Re: SECURITY - NewEra/ODBC
Posted in 1997
On 18 Jun 97 at 15:17, David Lapsley wrote: > Are we correct in saying that NewEra uses OBDC to access Informix > databases (via INET) ? NewEra can connect via Informix-Net _or_ ODBC. > If so how do we prevent users using other ODBC compliant products > such as MSQuery ( which comes with MSOffice) from accessing the > Informix ODBC data source directly and thus bypassing any > validation/integrity checks built into the NewEra application. Ha, ha. You've just seen the number one reason why I'm such a fan of client/server. You can't prevent users with other ODBC compliant products from accessing your data, _if_ you're running NewEra on ODBC. If you're using I-NET, then users can't (easily) bypass your security. BUT - having I-NET on your client brings them one step closer to installing their own ODBC drivers (which sometimes require I-NET) > Hopefully I have been mislead and NewEra calls INET directly !! As I said, it's either/or > One other question: Does INET encrypt passwords before passing them > over the network and if not should this be considered a security > risk. I-NET does not encrypt passwords AFAIK. But then, neither does telnet! :-) Unless you have a large network with lots of nosey and technically literate users, it's not generally a problem. However, as Nils Myklebust and many others have pointed out, the whole client/server security thing *sucks*. One final thought: OpenLink software ( http://www.openlinksw.com ) claim to have ODBC drivers that offer _some_ security enhancements. HTH. -- Ciao, Billy Nose to the ground and ear to the grindstone in: Kuwait