{"id":2800,"date":"2011-10-25T06:51:30","date_gmt":"2011-10-25T10:51:30","guid":{"rendered":"https:\/\/webhostinggeeks.com\/blog\/?p=2800"},"modified":"2021-10-19T06:48:33","modified_gmt":"2021-10-19T10:48:33","slug":"case-of-the-overzealous-security-guard","status":"publish","type":"post","link":"https:\/\/webhostinggeeks.com\/blog\/case-of-the-overzealous-security-guard\/","title":{"rendered":"The Case of the Overzealous Security Guard"},"content":{"rendered":"<p>Just last week, I had an interesting experience with a web host that I use (as always, names of the guilty withheld).\u00a0 It highlighted some of the things that I&#8217;ve talked about in this column about customer service, security, and employee empowerment.\u00a0 It wasn&#8217;t that big of an issue, but it was a reminder of how little problems can easily cascade, eventually resulting in lost customers (which I considered becoming before they fixed the problem).<\/p>\n<p>Let me hit rewind and go through the play-by-play.\u00a0 I think there are some important lessons to be reminded of here.<\/p>\n<p><strong>The prosecutor\u2019s case<\/strong><\/p>\n<p>I was attempting to setup a common <a href=\"https:\/\/www.webopedia.com\/definitions\/cgi\/\" target=\"_blank\" rel=\"noopener\">CGI<\/a> package on my account. I went on for a while and ran into problems that I knew meant that there was something wrong with either their servers or the installation process.\u00a0 The host&#8217;s online help docs didn&#8217;t get me anywhere, so I went searching around the net.\u00a0 With a little Google mojo, I found a good lead.\u00a0 There was a configuration file that needed to be adjusted.<\/p>\n<p>The problem was that it wasn&#8217;t clear exactly how it was supposed to be adjusted.\u00a0 I tried just about everything obvious.\u00a0 Nothing worked.\u00a0 Finally at a standstill, I threw in the towel.\u00a0 I dropped an email to their tech support.\u00a0 They had an online submission form, but it went to the email that the host provides, which I&#8217;d never used or redirected.<\/p>\n<p><strong>The defendant&#8217;s case<\/strong><\/p>\n<p>I received a reply back pretty quickly.\u00a0 It stated that since my address wasn&#8217;t the primary email address for the account that, per their security procedures, they would have to contact the address that was, and see if this was a valid address to offer tech support to. From that point on it was mostly smooth sailing.<\/p>\n<p>Well, gee, that doesn&#8217;t sound all that bad.\u00a0 <em>So where&#8217;s the problem?<\/em><\/p>\n<p><strong>The cross-examination<\/strong><\/p>\n<p>There were a few of them.\u00a0 First of all, even though it was true that I wasn&#8217;t writing from the contact address on file, I did include in my email to them the domain name that I was working on, and two forms of customer ID numbers that you can only get from within the account.\u00a0 Furthermore, I pasted in the entire error message that I was getting, again something that proves that I was already in.\u00a0 Given all of the information that I gave to them, it would have been trivial as well to check through their logs to see that I was, indeed, doing the work on this site that I said I was.<\/p>\n<p>In short, it should have been clear that I already had full access to the site.\u00a0 One could counter that this doesn&#8217;t necessarily mean that I didn&#8217;t hack into it.\u00a0 There are problems with this response as well, though.\u00a0 For starters, I could just as easily hack into someone&#8217;s email as I could their web hosting account, <em>so how would that have been de facto more secure<\/em>? \u00a0Additionally, if I really did hack in and wanted to contact them for help, why would I have \u201ctipped them off?\u201d\u00a0 There were certainly ways to write them that wouldn&#8217;t have.\u00a0 I could have actually used the in-house contact form.\u00a0 I could have just changed the contact email address once I was in there.\u00a0 On the other hand, it&#8217;s common for multiple people with different addresses to be working on the same account.<\/p>\n<p><strong>The verdict: guilty of misdemeanor<\/strong><\/p>\n<p>In the end, this only resulted in a short waste of time for us, but what if that time had been critical?\u00a0 It was, in truth, something I was trying to setup quickly, and the delay was quite irritatingly timed.\u00a0 The greater problem, though, was that it was unnecessary.\u00a0 The amount of assumptions that you would have to make to conclude that I was an intruder is too high to be easily plausible.<\/p>\n<p>Of course, no web host wants to take unnecessary chances on security.\u00a0 <em>So maybe was there another way?\u00a0 <\/em>Yes: the host could have responded to my request with the necessary technical information, then dropped a separate note to the email address on file telling them of the conversation and verifying with them that I was indeed authorized to be working on the site.<\/p>\n<p><strong>The sentence: make your security more dynamic<\/strong><\/p>\n<p>This approach would accomplish multiple things.\u00a0 It would, of course, let me continue working on the site immediately.\u00a0 On the miniscule chance that I really was a bad guy, it would still let the account holder know about it.<\/p>\n<p>It would also have another subtle advantage on this note.\u00a0 If I were truly a hacker, and I got an email saying \u201cWe&#8217;re going to check on you\u201d, that would be my cue to cause whatever damage I was meaning to and get out of town.\u00a0 Instead, using the above approach, you can keep a quiet eye on them to see exactly what they are doing.\u00a0 This approach would have been more secure.<\/p>\n<p>This goes back to the inherent deficiency of unbending rules.\u00a0 We mentioned in the past that it&#8217;s better to cut your employees some slack and given them the room to make judgment calls.\u00a0 This is a great example of why.\u00a0 A single tech worker given the room to think about this email could easily have come to the above correct conclusions.<\/p>\n<p>On the other hand, if you make your security procedures rigid to the letter, you hand the people who really do want to cause damage a road map telling them exactly how to get in.\u00a0 If your procedure is dependent partially on well thought-out rules and partially on \u201ccommon sense\u201d, an intruder will have a harder time penetrating it.\u00a0 Meanwhile, the entire tech world is filled with people who have been locked out of their own accounts because of overly strict security doors that they lost the key to.<\/p>\n<p>A co-worker I once had summed it up eloquently: \u201cLaziness and security never go together.\u201d\u00a0 A hard set of rules that you apply in all cases, even the most ridiculous, is lazy.\u00a0 Some workers may want to fall back on being that lazy, but that does no one any good.\u00a0 The sentence in this case is to teach your workers a bit more about how to spot the little things that signify that something is wrong, and then gives them the free hand to react to it intelligently, based on the specifics of each situation.\u00a0 It&#8217;s a little time invested for a lot of reward.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just last week, I had an interesting experience with a web host that I use (as always, names of the guilty withheld).\u00a0 It highlighted some of the things that I&#8217;ve&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"wds_primary_category":0,"footnotes":""},"categories":[9],"tags":[],"class_list":["post-2800","post","type-post","status-publish","format-standard","hentry","category-security-issues"],"views":100,"_links":{"self":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/posts\/2800","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/comments?post=2800"}],"version-history":[{"count":0,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/posts\/2800\/revisions"}],"wp:attachment":[{"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/media?parent=2800"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/categories?post=2800"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/webhostinggeeks.com\/blog\/wp-json\/wp\/v2\/tags?post=2800"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}