Re: read-only access
Posted in 2000
Hannes Visagie wrote: > > Yes Mark. This works fine but what if the user needs to access the DB with > ODBC because they use some MSoft product, but still needs to use > applications that runs on the application server {UNIX - Telnet}, full > access. > > The only secure way is to use OPENLINK ODBC drivers {Or some other type of > middleware product}. No use to give the user 2 logins, because he/she can > use the non secure one any time with ODBC. According to the research we > have done at the previous GSM telecom comp I worked for {Sure U know who I > am talking about}, the only ODBC driver that had security build in was > OPENLINK. This seems to be a major draw back of ODBC/JDBC drivers. Call me old fashioned, but I just can't get my mind round the concept of granting DIFFERENT privileges on the SAME object to the SAME user. x-| > I think I is a major draw back of the design of the ODBC layer. Passwords > can sniffed out on the net. Easiest thing to break in on a network. > Openlink has the option to encrypt data, but I am not sure of passwords. > But then they have the option to limit from were you allowed to connect. Sure, but who do you let loose on YOUR network? > Old saying, can U trust your employees ? That's a question, but you would have to, if you were giving them multiple privilege sets. ;-) > PS. Today cold in SA. Feels like the UK. PS. Today hot in UK. Feels like SA. :-) Cheers, -- Mark. +----------------------------------------------------------+-----------+ | Mark D. Stock mailto:mdstock@mydas.freeserve.co.uk |//////// /| | http://www.informix.com http://www.informixhandbook.com |///// / //| | http://www.iiug.org +-----------------------------------+//// / ///| | |What year 2000 bug? year 2000 bug? |/// / ////| | |year 2000 bug? year 2000 bug? year |// / /////| | |2000 bug? year 2000 bug? year 1900 |/ ////////| +----------------------+-----------------------------------+-----------+