Subject Re: [firebird-support] Re: Encrypted authentication
Author Alexandre Benson Smith
Anderson Farias wrote:
> --- Doug Chamberlin wrote:
>
>> Firebird and Interbase both encrypt passwords before sending them
>>
> across
>
>> the wire. Always have.
>>
>>
>
> Wow!! Thanks Doug, didnĀ“t know that!
>
> Regards,
>
>
>
>

It's converted at client side, but it's just easy to use a replay
techinique to fool FB engine.

It will be improved on future versions, but if you really care about
secutiry, and if your data cross public nets, I would go for using a
secure tunnel, the overhead is really minimal.

see you !

--
Alexandre Benson Smith
Development
THOR Software e Comercial Ltda
Santo Andre - Sao Paulo - Brazil
www.thorsoftware.com.br