[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-Disclosure] Gates: 'You don't need perfect code' for good security



On Tue, 04 Nov 2003 06:03:40 EST, Geoincidents <geoincidents@getinfo.org>  said:

> Nonsense, you read to many MS papers <g>. Lots of ISP's run SQL servers on
> the internet for radius authentication, where the database and stored
> procedures are not exposed.

The SQL server doesn't have to be accessible to the Internet.  It only
has to be accessible to those machines authorized to do authentication
lookups.

There's reasons why 'best practices' call for a physically separate
management network....

Attachment: pgp00018.pgp
Description: PGP signature