Re: ODBC and Security
Posted in 1996
> Harald.Ums@t-online.de (Harald Ums) writes: > > I think the whole thread moves in the wrong direction. > ODBC is no more a security hole than INET alone. > ODBC only makes the underlying problem more visible. > > Someone could just as well write a dbaccess-like utility for > windows solely based on INET - what then?? Yes, exactly. The problem is larger than ODBC. On Unix we have been able to rely on access rights to programs and controling what users can do that way. Most users never see Unix, and can only start selected programs from a menu. This is secure enough. We can however not give a normal user access to any program that can be used for direct update of the database. That would currently require a separate login where that user had only read access to every table. 2 logins is 1 to many. One big issue here is that there are no access rights on a PC. That's actually important for many PC users. (This is equally true on a Unix workstation by the way, at least if the user has his own root password.) Roles, as they are currently implemented doesn't help at all. The suggestion from someone here to "encrypt" the role name is no solution. Passwords on roles by itself also isn't very helpfull. We have to remember that the users have problems with a single password on one login account. If they have to remember multiple passwords all is lost. They will write them down. Also with current technology many users allready have multiple passwords (login to the PC network, the mail system, the Unix server+++). This situation allready is very bad, we can't make it even worse. There are single login systems available that may prove helpfull, but the whole technology isn't currently very supportive of such systems. I am currently looking into what Openlink has done with security in their ODBC drivers. From reading the information available at their web-site it looks very interesting. Their current problem is they can't stop others from installing another ODBC driver and gaining access outside their security system. As far as I can see Informix should however easily be able to do that. I will come back to this as I study the Openlink solution further. In the meantime I would appreciate hering from anybody about their experiences with Openlink. Also input from Openlink themselves would be helpful. May be we here have a solution that could be standardised? Nils.Myklebust@ccmail.telemax.no NM-data, Aasesvei 71, 1300 Sandvika, Norway My opinions are those of my company