Last week I attended a data management conference organized by DAMA NL. Good data quality, metadata, and data ownership are important. But it’s also hard to convince organizations and people to spend time and money on them.

And you know how history doesn’t repeat itself, but it rhymes? I hear echoes of the time I tried to convince organisations to improve security. To change that default Oracle password from “Welcome123!” to something less easily guessed, to patch that database software, and to apply the principle of least privilege.

I was talking yesterday to a colleague and team mate from years ago about that one time I had surprising success getting a manager to improve security. I thought I had written a blogpost about it on my old Oracle blog, but I couldn’t find it anymore. And it’s worth it telling the story anew, as best as I can remember it.

There was a health insurance company I worked for for two years in the early aughts. That was the time when the discrepancy grew between how easy I knew it was to hack systems and how little most organisations were willing to spend on improving security. It was a time before laws and compliance requirements really demanded it.

I was about to leave this health insurer for another assignment, but they asked me if I could come back one day every two weeks to work on the security. Since I had some extra time, I agreed.

The biggest issue in my mind was the application account. Let’s call the application Buffalo. The Oracle user buffalo had a wealth of roles and permissions. It owned a large database schema. And the password had the software brand and version number. And it hadn’t changed in years. We even had employees returning back to the company after a while who laughed that the password for buffalo was still the same. In my mind, it was the biggest security issue. So I submitted a change request to fix that.

It got denied.

The risk that some unknown process using buffalo might break was considered too great. All the more reason to work on it, if you ask me, but hey.

“You know, I can check how old the account is in DBA_USERS,” I said. “You can be sure the password is just as old.”

So I did. The account was about to turn five years old in a couple of months.

I joked, “We could celebrate it with cake. Congratulations on five years of the buffalo account password.” And the security officer said: “that’s actually a nice idea. I will suggest this in the next management team meeting.”

He did and sure enough, I got permission for the change of the password.

I was flabbergasted. 

So threatening with cake… did change their view on changing the password?

Artists impression of a database administrator treating cake to management. The text on the cake reads "5 years of the Buffalo account password!".
Artists impression of a database administrator treating cake to management.

Fast forward a few years. I was teaching an Oracle security course at Transfer Solutions. And of course the challenge to get management backing and fixing security came up. So I told this anecdote.

One of my students said he liked the idea. A year later I met him at another course I was teaching. 

“I’ve done what you said”, he told me. “I have treated our directors on cake. They asked for the occasion. And I said it was to celebrate that the password of their application accounts where ten years old”. 

Shocked, they immediately required the vendor, who had told my student that changing the password was impossible, to fix the issue.

And that’s how I apparently stumbled upon a new type of social engineering: the kind that nudges management into spending time and resources on improving security.

This blogpost was written by me, not AI. But I did ask Copilot to proofread this text for me and I have adjusted some things accordingly. The image was generated by ChatGPT.

Categories: Uncategorized

0 Comments

Leave a Reply

Avatar placeholder

Your email address will not be published. Required fields are marked *