6 ms·
I do have one problem with part of this article. > From a purely technological standpoint, these two scenarios are exactly the same [...] Neither of these diff
by pudquick 13y ago
I do have one problem with part of this article.
> From a purely technological standpoint, these two scenarios are exactly the same [...] Neither of these differences is visible to the company’s technology - it can’t read the employee’s mind to learn the motivation[...]. Technical measures that prevent one access scenario will unavoidably prevent the other one.
Emphasis on the last sentence - since this is only due to implementation in the chosen example.
As a counterpoint example, a system that allows for user data access only after a request has been made to access that data, the request is recorded in a request log system of some sort, and approval for the request goes through the appropriate checks (legal and procedurally) at which point it's signed off on and data access can occur.
(The counter-counter-argument is that technology isn't perfect and someone with the right access could potentially get around it ... but enterprise key management is a real thing, folks)
In this sort of system, the "intent of the employee" piece is encoded in the checks/approval piece as long as you make sure the same employee making the request is not the one with approval rights and that legal representation gets included in the loop for these types of accesses.
In this situation the hypothetical criminal syndicate would have to mount a larger and larger attack involving more people and greatly reducing the chance of it happening.
A government, however, would just pile on the legal requests and increase the number of employees involved until the request could be potentially be satisfied. By doing it this way, you make it unlikely for the government to il/legally pressure a single individual and instead involve your company's legal representation and a larger portion of the government's legal apparatus in determining if the request is valid - and in the meantime create some sort of documentation about the event (even if you can't publish / talk about the documentation while you're going through the courts).
The only advantage in defensive design where you literally cannot access your customer's information is that it absolves you of knowledge of what any one specific customer is doing. However, you increase your risk exposure to your services being used for illicit purposes (as defined by whoever is bringing a lawsuit against you), potentially being shut down, and potentially losing money as a result.
Some companies are ok with accepting that cost (in return for something that you can't put a price on) - most aren't.
There is a big difference between no employee can access the data and no single employee can access the data.
- Amadou 13y agoA couple of somewhat contradictory points: (1) Procedures are only as good as the people who follow them. Somebody has to actually access the data - that guy is the insider you have to worry about bypassing the procedures. Maybe I am just not imaginative enough, but I can't think of a scenario that is completely immune to the single insider. The best I can come up with would be key-splitting such that everybody with a piece of the key would need to agree that it is a valid access request. But even then you have to worry about the process for generating the key before it is split. Even if everybody is in the room when it is generated and split, you have to worry about whether the computer doing the generation wasn't compromised by the insider to surreptitiously make a copy of the whole key. (2) The idea of creating a system for data access presupposes that any developer must cater to the potential desires of law enforcement and make the effort ($$$) to accommodate them before they've even issued a valid court order. CALEA has put that burden on some telecom operators, but on the other hand the Clipper Chip with its key escrow system was an attempt to manipulate the market into building such access into all encrypted comms and Congress didn't even come close to passing that for government use and so the free market didn't even try. CALEA: https://en.wikipedia.org/wiki/Calea https://en.wikipedia.org/wiki/Calea Clipper: https://en.wikipedia.org/wiki/Clipper_chip https://en.wikipedia.org/wiki/Clipper_chip EDITED TO ADD: (3) There is also the trade-off between security and cost. We all know there is no such thing as perfect security, only an increasing level of cost to circumvent or penetrate. As you mention, a procedural system gets more expensive to compromise the larger the number of people necessary to grant access. But at what point does the cost to bribe or otherwise co-opt all those people equal or exceed the cost to crack the encryption? Just a SWAG, but lets say a well-implemented encryption system takes $100M to crack, how many people can you compromise for the same amount of money? What if $25M is enough to buy the entire company outright? A system that is more expensive to crack because the only means of access is through good crypto is a more valuable service than one with an access procedure involving humans. Maybe that theoretical drug cartel can afford $25M but they can't afford $100M. So a user of a pure-crypto system would be safe from the cartel but one with a process for law-enforcement access would not.
- kefka 13y agoAnother possibility is to split the keys and include external keyholders, like famous security researchers and lawyers. And give everybody 2 keypairs. One keypair slowly corrupts the database while the other is legit.