![]() |
|
|
|
Registered
|
OK you IT security guys
Am I over reacting or is it a legitimate complaint.
We have a vendor that we use to check PHI via a Java applet. Whole other ball of worms for me, but not the crux of the current issue. The issue is they communicate with the Java applet to their website to check for updates and whatever else and the web site has no certificate. It communicates via HTTP not HTTPS and Java complains that it is not secure so the vendor says just put it in the exceptions list. I tell them spend the $70 for a two years cert for their website since no part of their web is secure. It strikes me as an easy way to compromise the information behind that IP and certs are cheap. I can create a GPO to add the exception, but I don't feel I should have to because there is no reason they should not have a cert on their site. What say you all ye smarter than me?
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Cars & Coffee Killer
Join Date: Sep 2004
Location: State of Failure
Posts: 32,246
|
Someone would have to spoof their DNS to take advantage of that vulnerability, no?
I know with my employer, that would be a complete and total no-go and grounds for the immediate termination of our contract with them. While certificates aren't all that great, they are better than nothing.
__________________
Some Porsches long ago...then a wankle... 5 liters of VVT fury now -Chris "There is freedom in risk, just as there is oppression in security." |
||
![]() |
|
Registered
|
At least with a certificate you aren't broadcasting in the clear. Without a certificate it is much easier to penetrate a web site to see what is behind it. Been there, done that and don't need to again.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
The Stick
|
If their Java applet is vulnerable then that makes access to your stuff vulnerable.
ie they provide secure passwords to get to your stuff, but their system is hackable to get the credentials.
__________________
Richard aka "The Stick" 06 Cayenne S Titanium Edition |
||
![]() |
|
You do not have permissi
Join Date: Aug 2001
Location: midwest
Posts: 39,937
|
^man in middle scenario?
|
||
![]() |
|
Registered
Join Date: Oct 2003
Location: Roseville, CA
Posts: 3,066
|
Sure seems like a completely unnecessary gap when a $70 cert would at least make Java happy and add a little security.
__________________
1992 968 Polar Silver 2010 Toyota Highlander SE 2006 Lexus LS430 ML |
||
![]() |
|
![]() |
Registered
|
Quote:
So I lock all the doors, but I have to leave the bay window out so I can see.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Too big to fail
|
This makes my head hurt.
They need to suck it up and move to ssl. Do not pass Go, do not collect $200. A self-signed cert is also not the answer.
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had." '03 E46 M3 '57 356A Various VWs |
||
![]() |
|
Too big to fail
|
I assume you mean while self-signed certificates aren't all that great
__________________
"You go to the track with the Porsche you have, not the Porsche you wish you had." '03 E46 M3 '57 356A Various VWs |
||
![]() |
|
The Unsettler
|
No excuse for that other than pure laziness which would make me wonder what corners are they cutting on the hard stuff?
Especially when you have solutions like https://letsencrypt.org I'd be rethinking my relationship with this vendor and if you are in a position to dictate you should be squeezing their balls real hard.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
![]() |
|
Registered
|
My recommendation was that it would be a deal breaker. Just got back from a meeting and brought it up with the Administrator and DoN. They are now thinking the same.
The head of IT that was there when we first started dealing with this said they have a cert for the website. I said no you don't. He said he was told they did. The new IT guy there says just do a GPO and bypass the security message. I said no, buy a cert. That is what brought me here, to see if I am being too paranoid.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Slackerous Maximus
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,196
|
PHI. No ssl. Un-freaking believable. How can that be HIPAA compliant?
__________________
2022 Royal Enfield Interceptor. 2012 Harley Davidson Road King 2014 Triumph Bonneville T100. 2014 Cayman S, PDK. Mercedes E350 family truckster. |
||
![]() |
|
Registered
|
Quote:
I cannot cancel the project but I can and did highly recommend they find another vendor.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
The Unsettler
|
I share that opinion as I suspect many others would as well..
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
![]() |
|
Registered
|
Well at least if I am paranoid I am in good company.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Gon fix it with me hammer
|
without cert that automated crap of his is just that, crap
should not even be discussed. Anybody can jump in the middle and have you machine update itself with payload. Any machine can pretend to be that host.
__________________
Stijn Vandamme EX911STARGA73EX92477EX94484EX944S8890MPHPINBALLMACHINEAKAEX987C2007 BIMDIESELBMW116D2019 |
||
![]() |
|
Registered
Join Date: Mar 2003
Posts: 10,348
|
Don't even have to buy a cert - the EFF and letsencrypt will give you one for free (I use 'em at home and on a few work machines)
|
||
![]() |
|
Slackerous Maximus
Join Date: Apr 2005
Location: Columbus, OH
Posts: 18,196
|
Asking people to be vaguely competent is not paranoia.
__________________
2022 Royal Enfield Interceptor. 2012 Harley Davidson Road King 2014 Triumph Bonneville T100. 2014 Cayman S, PDK. Mercedes E350 family truckster. |
||
![]() |
|
![]() |
Registered
|
I forwarded the link from SM to them. Will see if they will comply and earn our business. At this point I trust nothing they say.
__________________
Brent The X15 was the only aircraft I flew where I was glad the engine quit. - Milt Thompson. "Don't get so caught up in your right to dissent that you forget your obligation to contribute." Mrs. James to her son Chappie. |
||
![]() |
|
Registered
Join Date: Dec 1969
Location: chula vista ca usa
Posts: 5,703
|
If it were me, and some years ago it was the company I worked for was trying the same approach with letting customers check for updates and 9 times out of ten they would get them and never read the SQL instructions of other notes and we would have to do repairs. I finally convinced the CEO to stop with letting the customer get and try the updates. Then we did the Oracle method, we emailed them and provided a link to a secure (sort of) FTP site we had and it required them to use HTTPS which of course is only a small part of the whole security setup required.
Amazingly everyone ended up way happier aa year or so later. I had also implemented a short program to verify the software was not modified or any table/field changes to the database. If there was, we had to find out why (the SAP methodology)! |
||
![]() |
|