Re: Native Informix Driver for Visual Basic.
Posted in 1998
In article <3550a32d.14503281@news.newmedia.no>, Nils Myklebust <Nils.Myklebust@nmdata.com> writes >On Tue, 05 May 1998 19:28:01 +0100, Allan Gould ><allang@sco.com.no.spam> wrote: > >>Nils Myklebust wrote: >> >>> > [snip] >>> >> >>> >P.S.: What do you think about the "new" CLI 2.8 which is released by >>> >informix and now also includes Intersolv 3.0 drivers? Which one is better? >>> >CLI or Intersolv? >>> >>> The only opinion I have on these products is that they are useless >>> untill they at least solve the security issues. It's completely >>> mindless to make such products available where there is no way to >>> protect my database from free updates anywhere via tools like MS >>> Access. >> >>To be fair, this would require a re-write of the ODBC standard as there is no >>clear statement of security issues in the ODBC standard. Many ODBC driver >>vendors do implement security (Yes, we do as do others), but they are above and >>beyond the ODBC standard. > >I don't see a big need for rewriting the ODBC standard. As far as I Security MUST always be implemented fromthe start, doing it as an add- on will always fail. Security must exist thoughout the design not as an afterthought. >know the drivers who do implement security still have a 100% compliant >ODBC driver (excluding any bugs or lack of support of some feature). >The standard itself defines the call level interface and the SQL that >should be understood. I doubt one could call it a non conformance to >the standard that a connection is refused or some statements allways >fail (i.e. updates on a read only connection) in some cases due to an >extra layer of security implemented by the vendor. (At least you would >have to be a prety strange kind of person to worry about that :-) > >So the point is that the security is an extra add on product to the >ODBC driver. May be a standardisation could have some benefit for such >an extra product as well, but that's another issue. What I am saying >is that an ODBC driver who doesn't have this add on isn't very usefull >for us. I also say that it's dangerous for many others. I will even >say that it's dangerous to the extent that there are some (hopefully >not many) out there who doesn't fully realize the extent to which they >put themselves in a dangerous situation by starting to use ODBC based >applications with drivers without such security implemented. All this >may one day fire back on the vendors. Now is the time to do something >about it. ODBC has become realy popular and some of the same issues Agreed and a new standard would give a standard way to address the problem and can be validated as secure ONCE not many times.. >are appearing with JDBC. > >It's great that we at least have some vendors who do do something >about important issues. > > >Nils Myklebust >NM Data AS >Norway >E-mail: Nils.Myklebust@nmdata.com >FAQ at: http://www.iiug.org/techinfo/faq/faq_top.html >(Now with ODBC info under "Third party products".) -- David Williams Maintainer of the Informix FAQ Primary site (Beta Version) http://www.smooth1.demon.co.uk Official site http://www.iiug.org/techinfo/faq/faq_top.html I see you standin', Standin' on your own, It's such a lonely place for you, For you to be If you need a shoulder, Or if you need a friend, I'll be here standing, Until the bitter end... So don't chastise me Or think I, I mean you harm... All I ever wanted Was for you To know that I care