Re: Security Question....
Posted in 2006
On 7/5/06, Tam OShanter <tam@oshanter.com> wrote: > Wondering on opinions regarding best practices for use of the public user in > IDS. > > Is there a compellign reason to allow the public user permissions to execute > DDL statements, or, in your opinion, should the public user be tightly > locked down and ddl administration restricted to specific users (an > application or administration account...)? PUBLIC should never be granted more than CONNECT permission to a database, the stores demo examples notwithstanding. That means they have no DDL privileges. Personally, I'd be cautious and consider only granting SELECT to PUBLIC on many tables; not allowing them the update DML operations restricts the damage they can do to leaking information. Those who need to modify the data can be given a role that allows them to make the changes. Those tables that should not be revealed can be left without public SELECT privilege. Note that roles can be regarded as a security-through-obscurity mechanism. I'm not advocating roles because it obscures the security; I'm advocating them because it is easier to set the privileges for a role (once, carefully) and then let authorized people use that role than to set the privileges for each separate user (carefully, many times over). Ditto for revoking the privileges later. -- Jonathan Leffler #include <disclaimer.h> Email: jleffler@earthlink.net, jleffler@us.ibm.com Guardian of DBD::Informix v2005.02 -- http://dbi.perl.org/