Oracle FAQ | Your Portal to the Oracle Knowledge Grid |
Home -> Community -> Usenet -> c.d.o.server -> Re: add new user to oracle ??
On Sat, 31 Jan 2004 10:53:07 +0100, Thomas Kellerer
<spam_eater_at_gmx.net> wrote:
>Thanks for the detailed answer. Always learning something new...
>
>I use and maintain databases for development purposes only, and I do have
>to create views, procedures, database links, table, etc.
>
>So I gues my usage is OK :-)
Sorry to differ with you, the usual procedure the application ends up one on one in a production situation, with the identical abysmal privileges assigned to them by the developers, the developers stating the privileges can't be changed because otherwise the application won't work (Which is often of course not true, the real answer should be 'We don't know how to change it, and we don't know which privileges our application reallly needs)
We are maintaining an application *developed by Oracle Consulting*,
where all applications accounts don't have a real password (the
password is identical to the username) *and* the application account
have CONNECT, RESOURCE, DBA assigned.
Now do you think that database is secure?
-- Sybrand Bakker, Senior Oracle DBAReceived on Sat Jan 31 2004 - 06:52:04 CST