Subject RE: [firebird-support] Security
Author Johannes Fourie
Well this is where my main problem lies, I developed a commercial application via Delphi/ FireBird for doctors offices, with all their clients information on it. In essence it is a young product with 17 clients at this stage. The application gets installed on the receptionests PC, and some of the doctors link to the central database via a COM interface.
There is not alot of data-movement, mostly client related queries. Most of the clients are not willing to purchase another PC for this application because they do not feel the need to add more overheads (which I personally feel is a little bit silly)

Thank you again for all the responses. the link "How to install Firebird on Windows 2003 Server and Windows XP" was much helpfull, and this could as well possibly be my answer on how to do it with minimal application changes. I just now have to figure it out per operating system what would be the best sollution for this scenario. What I am definately as well going to do is to add an encryption layer in the application, just before the database layer, for all the sensitive data.

Thank you
Johan Fourie
www.cq.co.za

-----Original Message-----
From: firebird-support@yahoogroups.com on behalf of Si Carter
Sent: Fri 12/2/2005 11:03 AM
To: firebird-support@yahoogroups.com
Cc:
Subject: RE: [firebird-support] Security





> -----Original Message-----
> A comment was made that you can just delete the security.fdb,
> and add your own security file?

The assumption I made there was that the user has access to the
security.fdb, there is a simple guide
(http://www.fbtalk.net/viewtopic.php?id=210) for setting up FB on Windows
Server/XP which includes details on setting permissions on folders, if it
helps.

> If I understand this comment correctly, Does this then mean
> that there is NO proper security on the Firebird database? I
> have a couple of clients with sensitive data in the Firebird
> database, and I gave them a couple of times the assurance
> that the information in the database is secure. But if it is
> this the case I lied then to the users.

This depends on where the server is and who has access to it.

Rgds

Si Carter
http://www.fbtalk.net/ - Web Based Firebird Forum
http://sourceforge.net/projects/fbutils - FBUtils
http://www.tectsoft.net/ - Homepage



------------------------ Yahoo! Groups Sponsor --------------------~-->
Most low income households are not online. Help bridge the digital divide today!
http://us.click.yahoo.com/I258zB/QnQLAA/TtwFAA/67folB/TM
--------------------------------------------------------------------~->

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Visit http://firebird.sourceforge.net and click the Resources item
on the main (top) menu. Try Knowledgebase and FAQ links !

Also search the knowledgebases at http://www.ibphoenix.com

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Yahoo! Groups Links