[Full-Disclosure] Gates: 'You don't need perfect code' for good security

Valdis.Kletnieks at vt.edu Valdis.Kletnieks at vt.edu
Tue Nov 4 14:22:44 GMT 2003


On Tue, 04 Nov 2003 06:03:40 EST, Geoincidents <geoincidents at getinfo.org>  said:

> Nonsense, you read to many MS papers <g>. Lots of ISP's run SQL servers on
> the internet for radius authentication, where the database and stored
> procedures are not exposed.

The SQL server doesn't have to be accessible to the Internet.  It only
has to be accessible to those machines authorized to do authentication
lookups.

There's reasons why 'best practices' call for a physically separate
management network....
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 226 bytes
Desc: not available
Url : http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20031104/aabddfef/attachment.bin 


Full-Disclosure is hosted and sponsored by Secunia.