From: Carl Youngblood Date: 2004-07-10T01:09:42+09:00 Subject: Re: Secure Database Systems Sorry, I should probably have given you more suggestions of where to look next: a) Write an password-based authentication system to keep unauthorized users from accessing data in the database b) Require your users to access your interface through SSL c) Some of the RDBMS systems you mentioned allow for replication over SSL (encrypted) connections, but you probably don't need a distributed database for the system you are talking about. One server will do just fine. d) http://www.bookpool.com/.x/ocyx4nms4m/sm/067232525X If you want a platform that is a little more tried and true for web development, I suggest PHP with MySQL or maybe even Sqlite for the backend database. I love Ruby. It is a lot more pure and pristine than PHP, but it is still doesn't provide a web development platform that is as comprehensive (batteries included) as PHP. You have to roll a lot more of your own code and understand web development more thoroughly to be able to do it in Ruby. Just my opinion. Carl On Fri, 9 Jul 2004 09:00:30 -0700, Carl Youngblood wrote: > Even though this is probably off-topic for a Ruby forum, you have > merely to learn how to use the RDBMS technologies you mentioned to > realize that they all provide security mechanisms that are sufficient > for what you want to do. > > > > On Fri, 9 Jul 2004 15:57:31 +0900, Sarah Tanembaum > wrote: > > I was wondering if it is possible to create a secure database system > > using RDBMS(MySQL, Oracle, SQL*Server, PostgreSQL etc) and web > > scripting/programming language(Perl, PHP, Ruby, Java, ASP, etc) combination? > > > > I have the following in mind: > > > > I wanted to store all my( and my brothers and sisters) important > > document > > information such as birth certificate, SSN, passport number, travel > > documents, insurance(car, home, etc) document, and other important > > documents > > imagined in the database. > > > > The data will be entered either manually and/or scanned(with OCR). I > > need to > > be able to search on all the fields in the database. > > > > We have 10 computers(5bros, 4sisters, and myself) plus 1 server with I > > maintained. The data should be synchronize/replicate between those > > computers. > > > > Well, so far it is easy, isn't it? > > > > Here's my question: > > > > a) How can I make sure that it secure so only authorized person can > > modify/add/delete the information? Beside transaction logs, are there > > any > > other method to trace any transaction(kind of paper trail)? > > > > Assuming there are 3 step process to one enter the info e.g: > > - One who enter the info (me) > > - One who verify the info(the owner of info) > > - One who verify and then commit the change! > > How can I implement such a process in RDBMS and/or PHP or any other web > > language? > > > > b) How can I make sure that no one can tap the info while we are > > entering > > the data in the computer? (our family are scattered within US and > > Canada) > > > > c) Is it possible to securely synchronize/replicate between our > > computers > > using VPN? Does RDBMS has this functionality by default? > > > > d) Other secure method that I have not yet mentioned. > > > > Anyone has good ideas on how to implement such a systems? > > > > Thanks