Tag: security

  • ETL Security Holes

    The addition of DTS to SQL Server meant that more and more of us could grab data from a variety of sources, easily, and move it to SQL Server systems. SSIS enhanced our capabilities and made it fairly simple for non-programmers to grab web service data, and other formats, and quickly decompose them into relational formats. This made it more likely that we would build data warehouses or reporting systems, and easily keep them up to date with data from our OLTP systems.

    However the ease of using ETL (extraction, transformation and loading) processes to move data did not include the moving the same security controls and restrictions to these new systems. That can create a big security holes, especially when you have secondary systems used for decision support that might not be contained in the production network and not audited to the same level as other production systems.

    Whenever you move data around, there ought to be some set of guidelines for the security protocols required. That can be hard to track when you are pulling data from a secure system and your connections look like every other connection. One of the dangers that I suspect we will run into with Powerpivot is that secure data will be downloaded to Excel worksheets on insecure systems, and all of the controls that we have in place for protecting sensitive information are ignored when we pull data for analysis elsewhere.

    Our data security has gotten better, but we have a long way to go. If you are working with ETL processes, and especially with end-users, make sure that some sort of security policy is in place to help protect this data from being accidently disclosed. It’s not a great suggestion, but until we have better security tools to allow policies to follow the data, that is all we can do.

    Steve Jones

    (originally published at http://www.sqlservercentral.com/articles/Editorial/72157/)

    Podcasts

  • In Case of Breach


    What would you do if you received a phone call in the middle of the night saying that one of your databases had been hacked and data released? Do you know what to do as a first responder? There’s a report from Dark Reading that talks about some of the things you might want to consider.

    Crisis situations, and this is definitely one, require some planning and thought ahead of time. You ought to have some sort of “run book” similar to the one you have for disaster recovery, that helps you decide how to handle the situation. Unlike many troubleshooting situations, rebooting a server might be the worst thing you can do.

    I used to think that database people were more insulated from responding to these types of crisis situations. It seemed early in my career that we would be backups for the system administrators, and not necessarily need to respond to a midnight call. However the last 5 years have shown that this type of call is more and more likely for all data professionals.

    As we store more and more data, of great importance to the organization, we should be more prepared to respond to these types of incidents. Financial, identity, medical, and other types of data are becoming mixed in with all sorts of business data. As we build warehouses and transfer data among more systems, the likelihood we have data needing strong protections increases.

    At the very least, we must educate ourselves on our legal responsibilities as the data profession moves forward. More and more laws are being passed and regulations applied to data, and a good data professional in the future needs to be aware of their responsibilities in this area.

    Steve Jones

  • Getting a Dedicated Admin Connection

    Did you know you can easily get a Dedicated Admin Connection (DAC) in SSMS? I didn’t assuming that I’d need to use a command line and SQLCMD. However while studying for the MCM, I learned that there’s an easy way.

    I tested this on a SQL Server 2008 instance, having a normal connection, as seen in the lower status bar:

    admin_connection2

    Right click in the query window, and select “Change Connection”. In the dialog, not add “Admin:” before the server name, as shown below.

    admin_connection

    When you connect, you’ll have an admin connection, which you can see in the status bar.

    admin_connection1 

    Pretty cool.

  • Elections

    In the last few elections in the US, there has been concern over the validity of votes. As more and more electronic machines are being used to record votes, and often being built with very little security, how can we be sure that the data is being collected, tabulated, and securely stored for our elections? It’s an issue that most countries face, and will continue to face as they deal with larger and larger elections.

    Developing a secure way to collect, store, and verify data is hard. We struggle with that on a regular basis, and I think we often tend to ping across both ends of the spectrum on how to handle this. We tightly control all access and storage of data,  keeping access as limited as possible, and we still have regular problems with data loss and breaches. Or we may open up our systems to large groups of users, essentially ignoring security. Is there any hope for voting data?

    I came across this idea from David Bismark that explains a fairly simple, and reliable method of both allowing access to data, while also keeping the secrecy necessary for each person’s vote.  It’s in a TED Talk that discusses the idea in a few minutes, and it’s rather amazing.

    I don’t know if there’s something we can learn here to apply to other data issues, but I would guess that any area that needs to distribute data while protecting privacy could use something similar.

    Steve Jones