Re: security risks
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 15 Apr 2004 04:02:38 BST, =?iso-8859-1?q?Zarina=20Musa?= <[email protected]> said: > Hope any one can give some ideas on this. > What are the security risks for allowing a client > software security function such as signing to be > called by external software? An often overlooked point: The risk is equal to the value of the data to the owner, or the value of corrupted/destroyed/forged data to an attacker, whichever is greater. Note that the two values are usually *not* symmetric - for instance, although the residual value of a valid entry for a claim form in an insurance company's database may be close to zero except for data mining value as an actuarial data point (as it's just documentation of a processed claim), the ability to inject a bogus entry may be of great value to somebody engaging in insurance fraud.
signature.asc
(application/pgp-signature, 226 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFAfvA5cC3lWbTT17ARAj2OAJwPV/YjNmFC9Od/5Of3Ypn3+0UW4gCgmSdF VjAP29PZfucrl7KICc51fM8= =uL+5 -----END PGP SIGNATURE-----