Re: Native Informix Driver for Visual Basic.
Posted in 1998
On Tue, 05 May 1998 19:28:01 +0100, Allan Gould <allang@sco.com.no.spam> wrote: >Nils Myklebust wrote: > >> > [snip] >> > >> >P.S.: What do you think about the "new" CLI 2.8 which is released by >> >informix and now also includes Intersolv 3.0 drivers? Which one is better? >> >CLI or Intersolv? >> >> The only opinion I have on these products is that they are useless >> untill they at least solve the security issues. It's completely >> mindless to make such products available where there is no way to >> protect my database from free updates anywhere via tools like MS >> Access. > >To be fair, this would require a re-write of the ODBC standard as there is no >clear statement of security issues in the ODBC standard. Many ODBC driver >vendors do implement security (Yes, we do as do others), but they are above and >beyond the ODBC standard. I don't see a big need for rewriting the ODBC standard. As far as I know the drivers who do implement security still have a 100% compliant ODBC driver (excluding any bugs or lack of support of some feature). The standard itself defines the call level interface and the SQL that should be understood. I doubt one could call it a non conformance to the standard that a connection is refused or some statements allways fail (i.e. updates on a read only connection) in some cases due to an extra layer of security implemented by the vendor. (At least you would have to be a prety strange kind of person to worry about that :-) So the point is that the security is an extra add on product to the ODBC driver. May be a standardisation could have some benefit for such an extra product as well, but that's another issue. What I am saying is that an ODBC driver who doesn't have this add on isn't very usefull for us. I also say that it's dangerous for many others. I will even say that it's dangerous to the extent that there are some (hopefully not many) out there who doesn't fully realize the extent to which they put themselves in a dangerous situation by starting to use ODBC based applications with drivers without such security implemented. All this may one day fire back on the vendors. Now is the time to do something about it. ODBC has become realy popular and some of the same issues are appearing with JDBC. It's great that we at least have some vendors who do do something about important issues. Nils Myklebust NM Data AS Norway E-mail: Nils.Myklebust@nmdata.com FAQ at: http://www.iiug.org/techinfo/faq/faq_top.html (Now with ODBC info under "Third party products".)