SyncriTab

Security & Encryption

SyncriTab gives people access to your databases, so protecting it matters. This page explains each security setting and how SyncriTab protects the data it stores.

The Security tab

Most security settings are on the Security tab of the Configuration page. Sign in as an administrator, click Configuration in the side menu, and open the Security tab. After making changes, click Save.

The Security tab with administrator email, MFA, IP blocking, encryption, and session timeout settings.
Security settings on the Configuration page.

Alert and sender addresses

Both need a working email server. See Email Configuration.

Mandatory two-factor authentication

Two-factor authentication (MFA) asks for a one-time code after the password, so a stolen password alone isn't enough to sign in. Users can turn it on for themselves (see Your Account), but you can require it for everyone by selecting Mandatory MFA.

SyncriTab turns it on only when all of these are true, and otherwise lists what's missing:

Once it's on:

See Signing In for what users see.

Blocking malicious IP addresses

When Block malicious IP addresses is selected, an IP address with 5 wrong passwords is blocked from signing in until 10 minutes after its first wrong password. This stops attackers from guessing passwords quickly. A blocked user sees Your IP address and/or login ID has been temporarily blocked due to too many failed login attempts, even if they then enter the right password.

Only IP addresses are blocked, not login IDs, so nobody can lock another user out of their account by typing wrong passwords for it. Users who share an IP address, for example behind the same office router, are blocked together, so tell users to use Forgot? instead of guessing. Administrators can see failed sign-in attempts in the Login Audit report. See Reports.

Independently of this setting, SyncriTab always refuses connections from known Tor exit nodes, and blocks addresses that send the kinds of web requests used to probe servers for weaknesses.

Limiting where each user can sign in

You can also restrict individual users to the server itself, your local network, or specific IP addresses. For example, you might allow administrators to sign in only from the office network. See Restricting sign-in by IP address.

Idle timeout

Session Time (minutes) sets how long a user can be idle before SyncriTab signs them out and closes their database connections. The default is 30 minutes; you can enter 5 to 1,440. A shorter time lowers the risk of someone using an unattended computer. A longer time is more convenient but keeps database connections open longer.

While a session is idle but hasn't timed out, SyncriTab keeps its database connections alive, so the database doesn't drop them first.

Password strength policy

By default SyncriTab accepts any non-empty password. To require stronger passwords, select Enforce password strength policy. Once that box is checked, every new or changed password must meet the rules you configure. Existing passwords are not affected: a user with a weak password that was set before the policy was turned on can still sign in, but the next time they change their password the new one must pass.

Configuring the rules

The following options appear when Enforce password strength policy is selected. Each one can be turned on or off independently:

SettingWhat it requires
Minimum lengthPassword must be at least this many characters. Enter any value from 1 to 128. The default is 8.
Uppercase letterAt least one uppercase letter (A–Z).
Lowercase letterAt least one lowercase letter (a–z).
DigitAt least one digit (0–9).
SymbolAt least one character that is not a letter or digit, such as !, @, #, $, or a space.

The policy applies everywhere a password is set or changed:

If a password doesn't meet the rules, SyncriTab shows a message describing which rule was violated and does not save the change.

Encrypting data at rest

SyncriTab saves some information on the server's disk, such as query results in saved sessions. That data can include anything your databases hold. When Encrypt sensitive data at rest is selected, SyncriTab encrypts these files, so they can't be read by someone who copies them from the disk, a backup, or a stolen drive.

How encryption at rest protects saved sessions, temporary query results, and query history, and which key is used.
How encryption at rest works.

What is encrypted

DataEncrypted
Saved sessions: query pages, SQL, and saved resultsYes
Temporary query results, while a query page is openYes
Query historyYes
Saved scripts and workbooks, Schema Diff reports, and files waiting to be downloadedOnly when the extended areas are also turned on
Files written by scheduled exportsNo. They're meant to be read by other programs. Protect their folder with file permissions or disk encryption.
SyncriTab's internal databaseNo, but passwords and other secrets in it are stored encrypted.
CertificatesProtected by their own passwords.

Encryption at rest doesn't protect data while it travels over the network; use HTTPS for that. See SSL Certificates.

Turning encryption on or off

Select or clear Encrypt sensitive data at rest and click Save. You can change it at any time, and nothing is lost:

The encryption key

The line below the check box shows which key is in use:

For the best protection, use your own key. Set the environment variable SYNAMETRICS_CUSTOM_KEY_PASSPHRASE to a long, random passphrase where the SyncriTab service can read it, then restart:

Back up your passphrase. SyncriTab keeps no copy of it, and there's no way to recover data encrypted with a lost passphrase. Store it somewhere safe, separate from the server and its backups.

Keep in mind:

Extended areas

Saved scripts and workbooks, Schema Diff reports, and files waiting to be downloaded can also be encrypted. This is off by default, because encrypted scripts can no longer be opened directly from the server's disk in other tools, such as WinSQL or a text editor. The line below the check box shows whether the extended areas are on. They take effect only while Encrypt sensitive data at rest is also selected. To turn them on, contact Synametrics support. See Getting Support.

Security checklist

  1. Turn on HTTPS with a trusted certificate, then select Enforce HTTPS. See SSL Certificates.
  2. Set up email, and enter the administrator's and sender's addresses.
  3. Give every user an MFA email address, then turn on Mandatory MFA.
  4. Select Block malicious IP addresses.
  5. Restrict administrators to trusted networks with IP restrictions.
  6. Set a Session Time that suits how your team works.
  7. Turn on Enforce password strength policy and set the rules your organization requires.
  8. Turn on encryption at rest with your own passphrase, and back the passphrase up.
  9. Give each person their own account with only the roles they need. See User Roles.
  10. Keep SyncriTab up to date. See Updating & Restarting.