Comments: Nearly 6 million gamers hit by ‘Battle for the Galaxy’ data leak

Comments: Nearly 6 million gamers hit by 'Battle for the Galaxy' data leak

Comments by: Tim Mackey, Principal Security Strategist, Synopsys Software Integrity Group

With the prevalence of misconfigured databases, it’s clear that some teams lack the ability to confirm they are using a secure configuration for their production systems. There are a number of potential remedies, but one of the simplest is to define an exception based update model for configuration settings. Under this model, an audit level review of configuration data is performed to create a set of approved configuration settings and files. Any update to those previously approved settings then requires that same audit level review for the changes, and current configuration is always validated against approved settings. While there are a number of technologies that can be used to implement exception based updates, this is a case where a well defined process with automated checks is far more valuable than the technology implementing the process.

Author

  • Hello! I’m Mark, the founder of techcoffeehouse.com. I love a good plate of Chicken Rice. So, if you have a story as good as the dish, HMU!

    View all posts Managing Editor

Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading