dimanche 28 décembre 2014

Right security architecture for SQL Server access in a distributed Windows-based system



I am designing a software product for which multiple SQL Server databases will be accessed by multiple applications residing in different Windows environments. Some of the environments are process hosts that run scheduled jobs against the databases. Some of the environments serve as APIs for the data. In all cases, the applications access the databases via an ORM (Entity Framework).


As a software engineer I'm getting better at what I do. But as an infrastructure security engineer I've got a lot to learn. My current thinking is that I want to use Windows authentication only and forget about roles and logins at the database level. Further, I'm thinking to run scheduled jobs using the Local Service account and restrict access to the database servers by endpoint using the firewall. But I'm concerned that if I grant INSERT/UPDATE privilege to any Local Service account and somebody makes a firewall mistake in the future, I might be in big trouble.


Please help me. I'm in over my head. Thanks in advance :-D





TrueCrypt not working on OS X 10.10.1



Can someone help explain why TrueCrypt isn't working on OS X 10.10.1 anymore? I can't get any version to work and it is frustrating. I know TrueCrypt has been discontinued with development but it was working before. Help!





What to do with an old smartphone? 9 ways to reuse it!



So, you got yourself a brand new smartphone. Do you send your old one to the grave or the back or a drawer? Here's some ideas of how you can reuse it.



(This is a preview - click here to read the entire entry.)





How can I test my CAPTCHA's (or CAPTHA-alternative's) effectiveness?



Are there any tools out there to test the effectiveness of user turing tests, such as CAPTCHAs or honeypots, on a site without intentionally getting the site targeted by spambots?


Or do I simply have to implement a solution, deploy to production, and watch the results while hoping for the best?





Which manufacturers who make BadUSB possible on their drives?



So as we all know by know BadUSB is possible on Phison 2251-03 chips. But are there any more reflashable devices in the wild that could be dangerous? And if there are is the firmware easily changed or does it require OEM tools?

I'm asking about this because I have once, when broken my USB stick, stumbled upon a Chinese manufacturer flashing tools and although i couldn't understand how to actually do it I'd guess some people could actually make it work.





In what companies can I find internship/job in information security?



I am a computer science master's student from Europe, majoring in information security and looking for an internship.


The problem is that I have no idea what jobs there are in what kinds of companies in information security.


I am very interested in almost all aspects of information security, but I am most interested in the theoretical parts, such as cryptography and formal methods of information security. Does anybody know of any jobs/companies where one has the opportunity to formally proof properties about a system, model systems to find attacks automatically, analyse/develop new cryptographic protocols or any similar thing? Or does anybody have advice what other jobs there could be in information security if one does prefer to not be programming all day?


I am very thankful for any hint!





My card has been flagged as high risk by online web host company, must provide "material" to override



Recently i changed my credit card since my last one expired. However my hosting company rejects this card because of a "3rd party risk estimator" has flagged it as high-risk, or something like that. In order for me to be able to override this risk estimator and be able to pay for my host, i have to provide some "verification material" which is a picture of the back of my credit card (signed) and my government issued ID on a paper that has "I authorize ******.com to charge this card" written on it, aswell as my signature. This seems awfully fishy to me, and i'm worried that they can use this to take all my money or something, i'm not really familliar with this kind of stuff. I have however been a customer for over 2 years and they haven't done anything like this before, and everything has been working as it should. Is this safe to send? Can they steal all my money if i send this or is this standard procedure when a card has been flagged as high risk? Thank you for your help!