5 ms·
I'm not going to argue that the NSA report is amazing or terribly well-written, but re-reading it with the principle of charity nullifys many of these rebuttals
by dlor 4y ago
I'm not going to argue that the NSA report is amazing or terribly well-written, but re-reading it with the principle of charity nullifys many of these rebuttals.
For one example, from the rebuttal:
> If there is concern that their user credentials will beget malefaction and mistakes, then why discourage service accounts2, which are inherently decoupled from specific user identities?
But then looking at the text from the document itself:
> Minimize and regularly audit service accounts,
> The use of service accounts, like non-human privileged accounts used to run automated processes, should be minimized and carefully audited. Every service account login should be logged. These logs should include date and time and the origin of login. Service accounts should follow the “least privileged” policy. All service accounts should be regularly reviewed to assure they are still needed, and unnecessary accounts removed.
I don't think the document is saying to avoid service accounts in favor of something silly like shared passwords. It's saying to use the fewest you can get away with, delete unused ones, and regularly audit access to them.
- MattPalmer1086 4y agoYes, agreed. The report itself is not unreasonable. The article sets up a lot of straw men and demolishes them.