-----Original Message-----
From: Pratt, Dave [mailto:DPratt@h...]
Sent: 23 August 2000 21:33
To: 'support@w...'
Subject: To Alex Homer, Dave Sussman, Brian Francis
... and all the other authors of Professional Active Server Pages 3.0.
In Chapter 10, you stated that the Connection and SQL parameters of the RDS
data control can be viewed by the user, and that this may be considered a
security hole.
Please note that by using RDS Customization Handlers (or "data handlers"),
these parameters can be stored in a secure file on the server and can be
totally invisible to the client application. This makes RDS an EXTREMELY
secure solution. For more information, you can access Microsoft's article
on this at http://www.microsoft.com/data/ado/rds/custhand.htm or you can
contact me.
I can assure you, it works very well.
David Pratt