5 ms·
Why would you give someone the ability to impersonate people with higher clearance? That seems like poor design from the start.
by Ellipsis753 13y ago
Why would you give someone the ability to impersonate people with higher clearance?
That seems like poor design from the start.
- theg2 13y agoThat is the issue with technology and those in power who don't know how to use it. If a General or higher up is having an issue with classified data, it's not like he can just look at the error message and then go home for the day, he requires an IT team to help and maintain the systems. A DBA can't do their job if they can't access the databases they manage/design/maintain.
- pothibo 13y agoThe same reason a secretary would have the keys to unlock her boss' secret file drawer. Convenience.
- pilom 13y agoI'm highly skeptical of the reporting. He may have impersonated other accounts to cover his tracks but if he had physical access to a system or the user database of a system then he was "authorized" to see all of the data on that system. Or they are doing IT security worse in that office than it is usually done.
- sigzero 13y agoNo he wasn't. Security is a "need to know". Just because you have a TS clearance for example doesn't mean you have access to all TS information out there. If you step over that then you get slapped down.
- stcredzero 13y ago> they are doing IT security worse in that office than it is usually done Two things that are undeniable: 1) They were doing IT security worse than the level which was actually needed 2) All the while, they were telling the world that effective mechanisms were in place which would prevent abuses. So they weren't doing what they were supposed to and they were deceiving the public about it. Whether or not this was intentional is just secondary.
- betterunix 13y agoI see two possibilities, though I am not that well-versed in the software used at the NSA: 1. Administrator accounts were not confined (in the SELinux sense), so he was able to transition to whatever security context he needed/wanted. 2. He was able to set up the login credentials for other users. He could have created his own accounts with higher-level clearances, or set up his own smartcard for logging in to some other person's account, etc. It may seem like poor design, but it is understandable why things might have been set up like that. In the first case, it is because the admins need to be able to solve problems that happen in a variety of security contexts / levels, and the overhead of defining a second set of policies governing the admins was just too high. In the second, it would be because someone has to be able to set up credentials and that there are a lot of systems for which credentials must be set up, making it hard to impose restrictions. There is also the matter of audit logs -- it might not be so bad to allow an admin to transition to whatever security level if each transition is logged. I suspect that much of the NSA's computer security is devoted to ensuring that people do not accidentally leak classified information, and that preventing insider attacks is done at a higher level (the clearance process, random audits, etc.).
- stcredzero 13y ago> preventing insider attacks is done at a higher level (the clearance process, random audits, etc.) So long as "preventing insider attacks is done at a higher level" isn't synonymous with: "once you're hired as sysadmin, you have the unsupervised keys to the kingdom!"