Re: Epithet

SMiller_at_unimin.com
Date: 12/02/03

  • Next message: Shawn Jackson: "RE: Load is balanced web app is on Windows 2000 or 2003 servers?......"
    To: Steve.Kirby@sealedair.com
    Date: Tue, 2 Dec 2003 12:30:51 -0500
    
    

    Steve,

    I too have been doing this for a long time. A few years ago I would not
    have hesitated to suggest that the userid match the user's name as closely
    as the system would allow. However, I see far too many applications today
    that automatically cache this value, even when the user has elected not to
    cache the password (a practice BTW that I believe should barred by any sane
    security policy) So I guess my best advice is to evaluate the
    administrative benefits of easy user identification by that string (also
    consider how easy or difficult it might be to create and maintain a
    separate table that would correlate a "random" id with user identity) with
    the incremental risk from id-caching applications. In no case would I
    advise use of a unique and loaded value such as employee number as a user
    id.

    Scott
    "Specialists without spirit, sensualists without heart, this nullity
    imagines that it has attained a level of civilization never before
    achieved" - J. W. von Goethe

                                                                                                                               
                          Steve.Kirby@seale
                          dair.com To: security-basics@securityfocus.com
                                                   cc:
                          12/02/2003 12:36 Fax to:
                          AM Subject: Epithet
                                                                                                                               
                                                                                                                               

    To the list:

    We are currently developing a meta-directory project. One data element that
    we may now be able to re-define, is that of a User's Identification (UID).

    There are many 'schools of thought' about what should, or should not make
    up a UID. Do you include all or part of a person's name, do you use
    initials, what about an employee number (and what if they're a contractor
    without one)? The permutations are endless.

    Having worked for many years in administration of systems, I tend to think
    you should be able to derive who the user is - so you can ring them....
    just as you log them off! But is it necessary to identify the user easily?
    Could a seemingly nonsensical code be used to preserve anonymity? Is a
    jumbled UID a better deterrent against someone trying to forge an identity
    into our systems because they wouldn't know how it was made up or verified?

    The questions are almost endless, but I would be very interested to hear
    from others about their experiences or thoughts. No names, no packdrills,
    but examples of how UIDs are made up or UIDs you've come across would be
    gratefully accepted.

    Regards,

    Stavros

    or should that be GX78F2792?

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Shawn Jackson: "RE: Load is balanced web app is on Windows 2000 or 2003 servers?......"

    Relevant Pages

    • Re: Epithet
      ... mind that "security by obscurity" is quite useless. ... >advise use of a unique and loaded value such as employee number as a user ... >we may now be able to re-define, is that of a User's Identification (UID). ... The permutations are endless. ...
      (Security-Basics)
    • Re: IDS Feature Request List (including potential new requests).
      ... built ins so that they can be parameters to min, max, ... some very useful SQL to be written clearly for example ... would give you the next employee after Utah Carl Bozon in the table. ... Plus I have the UID in so that I now have the unique key to the record ...
      (comp.databases.informix)
    • Re: IDS Feature Request List (including potential new requests).
      ... some very useful SQL to be written clearly for example ... FROM employee ... ORDER BY last_name, first_name, MI, UID ... DB2 Solutions Development ...
      (comp.databases.informix)
    • Re: Epithet
      ... one doing th 'crqack' doesn't know what SHOULD be. ... Jimi Thompson wrote: ... >>up a UID. ... The permutations are endless. ...
      (Security-Basics)
    • Epithet
      ... we may now be able to re-define, is that of a User's Identification (UID). ... The permutations are endless. ...
      (Security-Basics)