Re: Insufficient attention to security in contrib (mostly)

From: Josh Berkus <josh(at)agliodbs(dot)com>
To: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: Insufficient attention to security in contrib (mostly)
Date: 2007-08-28 05:32:36
Message-ID: 200708272232.36291.josh@agliodbs.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Tom,

> Now you can argue that approximate database size information simply
> isn't that useful to an attacker, and maybe that's true. But are
> we prepared to make a policy decision that we aren't going to try to
> protect such information at all?

But it's not making *no* attempt. This is a special case; it only applies
when a limited number of databases share the same tablespace. If the admin
is concerned about protecting private info about database size, then either
put the DBs in separate tablespaces, or make sure there's so many dbs in the
tablespace that no useful information can be derived.

Hmmm ... execept we're not requiring even permission on *one* DB in the
tablespace are we? That *is* an issue. How difficult would it be to require
that the requestor have CONNECT on at least one DB in the tablespace? Like
by requiring them to be connected to that DB, or to be the Superuser?

--
Josh Berkus
PostgreSQL @ Sun
San Francisco

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Tom Lane 2007-08-28 05:49:14 Re: Insufficient attention to security in contrib (mostly)
Previous Message Tom Lane 2007-08-28 03:31:00 Re: Problem with locks