Re: ISV Using SQL Authentication - a login concern

From: Geoff N. Hiten (SRDBA_at_Careerbuilder.com)
Date: 05/26/04

  • Next message: Hari: "Re: Windows Authentication"
    Date: Wed, 26 May 2004 11:13:53 -0400
    
    

    Everyone sharing SA is not secure at all. Anyone can make changes and you
    cannot track down who did it. If the SA password gets hacked or leaked,
    then whoever has it really does own the database and has unlimited access
    and control. If you need to change it, you have to change all the systems.
    (think about a person leaving the organization). Not good at all.

    -- 
    Geoff N. Hiten
    Microsoft SQL Server MVP
    Senior Database Administrator
    Careerbuilder.com
    I support the Professional Association for SQL Server
    www.sqlpass.org
    "dev" <anonymous@discussions.microsoft.com> wrote in message
    news:BEEEFD7D-7EA8-4858-812E-E61C46C8C9A6@microsoft.com...
    > thanks Geoff, I appreciate your reply.  You said it is not very secure..
    do you mean from external attacks or internal user issues.. what kind of
    general problems I can expect to encounter.
    >
    > Thanks
    

  • Next message: Hari: "Re: Windows Authentication"

    Relevant Pages

    • Re: Active/Active/Active/Passive and Database Mirroring
      ... Senior Database Administrator ... Microsoft SQL Server MVP ... In the active/active/active/passive configuration is it possible to load ... "Geoff N. Hiten" wrote: ...
      (microsoft.public.sqlserver.clustering)
    • Re: Data Loss?
      ... Is the application using Windows Authentication or SQL Server logins? ... -- "Geoff N. Hiten" wrote in message ... I was able to when the deleting took place,> and the SPID of the user or computer it came from, but apparently SPIDs> change so whoever had that number on the day the deletions occurred has a> different SPID now. ... >> Senior Database Administrator ...
      (microsoft.public.sqlserver.server)
    • Re: Maintenance PLan recommendation
      ... I support the Professional Association for SQL Server ... > I can definitely confirm that what Geoff is stating is true. ... the SQL Service account must have FULL CONTROL ... >>>Senior Database Administrator ...
      (microsoft.public.sqlserver.server)
    • Re: Scenario
      ... limited budget, but you may need to point out to management that they will ... I support the Professional Association for SQL Server ... > "Geoff N. Hiten" wrote in message ... >> Senior Database Administrator ...
      (microsoft.public.sqlserver.clustering)
    • Re: Share Database with 2 SQL Servers.
      ... Why would you need more than 900 bytes in an index key? ... Senior Database Administrator ... I support the Professional Association for SQL Server ... > -0400, Geoff N. Hiten wrote: ...
      (microsoft.public.sqlserver.clustering)