Re: ODBC and Security
Posted in 1996
Nils, I agree with almost everything you mentioned in your post. Nils.Myklebust@ccmail.telemax.no wrote: > ... > A third problem, related to the suggestions that server based applications should > switch to one common "user" whoever loged in, is that we want to know exactly who > did what in the database. That becomes more difficult, if not impossible, under > this senario. Also it looks too much like a hackers solution in the face of > a problem that should have been solved better. > ... You've probably read my articles that suggest a single update user which would be hard coded along with the password into the application that is to modify data. I assume such a setup is what you are referring to above. I'm not sure why there is a problem in knowing "who did what in the database", because the application obviously knows who the user is even though the database server doesn't. In I4gl the real user can be put in a global variable. From the DBA viewpoint, he will see a bunch of connections with the same update user. However, he can determine who the real user is, if he really needs to, by his connection (tty). I can agree that this is not an elegant solution for the 21st century, but it does the trick, while an elegant solution simply doesn't exist. Someone else mentioned the Openlink ODBC driver which has security features built in, like restricting all ODBC programs except perhaps one, from modifying data. > ... > Using stored procedures for all database updates is *not* a workable solution. > The leagacy applications can't be changed to do that, and even if they could > it's to hard. > ... Agreed, although this may change as the stored procedure language develops and becomes more robust. This has the potential of being the most elegant solution, but will require major rethinking of how things are done. > ... > Using roles in the database may help, but what will hinder a user from setting > any role from say MS Access? > ... While roles have no associated password, they do nothing to increasing security, only in managing security. Note that there is a password column in the sysusers table where roles are stored, marked for future use. Thanks for your comments, and I'm glad more people have become aware of this problem. ---------------------------------------------------------------------- John H. Frantz Power-4gl: Extending Informix-4gl frantz@centrum.is http://www.strengur.is/~frantz/pow4gl.html