{"id":84987,"date":"2019-08-12T03:25:02","date_gmt":"2019-08-12T03:25:02","guid":{"rendered":"https:\/\/www.red-gate.com\/simple-talk\/?p=84987"},"modified":"2019-08-12T08:59:21","modified_gmt":"2019-08-12T08:59:21","slug":"hiding-what-you-shouldnt-see","status":"publish","type":"post","link":"https:\/\/www.red-gate.com\/simple-talk\/opinion\/editorials\/hiding-what-you-shouldnt-see\/","title":{"rendered":"Hiding What You Shouldn&#8217;t See"},"content":{"rendered":"<p>Back when I was working on a master\u2019s degree, one of our professors told us a story about a colleague who learned how to navigate the Unix system. She was so thrilled about learning this new skill that, in her exuberance, she stumbled upon some hidden human resource files containing confidential information. Eventually, an administrator realised that the woman had located these files and told her \u201cyou can\u2019t do that.\u201d Well, she could and did do that. Even though the files were hidden in the hopes that people wouldn\u2019t find them, they were not secured. Security by obscurity doesn\u2019t work because someone will eventually find what you are trying to hide if they are motivated and put enough effort into it.<\/p>\n<p>On the other hand, there is the problem of showing resources to people when they don\u2019t have rights to them. Nothing is more annoying than clicking on a link and then being told that you do not have permission to view the resource. It would have been better if you hadn\u2019t known about it at all.<\/p>\n<p>In a Windows shop, administrators control what people can do and access by using Active Directory ACLs (access control lists), group membership, and Group Policies. Security in AD can get complicated quickly. To ensure administrators follow the principle of least privilege, proper planning and assigning rights to groups instead of to individual users are essential. I\u2019ve not been an AD administrator, but from a user perspective, it seems to do a good job of both securing and hiding resources.<\/p>\n<p>SQL Server doesn\u2019t always hide what you shouldn\u2019t see. Say an account only has SELECT permission on one table in one database on a server. The account can view all the databases when using SSMS, even those where they can\u2019t connect. After connecting to that one database, they only see the one table in SSMS, but querying other tables returns an error message stating that SELECT permission is denied. A different message appears when attempting to query a nonexistent table. While the specific messages are useful for troubleshooting permissions problems, they give too much information to someone with evil intentions.<\/p>\n<p>Once security has been figured out, it easy for organisations to enable self-service for things like business intelligence or even provisioning virtual machines. It\u2019s essential, however, that the user is not overwhelmed with too many choices. Having too much from which to choose wastes time and can be quite frustrating.<\/p>\n<p>Take a product like <a href=\"https:\/\/www.red-gate.com\/products\/dba\/sql-clone\/\">SQL Clone<\/a>, for example, with its new Teams feature. Until the recent 4.0 release, DBAs could only control who could create images and clones, not which ones they could create. For a small shop, that might be good enough. In a bigger team, this might discourage DBAs from allowing self-service to keep someone from creating a clone from an image they shouldn\u2019t see. With the new Teams feature, a DBA has precise control so that developers can only create clones from specific images. This makes self-service more attractive and saves time for everyone involved.<\/p>\n<p>Just hiding what people shouldn\u2019t see never works. Showing them more than they need to see is annoying for the users. Getting security right is a win for both admins and users.<\/p>\n<div class=\"spaced-bottom padded--tight scheme--lightest-grey\">\n<h4>Commentary Competition<\/h4>\n<p>Enjoyed the topic? Have a relevant anecdote? Disagree with the author? Leave your two cents on this post in the comments below, and our favourite response will win a $50 Amazon gift card. The competition closes two weeks from the date of publication, and the winner will be announced in the next Simple Talk newsletter.<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Back when I was working on a master\u2019s degree, one of our professors told us a story about a colleague who learned how to navigate the Unix system. She was so thrilled about learning this new skill that, in her exuberance, she stumbled upon some hidden human resource files containing confidential information. Eventually, an administrator&#8230;&hellip;<\/p>\n","protected":false},"author":110218,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[47125,53],"tags":[68855],"coauthors":[11292],"class_list":["post-84987","post","type-post","status-publish","format-standard","hentry","category-editorials","category-featured","tag-sql-provision"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/84987","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/users\/110218"}],"replies":[{"embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/comments?post=84987"}],"version-history":[{"count":6,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/84987\/revisions"}],"predecessor-version":[{"id":84993,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/posts\/84987\/revisions\/84993"}],"wp:attachment":[{"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/media?parent=84987"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/categories?post=84987"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/tags?post=84987"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.red-gate.com\/simple-talk\/wp-json\/wp\/v2\/coauthors?post=84987"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}