Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, August 1, 2008

Microsoft SQL Server: World's most secure RDBMS

Hey, that's a pretty controversial headline for a mild-mannered blog like this one! But I think it's supported by evidence.

In November of 2006, Enterprise Strategy Group released an "Information Security Brief" that makes the following conclusions, based on Common Vulnerabilities and Exposures (CVE) data from the National Vulnerability Database:
  • Oracle’s results over the past two years show that much work has to be done to bring the vulnerabilities into line with competing database products from IBM, Microsoft, MySQL and Sybase.
  • ESG considers Microsoft to be years ahead of Oracle and MySQL in producing secure and reliable database products.
  • Microsoft’s results are almost too good to believe, and thus serve as a model for other database vendors.
During that same month, David Litchfield did a separate study based on a broader set of data and reported:
  • It is immediately apparent...that Microsoft SQL Server has a stronger security posture than the Oracle RDBMS.
  • The conclusion is clear – if security robustness and a high degree of assurance are concerns when looking to purchase database server software – given these results one should not be looking at Oracle as a serious contender.
Even before those reports were compiled, Cesar Cerrudo of Argeniss put together this presentation in which he provides lists of Oracle security flaws and SQL Server security strengths and asks, in apparent exasperation, "Why do you think [Oracle] is Secure?" And, "Why do you think [Microsoft] is not Secure?"

It's interesting that Microsoft has several pages on its website where you can find articles like these (albeit not these specific ones) touting the security of SQL Server, while I couldn't find anything on Oracles site (and I looked) citing independent analyses that provide evidence that Oracle is more secure than SQL Server...and Oracle has had a couple of years to respond.

OK...so, all of this does NOT mean that SQL Server is better than Oracle. Recent releases of Oracle 11g and related products offer all kinds of features that SQL Server doesn't. I'm certain that there are literally thousands of companies currently using Oracle that would be foolish to consider a switch to SQL Server. There may even be hundreds of companies that should seriously consider switching from SQL Server to Oracle, for any number of valid reasons.

But, c'mon, think about it: Microsoft SQL Server more secure than Oracle??? Are we talking about the same Microsoft and Oracle? Unbreakable Oracle?

And don't forget that ESG found SQL Server to be more secure than MySQL...and MySQL doesn't have a target painted on its back. Hackers exploiting flaws in MySQL would be like animal rights activists vandalizing PETA headquarters. Well, not exactly, but it makes an entertaining simile.

In any case, SQL Server has worked great for us. We're looking forward to using some of the features in SQL Server 2008. I'll try to describe how we end up taking advantage of those features in future posts.

Saturday, July 26, 2008

Who "owns" patient data?

One of the first hurdles that we had to clear as a SaaS company was the objection of providers who were accustomed to keeping their data within their offices. We called it "storing data in the broom closet", since in many offices the actual physical location of their server was no more secure than a utility closet. While the data was certainly NOT secure, it was accessible, or at least perceived as such.



In fact, there are many problems with that arrangement, among them:
  • Dismal disaster recovery (DR) options. I once heard that 60% of magnetic tape backups are unusable, although that number may be high. More conservative estimates vary between 10% and 50%. Within medical offices, where there generally is no dedicated IT staff, I would lean toward the higher estimates.

  • Lack of security. It would be easy for a disgruntled employee to unplug a few cables and carry the whole server out the door, or just bring in a laptop and wirelessly copy data from the server.

  • Risk of physical damage. Hundreds of medical offices were devastated by Hurricane Katrina, for example, and permanently lost huge amounts of irreplaceable patient information.
So, over time, our customers have accepted the fact that they are better off letting AdvancedMD keep their data for them, as long as we provide methods (standard data exports, ODBC access, etc.) for them to get access to it.

Now doctors are being faced with more dispersal of patient information, in the form of electronic prescribing systems, RHIOs, HIEs, PHRs, etc. I'm not a doctor (obviously), but I have to believe that this new sharing of data is a little disconcerting for some.

In the Summer 2008 issue of JHIM, Richard D. Lang, EdD, writes in "Blurring the Lines: Who Owns the Medical Data Home?" (HIMSS membership required) about the very objection that we used to face, but applied in a slightly different way.

Dr. Lang says:
Healthcare IT is evolving from a physician-centric model to
a collection of disparate patient-centric applications where
all constituents contribute to a mélange of databases that
serve people and processes in many different ways. By electronically
diffusing the traditional patient record, this new model blurs
the long-established medical data home.
As a true SaaS company, AdvancedMD assumes ownership of the provider's physical data, even though conceptually the data remains the property of the provider. Similarly, if a practice contracts with a billing service, the lines of ownership become further blurred, as the billing service assumes ownership of whatever data it needs to effectively bill for the practice's services. In that scenario, the billing service contracts with AdvancedMD, not the providers, so we are an additional level removed from the actual healthcare practitioner.

For eight years, we've proven that this data model can work, and, in fact, it works extremely well. It almost seems natural that, over time, patient information will continue to be further dispersed among interested parties that play a role in the patient's care.

As a patient, I kind of like the idea of spreading my information around, as long as it's secure. The next time I need to see a PCP and can't even remember who I saw last, wouldn't it be great if my new doctor could access my medical history without me having to remember it?

I have to believe that AdvancedMD's customers are better prepared for this "brave new world" than those who are still stuck in their broom closets.

Thursday, May 8, 2008

An IE security improvement that doesn't make our lives more difficult?

One of the key advantages of AdvancedMD over other (generally client/server) practice management systems is the fact that it is a browser-based application, built on the ubiquitous Microsoft Internet Explorer. That means that anyone can pick up a commodity PC at Best Buy or Costco, take it home, and run AdvancedMD without inserting a CD or contacting their PC support people.

AdvancedMD does, however, use a few ActiveX controls that allow us to do things that aren't normally permitted by the browser. Things like transparently saving temporary files to the local disk, compressing data, and managing printers.

When we first released AdvancedMD (as PerfectPractice.MD) back in 2000, Internet Explorer was on Version 5.0. Back in those days, the Internet was still relatively new, and Microsoft hadn't yet become every hacker's favorite target. So, security was a topic of discussion, but not the huge focus that it became in the months leading up to the release of Windows XP in August of 2001. (I'm relying on a Wikipedia article for these dates.)

In those good ol' days, ActiveX controls just worked. Sure, it helped to sign them (or, rather, the CAB files that contained them), but aside from that it was a piece of cake to deploy a control that could access the registry, read and write files, format the hard drive, beat the dog, stampede the horses, etc. The Wild, Wild West of the World Wide Web.

Since that time, the wizards at Microsoft have had a little fun at our expense (albeit, to be fair, to the benefit of IE users):

  • AdvancedMD domain must be added to Trusted Sites zone in order for ActiveX controls and many other functions to work.
  • The ActiveX controls within CAB files must be signed, not just the CAB files themselves.
  • By default, windows can't be sized or positioned in such a way that they appear off-screen, even in Trusted Sites zone.
  • A website can't be added to the Trusted Sites zone via javascript (IE6) or ActiveX controls (IE7).
  • On and on and on...

As a general rule, the AdvancedMD Engineering team emits a collective groan whenever a new version of IE comes out, because it means days of testing and retrofitting to comply with new security features.

IE8 will no doubt present some new challenges, but at least one new feature mentioned on the IEBlog may actually help us out.

For quite some time, some of our larger customers (the ones who actually have IT staff) have complained that, every year or so, we deploy new versions of our ActiveX controls. Since they have restricted their users' Windows accounts from installing software, their users are unable to install the new controls. Instead, an IT person has to walk from machine to machine, logging in as an administrative user and allowing the AdvancedMD browser application to install the controls.

IE8 has a new feature called "Per-User (Non-Admin) ActiveX" that, presumably, will make this a thing of the past. According to the IEBlog post:

"Running IE8 in Windows Vista, a standard user may install ActiveX controls in their own user profile without requiring administrative privileges."

Sounds pretty good to me. Now if we could just get away from ActiveX controls altogether...