Re: Encrypt data before inserting into DB
Posted in 1998
Boris wrote: > > If you encrypt payroll data it wouldn't be possible to write > queries like: select everybody with salary > xxx. So it's > probably better to use security mechanisms provided by SQL > Server. For example, remove SELECT rights to that column > from everybody (to provide better performance I'd rather > remove rights on whole table) and have people use views or > stored procedures instead. > > Boris Actually you can. Well sort of. Your payroll field would have to be a character datatype and the salt would have to be the same for all rows. Its not a good idea. You will want to have a random salt for encryption. But the bottom line is that if you are going to encrypt your data, be prepared for it to be cracked. I mean what, DES was broken in 2 hours or so. Even using roles and table permissions, the DBA will be able to see the data. That means you have to trust your System Administrator and your DBA. Hope you pay them well. -Mikey -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resembalence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** * Attention * -*- Due to AGIS's Refusal to Act Responsibly -*- Due to ACSI's latest actions, they have been pardoned. [E.Spire] We are blocking all of their domains at the packet level. This block will exist until they modify their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************