Re: No secrete to a root account holder under Informix
Posted in 2000
--- "Chen, Alex" <AChen@nvrinc.com> > wrote: >Unlike Oracle, Informix doesn't have its own user authentication security >scheme at the database level. >Unlike Unix either, Informix doesn't have data encryption tool to protect >data at the individual user level. >In other words, Informix potentially grants an unlimited database access >authority to the root user account, >because root can behave on behalf of any other users within the >Unix/Informix systems. The question is: >does root have to be a trustworthy user account? Normally it is a shared >Unix administrator account. >I couldn't agree that an organization should allow a group of Unix system >administrators to have the >unlimited access to the company sensitive data, such as payroll system data, >personnel system data, >or any other security data under the Informix-based application systems. >Wondering how FBI handles >this issue - no secrete to a root user account holder. I would imagine they hire trustworthy people.... How does this differ from an Oracle DBA having access to root privileges (as I've been told is the case by an Oracle DBA)? Should a DBA (or a group of individuals with DBA status) have unlimited access to the OS? There are probably more sysadmins that feel they need to protect their boxes from clueless DBA's than DBA's feeling they need to protect their data from clueless sysadmins (and the clueless are certainly represented in both camps). == "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next. _____________________________________________________________ Want a new web-based email account ? ---> http://www.firstlinux.net