Re: Informix security
Posted in 1998
John Carlson wrote: [SNIP] > Read it. While it woould work under normal circumstances . . . > > We have a test system and a production system. 4GL developers have > command-line access to both systems, although rarely on the production > system. My understanding of roles is that the role would be embedded > into the 4gl program, thus preventing certain table access. > > The problem is that the same people who would add the role to the 4gl > would also have access to the role name. All that is needed would be a > DBACCESS session and . . . > [SNIP] You will always have that issue. Whoever knows root on a system will have access to anything. ( does su - informix mean anything? :-) The only way you could limit them is to reduce their access to the production system, and secure the production system. (Ie no .rhosts, and keep the development systems out of host.equiv) My point is that no matter what you do, you will always have someone who has total access to the data. Unless of course you want to encrypt the data before entering it in to the DB, then the programmers can get at the encrypted data, unless they know the key. (salts are usually the first two bytes if using crypt()) Now that's getting paranoid. And thats why they pay me the big bucks. ;-) -Mikey -- #include <std_disclaimer.h> /* Mike Segel (MS385) */ #include <No_Spam.h> #ifdef OFFENDED_BY_CONTENT The author takes no responsibility for this post. Any resemblence to a coherent rational thought is purely coincidence. -The Management. #endif ***************************** Due to AGIS's Refusal to Act Responsibly We are blocking all of their domains at the packet level. This block will exist until AGIS modifies their policies to conform to existing RFCs and net community standards. We encourage all ISPs and domain holders to do the same. *****************************