AWS security exec: You don't want to win this database popularity contest
- Reference: 1680029703
- News link: https://www.theregister.co.uk/2023/03/28/aws_ciso_director_database_security/
- Source link:
"Databases are hard to manage, and people have taken the easy path: given lots of people admin privileges and hardcoded database credentials into their software," says Mark Ryland, a director in Amazon Web Services' Office of the CISO.
Complexity is the enemy of security, and, let's face it, databases aren't simple. It's an area that requires better "education, better technology, and better automation," he told The Register , in a conversation about database security, which you can watch below.
Database administrators aren't the only ones looking for the easy button, however. Crooks looking to break into databases are, too, and when it comes to choosing a target, they want the highest return on investment, so they're going to attack the vault with the most users that's most likely to be poorly protected.
"Attackers are pragmatists," Ryland said. "The popularity of the database has more to do with it than the database itself. It's almost a popularity contest, in this case not a good one, for those who are looking to do malicious activity."
[1]
There's no inherently insecure option, he added. Popular open source and commercial databases are protected — "if they are properly installed and configured and managed." That's a big if, and one that organizations probably won't want to take a chance with.
[2]
The bottom line, for both managed databases and DIY options, is defense in depth, according to Ryland. "You really want to have multiple levels of controls in case one level fails." ®
Get our [3]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightondatabases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCNjgKw6KKisGDIVn7ftsgAAAIg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/spotlightondatabases&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCNjgKw6KKisGDIVn7ftsgAAAIg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://whitepapers.theregister.com/
The Easy Path was Taken: Why?
"Databases are hard to manage, and people have taken the easy path: given lots of people admin privileges and hardcoded database credentials into their software," says Mark Ryland
[database security is] an area that requires better "education, better technology, and better automation," he told The Register
I agree many people have taken the easy path. What I question: how many of those db admins and coders took the easy path because they were ignorant, had lacked sufficiently-good technology, and had lacked sufficiently-good automation, and how many of them took the easy path because their supervisors grossly overscheduled them?
(Icon for "Hmm...")