Re: ODBC & Client Access
Posted in 1996
Nils Myklebust wrote: > < Huge snip > > > This is exactly what OpenLink has allready done. They are using the > task list from Windows that can be manipulated by cleaver users, so > there are still holes, but it is prety good. This is good > Now they should of course talk to Micorosoft and make them put this > into the standard (in ODBC 3.0) as a requirement. The problem right > now is any user may install I-Net and an I-Net based ODBC driver on > their PC and bypass the security OpenLink provides. (I am talking to > people at Informix currently about this situation. May be they will > fix it one day.) < snip > I'd settle for keeping out tinkering but legitimate users. < snip > > problem. As long as users are using OpenLink you can still set up very > good security. However any user can now install any ODBC driver they > can get their hands on without you even knowing. But this is the problem > In this case the question of what kind of security you need arises. > For us the main problem isn't hackers that are out to destroy, but > users that do things they shouldn't and most often don't realy know > that they are doing something bad. I agree, this is the main issue to tackle. All sites have users :-( (life would be easier without them) but not all sites have external connections where the hackers are more (but not entirely) likely to come from. > > All in all the situation isn't as bleak as it seemed last time this > issue where up. Nice to know. I'm currently doing a security job. Things were much easier when all I had to do was develop applications (sigh). Ian