pg.ddx.io  pgsql-admin@postgresql.org mailing list archive  
help / color / mirror / Atom feed
From: Alvaro Herrera <alvherre@alvh.no-ip.org>
To: Wetmore, Matthew (CTR) <Matthew.Wetmore@evernorth.com>
Cc: David G. Johnston <david.g.johnston@gmail.com>
Cc: Siraj G <tosiraj.g@gmail.com>
Cc: sagar jadhav <sagarjdhv5@gmail.com>
Cc: Wasim Devale <wasimd60@gmail.com>
Cc: Kashif Zeeshan <kashi.zeeshan@gmail.com>
Cc: Muhammad Imtiaz <imtiazpg712@gmail.com>
Cc: Pgsql-admin <pgsql-admin@lists.postgresql.org>
Subject: Re: [EXTERNAL] Re: Detect who ran DROP schema
Date: Wed, 24 Jul 2024 19:22:23 +0200
Message-ID: <202407241722.yigc7p4tnajc@alvherre.pgsql> (raw)
In-Reply-To: <PH0PR12MB5499C8C2C4B5BECED962F686F5AA2@PH0PR12MB5499.namprd12.prod.outlook.com>

On 2024-Jul-24, Wetmore, Matthew  (CTR) wrote:

> This is a major issue in the DBA world as enterprise management lawyers get more popular.
> 
> At a large company I was at, there was only one elevated user, (which several people had user/pass) and then our personal accounts cannot do much due to modern corporate governance.  This is how it was set up.
> 
> As the DBA I couldn’t even log into the linux box where postgres was installed.
> 
> I couldn’t even change any logging without a two day ticket to do the work.
> 
> Not specifically this issue, but this is more the norm now-a-days then not.

Yeah.  This is an important if there are any potential attackers at all,
which given today's Internet, you can be pretty sure is always the case.

A database where people are allowed to connect as superuser is a sure
way to get in trouble sooner rather than later.  Having layered security
is one of the first things you should be thinking about.

FWIW I think even that one elevated user to which several people have
user/pass is a bad idea; forensics would require to know who used the
password when.  It's better to have one elevated user _without login privs_,
to which people can SET ROLE when they require it.  This leaves a better
trail.

If you add something like pgAudit to the mix and direct its logs (or all
Postgres logs) to a remote server where they can't easily be tampered
with by attackers, you'll have a better trail of who did what, when,
with what credentials.

-- 
Álvaro Herrera        Breisgau, Deutschland  —  https://www.EnterpriseDB.com/
"I can't go to a restaurant and order food because I keep looking at the
fonts on the menu.  Five minutes later I realize that it's also talking
about food" (Donald Knuth)





view thread (15+ messages)  latest in thread

Message-ID: <202407241722.yigc7p4tnajc@alvherre.pgsql>
Permalink:  ../202407241722.yigc7p4tnajc@alvherre.pgsql/
Also on:    postgresql.org/message-id/202407241722.yigc7p4tnajc@alvherre.pgsql

 · 

reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: pgsql-admin@postgresql.org
  Cc: alvherre@alvh.no-ip.org, Matthew.Wetmore@evernorth.com, david.g.johnston@gmail.com, tosiraj.g@gmail.com, sagarjdhv5@gmail.com, wasimd60@gmail.com, kashi.zeeshan@gmail.com, imtiazpg712@gmail.com, pgsql-admin@lists.postgresql.org
  Subject: Re: [EXTERNAL] Re: Detect who ran DROP schema
  In-Reply-To: <202407241722.yigc7p4tnajc@alvherre.pgsql>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by DDX for PostgreSQL; see mirroring instructions
for how to clone and mirror all data and code used for this inbox