Jeff (or any expert): Does hiding truly restrict scope, or just simply "hide" it. IOW, if the perpetrator knew the table name, could they then still get it?
Man, that's pretty scary, or pathetic, or I don't know what. That is amazing if you really can simply import anything you want from secure DBs ??!!!
Moreover, assuming hiding does the trick: how many times will designers remember to do that; and then, how much developer's pain results from obvious offshoots of using "hiding" on something you're developing with (e.g. having to unhide to do something, then rehide). Yuck - kind of like having to update a read only file. And this is all assuming that hiding indeed solves the safety issue!
Wow, this is astounding stuff, are you sure?!