Re: Salt in encrypted password in pg_shadow

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Greg Stark <gsstark(at)mit(dot)edu>
Cc: pgsql-general(at)postgresql(dot)org
Subject: Re: Salt in encrypted password in pg_shadow
Date: 2004-09-09 04:23:48
Message-ID: 727.1094703828@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

Greg Stark <gsstark(at)mit(dot)edu> writes:
> This means it's quite possible the NSA had differential cryptanalysis
> 30 years before anyone else.

s/quite possible/known fact/

> Quite a remarkable achievement. However
> it's unlikely that the same situation holds today.

Why would you think that? The US government may not have too many
clues, but they certainly understand the importance of crypto. I cannot
think of any reason to suppose that NSA et al would have stopped
spending serious effort in this area. (Where "serious effort" is
measured by the standard of "a billion here, a billion there, pretty
soon you're talking about real money".)

Quite honestly, as a US taxpayer I would not be happy if the NSA were
not far ahead of public research in this field ...

regards, tom lane

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Greg Stark 2004-09-09 04:40:34 Re: Salt in encrypted password in pg_shadow
Previous Message Greg Stark 2004-09-09 03:37:09 Re: Salt in encrypted password in pg_shadow