Subject RE: [firebird-support] Re: SuperServer on Gentoo doesn't start any more
Author Brenden Walker
> -----Original Message-----
> From: firebird-support@yahoogroups.com
> [mailto:firebird-support@yahoogroups.com] On Behalf Of skoczian
> Sent: Monday, January 21, 2008 9:03 AM
> To: firebird-support@yahoogroups.com
> Subject: [firebird-support] Re: SuperServer on Gentoo doesn't
> start any more
>
> --- In firebird-support@yahoogroups.com, "Brenden Walker"
> <bkwalker@...> wrote:
> >
> >
> > I don't see this as being any more of a security risk that having
> the
> > FDB file on your HD. The firebird file in /etc/conf.d should be
> > readable by root only anyway. Easily compromised with local
> access (as
> > pretty much all machines are). If someone can get to your /etc
> > directory over the net, there's a bigger problem.
> >
> Quite right. But security2.fdb (that's what you mean, isn't
> it?) is at least encrypted. And, if I read the supplement to
> the firebird book correctly, better encrypted than ever.

Actually, your databases and all the data they contain is likely as easy
to obtain as a copy of the firebird configuration file in /etc/conf.d

Nobody would likely try to attack security2.fdb, other than replacing it
with their own (which would be noticed quickly if the databases are in
use).

> But I'm really out of my depth here. And if I think about the
> _present_ "security" of the data I'm just converting to
> Firebird, I'll stop this right now.

Basically if there is any physical access to your computer, nearly
anything can be compromised. If you want to secure your system, it's
going to take a lot of work and hassle. The bottom line, is the data
worth it.