Oracle FAQ Your Portal to the Oracle Knowledge Grid
HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US
 

Home -> Community -> Usenet -> c.d.o.server -> Re: Urgent News Flash

Re: Urgent News Flash

From: RSH <RSH_Oracle_at_worldnet.att.net>
Date: Wed, 05 Jun 2002 01:25:29 GMT
Message-ID: <dMdL8.23947$UT.1644131@bgtnsc05-news.ops.worldnet.att.net>


Well, I was thinking, bloody hell.

If I've ever done anything interesting, I'd hope the government would have the courtesy to tell me about it, so I could know the so far undiscovered naughty bits of my life from somebody, and hope at least they were fun.

The ISP's (many of the major ones, especially the US based ones) have begun voluntarily screening, filtering and sorting, and collating, and handing over things they feel whomever in the US Government might find of interest. What, I don't know; presumably email and other things related to terrorism and such. This can be done now essentially without what once was called due process of law. Apparently this extends to cellular telephony and even what once were sacrosanct simple analog telephone calls.

Also there's the poor computer system that was initially given the extremely pejorative name of Carnivore [that the FBI has since renamed to something more benign, like THX-1138], that's hugely powerful at processing and sorting most of the data passing through the Internet, and they apparently can feed it a list of people or IP addresses or whatever and it goes off like a trained Doberman.

But get real everyone.

There's been all sorts of direct and circumstantial evidence indicating that terrorists and the like have been making use of the Internet for quite some time in coordinating their plans, and there's even web sites with Martha Stewart [No aspersion or offense meant to Ms. Stewart] "How to Build A Horrible And Devastating, Yet Decorative Bomb" recipes. After September 11, someone had to unleash the bloodhounds.

I honestly do not know what to think or say, as an American, or as an IT / Database / Telecomm / Defense person. I know numerous freedoms are being infringed in unprecedented ways (for Americans; the Official Secrets Acts and such give some of our friends a bit more muscle). And all of our militia groups are up in arms about it all (not in the literal sense, hopefully.)

Any random idiot knows all telephone calls placed or received within the greater Washington DC area have been on intercept for years (widely rumored, I haven't seen the actual process, and therefore could not attest to it factually).

And should know that the NSA has the legal right, and uses it, to intercept any electronic communications it chooses that cross the US borders or airspace. I don't know who does the DC stuff, but in the NSA case, there at least used to be a rule that if either party to the call was a US citizen, the NSA had to just vault it, and could not divulge whatever they glommed onto outside the agency. (Besides, it's a wonder anybody can call anyone in greater DC, between using an Area Code, not using one, using 1+7 digit, omitting the 1, using 10 digit, with or without a 1 in front....)

I would suppose all bets are off, now.

But not all bets are off.

The people like us that have been entrusted with the ultimate responsibility for personal information, medical data, and other records that could be abused in the wrong hands, have a duty to "Question Authority", ask all these people who the hell they are, get clearance [in written form, if you're smart] from Corporate Legal, Medicolegal Records Retention, the office of the Judge Advocate General (or whatever you non-Colonists call the base lawyers/investigators) that stipulates specifically, in detail, what information is wanted, in what form, the reason for the demand, and the time frame in which it is wanted, and stipulates and instructs you, in detail, how you are to provide it.

It was always AT&T/Bell policy to tell any government geek with any kind of legal paperwork to go to Hell, and after they got done with that, go see Corporate Legal to have them write out orders, and nothing without a signature from a Bell/AT&T lawyer, on proper forms, would be acceptable.

(After which they were thankful for the brief sojourn in Hell, where the coffee is at least hot, they have better donuts, and at least the Sports Illustrateds and People and Time are less than 20 years old.)

Even with this dreadful threat (or series of threats) hanging over us, we still have a duty to the people that entrust us to protect their data and communications against improper intrusion, examination, duplication, or worst of all, alteration.

I don't think that's any kind of oath they make you swear in Oracle School, but perhaps, it ought to be.

Database Architects and Designers and Senior DBA's and DBA/Managers out there, listen up; if you do not have systems and methods and procedures in place to protect your data, or if necessary, to obliterate it if Nasty [i.e.., terrorist type] People show up, start thinking about it, have a core security / terrorism (oh, call it Disaster Management if you want) group including the senior production SA and DBA, development SA & DBA, the Architect/Managing DBA/blah, the Network Administrator, and the Security Administrator, and talk to each other.

Entrance keycoding that includes a "yeah let us in, but guys with guns are behind me, so send lots of cops on silent alert would be nice" code is nice to have. Outright access denial can make people, particularly you.

It's never come to this, but I've worked some sneaky FKD measures into systems (Few Keys Destroy); "Oh golly, it'll just be a few minutes".........like until we get backup tapes from Wyoming, by which time the FBI et al will have your butts in jail.

More innocuously, little scripts and stored procedures that, say, set off an entire ANALYZE, COMPUTE of the database can buy time as well. In any case, users in Podunk, Iowa will not be happy; but Oracle has yet to provide a clandestine way for the Managing DBA to send a message like:

"Sorry for the inconvenience. Oracle Services will be temporarily unavailable until the police come and take away this guy holding a gun to my head. If you have an urgent request, please direct it to x8-1775 during the interim for assistance. Thank you."

RSH. "Niall Litchfield" <niall.litchfield_at_dial.pipex.com> wrote in message news:3cfd28d8$0$8509$cc9e4d1f_at_news.dial.pipex.com...
> "RSH" <RSH_Oracle_at_worldnet.att.net> wrote in message
> news:Hp7L8.23356$UT.1600981_at_bgtnsc05-news.ops.worldnet.att.net...
> > No, we just don't need to be crooks or terrorists.
> >
> > RSH.
> >
> > <Adndrew_at_novaresponse.com.au> wrote in message

>

> and anyway if the Australian govt comes knocking I'll just tell them where
> to go. They don't have jurisdiction in Hampshire.
>
>

> --
> Niall Litchfield
> Oracle DBA
> Audit Commission UK
>
>
>
>
Received on Tue Jun 04 2002 - 20:25:29 CDT

Original text of this message

HOME | ASK QUESTION | ADD INFO | SEARCH | E-MAIL US