Re: ODBC and Security
Posted in 1996
Nils.Myklebust@ccmail.telemax.no wrote: > > bw000001@pixie.co.za ("Billy Wheeler") writes: > > It would have been nice if the ODBC standard had catered for such > > things. Unfortunately, M*cr*s*ft don't seem to think about real-world > > issues much - gets in the way of the bank balance... :) > > You should place the blame where the blame is due. > ODBC is coordinated with the Call Level Interface originally specified by > the SQL Access Group (I think they where called) and is now (or is soon to be) > an ANSI standard. Roger Sipple (the founder of Informix) where (and possibly is) > heavily involved in this work. Er. As I recall, ODBC belongs to Microsoft. Or have I missed something here? And (at a guess) I'd say that there's a lot of stuff that ODBC has that SQLA didn't specify and there's a lot of stuff SQLA specified that ODBC doesn't have. And a lot of other people were involved in SQLA, not just Roger Sippl. :) What I'm trying to say is, that I reckon the "blame" for this rests with the vendor of ODBC. Which to the best of my knowledge, is Microsoft. I'm sure that there *are* lots of things that SQLA didn't cover, just as I'm sure that there are things Microsoft didn't cover properly. But since Microsoft put forth the standard and define it and refine it (?), I reckon the responsibility for enhancing the standard lies with them. Any third party (such as Informix) who enhanced ODBC for any feature, be it security or whatever, would then be out of the standard. And the whole song and dance that we had in the early days of SQL will happen again. Not to mention the legal implications.... I am certainly not condoning the lack of rigorous and sensible security in ODBC, I'm just saying that *everyone* would have to do it the same way and the ODBC standard would obviously have to change as well, otherwise there would be no point. All IMHO, of course.