| From: | Merlin Moncure <mmoncure(at)gmail(dot)com> |
|---|---|
| To: | Hector Beyers <hqbeyers(at)gmail(dot)com> |
| Cc: | pgsql-general(at)postgresql(dot)org |
| Subject: | Re: Hiding data in postgresql |
| Date: | 2010-05-24 21:04:10 |
| Message-ID: | AANLkTikAp_8IQWi4po6Em5XVe3HxfiGBBnqMUKQKCqyb@mail.gmail.com |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-general pgsql-hackers |
On Mon, May 24, 2010 at 3:16 PM, Hector Beyers <hqbeyers(at)gmail(dot)com> wrote:
>
> Hi guys,
> does ANYONE have any tips on hiding data on a database server? This means
> that data is stored in places that is not necessarily picked up in the
> schema of the database. I am doing some research on databases and need some
> direction.
> Any help or direction will be highly appreciated.
First question: Have you considered 1. encrypting data when you put it
in the database and 2. decrypting it when you pull it out?
Let me humbly state that the #1 problem that beginners face with
security and encryption is focusing too much on the mechanics and not
enough on the 'big picture' issues:
*) What data is to remain secret?
*) Who is allowed to see the secret data?
*) When do they see it?
*) What sacrifices are you willing to make to keep the data secret?
*) Where are you going to store the key?
Answers to those questions should get you more helpful answers.
Postgres has a lot of features to hide data, some obvious (pgcrypto,
grant/revoke) and some not so obvious (revoking permissions from
pg_proc). Judging from your question you may be interested in some
extra-special techniques...please be more specific!
merlin
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Dennis Gearon | 2010-05-25 03:54:09 | timestamp configuration |
| Previous Message | Scott Marlowe | 2010-05-24 20:32:16 | Re: Hiding data in postgresql |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Robert Haas | 2010-05-24 21:18:21 | Re: unnailing shared relations (was Re: global temporary tables) |
| Previous Message | Scott Marlowe | 2010-05-24 20:32:16 | Re: Hiding data in postgresql |