Re: BYPASS privilege !!
- From: JF Mezei <jfmezei.spamnot@xxxxxxxxxxxxx>
- Date: Mon, 11 Jun 2007 20:05:46 -0400
Richard B. Gilbert wrote:
Yes, it can! It may take me days to remember exactly what it's called but there is a secondary password that can be required to log in to an account; IOW two passwords, only one of which is known to the system manager. I've never known a site that actually used this feature but it's there!
Two passwords are not secure.
Consider an emergency where the system manager is at work, but the second person is at home or on a business trip.
I once had the two master passwords to a SWIFT application for those reasons. Eventually, having the system up and running has priority over what auditors demand and when push comes to shove, they have to waive those restrictions.
The one advantage of the two password scheme is that it prevents access via POP and FTP and probably other apps that are designed to work with a single password.
In fact, what might be interesting to do is a program which backs-up SYSUAF and RIGHTLIST on a daily basis, and compares that day's SYSUAF with the previous day's backup and then corroborates every chantge against the audit log to detect if any differences were made that were not logged and ring alarm bells when it finds some unaudited changes.
.
- References:
- BYPASS privilege !!
- From: BaxterD
- Re: BYPASS privilege !!
- From: JF Mezei
- Re: BYPASS privilege !!
- From: Richard B. Gilbert
- BYPASS privilege !!
- Prev by Date: Re: %TCPIP-E-ROUTEERROR from TCPIP SHOW ROUTES...
- Next by Date: Re: BYPASS privilege !!
- Previous by thread: Re: BYPASS privilege !!
- Next by thread: Re: BYPASS privilege !!
- Index(es):
Relevant Pages
|