Re: ODBC and Security
Posted in 1996
Billy Wheeler wrote: > > My understanding is that client/server architecture is *extremely* > vulnerable to basically any app (Lotus/Access/MS-Word :) with an ODBC driver > coming in and either acquiring or altering your data. I'd be very interested > to hear what experienced C/S developers do to minimise this risk. > -- Using an ODBC driver to an Informix database does not give you any greater access than with ESQL/C. The same user-level security is in place. The ODBC driver will still have to go through the connectivity software (ESQL/C and INET). They will still have to provide a username and password to login to the database. Whatever security you have implemented in the design of your database (user access to tables, permissions, views, etc.) are still in effect. If your database is designed with no security precautions (everyone logs in with the same user ID, all permissions are available to public, etc.) than that is what you get. Anyone accessing the database using any tool (whether via ODBC or not) will have full access to your tables.