Re: FW: Security and the ODBC
Posted in 1997
In <5v3eq6$iiv@cssun.mathcs.emory.edu> Tkelly@svhs.org (Tim Kelly) writes: >Let me take another stab at this. I'm not suggesting you're totally >wrong, but you cannot create a View on every relationship that you want. >It isn't that way. I have a very complex database schema with 56 tables >and some of them with over 25 million rows. Views are inefficient and >CANNOT always be used. The point of the original question was not to be >taken literally as the only example. Just think of it in several >different situations. If you give a user an ODBC connection (using the >Informix CLI) there is no way to ensure they are coming from your >application and your application only. That's the question. [Big Snip] Sorry to come in late on this, but is it not an option to use SQL Retriever or OpenLink which allows ODBC access from selected applications/users/machines et al.? It would seem the simplest alternative, and both these products provide some measure of security at not a huge cost. From what you're saying in this post, the cost would be more than offset by the time taken to implement some of the measures you are discussing. -- Bryan Tonnet batonnet@phase4.com.au