simply impossible.

    Many people have secure information on their hard drives too.


    Not in the Department of Revenue. At least, they shouldn't. That they obviously do should be a huge cause for concern and a process audit or three.
  5. Re:Indicitive of a larger problem on Trojan Compromises Oregon Taxpayers · · Score: 1
    Trojans don't replicate. While its payload might, the trojan itself is just a delivery mechanism.

    From the article:

    The "trojan" program attached to the file may have sent taxpayer information back to the source when the computer was turned on again.


    That suggests to me that only the workstation was compromised, as does this:

    McLaughlin said the department determined on May 15 that the computer was being improperly used and on May 23 that some data may have been captured and sent out.


  6. Indicitive of a larger problem on Trojan Compromises Oregon Taxpayers · · Score: 5, Insightful

    What was real data doing on a workstation with Internet access in the first place? One would think (hope?) that such data would be under heavy lock and key and only accessible by the software written to manage it or, when absolutely necessary, a trusted administrator with lotsa logging.

    It is absolutely amazing to me that this event was even possible.

  7. Re:Want to see easy? on Scientists Respond to Gore on Global Warming · · Score: 1

    You just got yourself a fan with that post. :D

  8. Re:Poor solution on Hawking Says Humans Must Go Into Space · · Score: 1

    I couldn't help it. I had just finished up reading a flame war about Coulter over at Crooks and Liars. :D

  9. Re:Poor solution on Hawking Says Humans Must Go Into Space · · Score: 1

    Who let the Freeper in here?

  10. Re:According to the site, it's a physical thing on Bellagio Fountains Recreated with Mentos and Coke · · Score: 1

    Here :)

  11. Re:According to the site, it's a physical thing on Bellagio Fountains Recreated with Mentos and Coke · · Score: 1

    (like soda, which is pumped full of carbon dioxide)

    You call it carbon dioxide. I call it life.

  12. Re:ohhh ... EULA on Site Says 'Go Away!'; Federal Court Says No · · Score: 1

    You haven't paid for it, therefore you're not bound by the EULA restrictions.

    Well that clears that up.

  13. In California... on WA Law: 5 Years in Prison for Gambling Online · · Score: 4, Funny

    possessing child pornography, threatening the governor or torturing an animal

    I'm pretty sure one of those is legal. I just can't remember which.

  14. Uh oh... on AMD-ATI Merger on the Way? · · Score: 5, Funny

    There goes the amd64 stable keyword...

  15. Re:Beyond the Civil Liberties issues ... on A DNA Database For All U.S. Workers? · · Score: 5, Funny

    Sure. Right after they sign their kids up to go to Iraq.

  16. Re:Then help with the testing process. on The CVS Cop-Out · · Score: 1

    Only at Slashdot do you get modded down for congratulating someone on a good post. Stupid, stupid people.

  17. Re:Talk about your gimmicks on MacSaber Turns Your Macbook into a Lightsaber · · Score: 0

    lol so true!

  18. Re:Then help with the testing process. on The CVS Cop-Out · · Score: -1, Redundant

    Excellent post! I really like your points. :)

  19. Ah, invention. on Ready to Test a 'SmartShirt'? · · Score: 1

    The mother of all necessity.

  20. Re:security over privacy on Americans Not Bothered by NSA Spying · · Score: 1

    Some of us still are!

  21. Re:To be used in 2003? on Gadgets for the Lazy · · Score: 1

    $500 for something lower tech than a Speak-n-Spell...

  22. Re:The way I see it on U.S. House Clears Anti-Internet Gambling Bill · · Score: 1

    Very well said!

  23. Re:So long... on U.S. Attorney General John Ashcroft Resigns · · Score: 1

    lol, fuck you guys. see, this is why i never log into this POS site anymore.

    later losers!

  24. So long... on U.S. Attorney General John Ashcroft Resigns · · Score: 0, Redundant

    And thanks for all the fig leaves.

  25. Re:It works! But... on Software For Slackers: Lockout · · Score: 1

    I love you guys. Except for the one that modded me down. I hope he burns in hell. =)