Oracle FAQ | Your Portal to the Oracle Knowledge Grid |
Home -> Community -> Mailing Lists -> Oracle-L -> RE: How to keep "root" out?
I have an idea
What do you think?
Sinardy
-----Original Message-----
Richard Ji
Sent: 31 August 2003 13:39
To: Multiple recipients of list ORACLE-L
A strange loop eh? You must have read GEB. :)
-----Original Message-----
From: Tim Gorman [mailto:tim_at_sagelogix.com] Sent: Sat 8/30/2003 12:49 AM To: Multiple recipients of list ORACLE-L Cc: Subject: Re: How to keep "root" out?
But if you encrypt it, where do you keep the key? How do you retrieve it for use? Donıt forget to follow the problem to the next step...
...and when you do, you realize that if nobody can be trusted, then the problem of security becomes an Escher print, or a Mobius strip, or the infinity symbol, or the exact value of ³pi²...
on 8/29/03 9:29 AM, Richard Ji at Richard.Ji_at_ztango.com wrote:
> We assume the SA don't know much about Oracle. But if some one is > particularly interested in > getting into the database, he might be on this list as well learning all our > defense mechanisms. :) > Or doesn't have to be subscribed to it since this list is mirrored other > places and google is his friend. > I think the bottom line is, if you absolutely don't want the data to be seen, > encrypt it. > > My 2 cents. > > Richard Ji
> Walt, > > Something that has not been suggested - migrate your database to 9.2. Connect > as internal goes away. > > Other than that, I think the best suggestion you got was a conversation, and > granting access to the v$ tables thru a specific account for that person. > > And then put a long trigger in place tracking all connections to the database. > Keep track of all SYS connections. At least you know when things happen. And > periodically review the init.ora file for the database to make sure that > nobody changes anything. > > Good Luck! > > Tom Mercadante > Oracle Certified Professional
-- Please see the official ORACLE-L FAQ: http://www.orafaq.net -- Author: Sinardy Xing INET: SinardyXing_at_bkgcomsvc.com Fat City Network Services -- 858-538-5051 http://www.fatcity.com San Diego, California -- Mailing list and web hosting services --------------------------------------------------------------------- To REMOVE yourself from this mailing list, send an E-Mail message to: ListGuru_at_fatcity.com (note EXACT spelling of 'ListGuru') and in the message BODY, include a line containing: UNSUB ORACLE-L (or the name of mailing list you want to be removed from). You may also send the HELP command for other information (like subscribing).Received on Mon Sep 01 2003 - 01:54:25 CDT