Re: AW: [HACKERS] Solution to the pg_user passwd problem !?? (c)

From: The Hermit Hacker <scrappy(at)hub(dot)org>
To: Tom I Helbekkmo <tih(at)Hamartun(dot)Priv(dot)NO>
Cc: Bruce Momjian <maillist(at)candle(dot)pha(dot)pa(dot)us>, Andreas(dot)Zeugswetter(at)telecom(dot)at, jwieck(at)debis(dot)com, pgsql-hackers(at)hub(dot)org
Subject: Re: AW: [HACKERS] Solution to the pg_user passwd problem !?? (c)
Date: 1998-02-19 23:08:39
Message-ID: Pine.BSF.3.96.980219190800.226W-100000@thelab.hub.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Thu, 19 Feb 1998, Tom I Helbekkmo wrote:

> [Marc]
>
> > I don't think so...but I'rather have the obviuos "select * from
> > pg_user" closed off, and the more obscure "copy pg_user to stdout" still
> > there then have both wide open...its a half measure, but its better then
> > no measure...
>
> [Bruce]
>
> > But it is not secure. Why have passwords then?
>
> [Marc]
>
> > passswords had to get in there at *some* point...they are there
> > now, now we have to extend the security to the next level. Better to move
> > forward 1 step at a time. If we remove the REVOKE altogether, the
> > passwords are still there, but there is *0* security instead of 50%
> > security...
>
> Wrong. It's still *0* security, but with the illusion of working
> security in the eyes of anyone who doesn't know better -- and you're
> trying to keep them from knowing better. If you go this way, cases
> *will* occur where people think their data secure, and then someone
> gains access to it who shouldn't. Security by obscurity never was,
> and never will be a good idea.
>
> Leave wide open looking wide open, and document it. Say something
> like "This release has a password field in the pg_user table, but it
> isn't actually useful as a security measure. It's there because we
> intend to use it in a secure manner in future. Meanwhile, a secure
> installation of the current version can be achieved by ...".

I concede the argument...you guys win...*groan*

Marc G. Fournier
Systems Administrator @ hub.org
primary: scrappy(at)hub(dot)org secondary: scrappy(at){freebsd|postgresql}.org

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Bruce Momjian 1998-02-19 23:23:08 Re: AW: [HACKERS] Solution to the pg_user passwd problem !?? (c)
Previous Message Phil Thompson 1998-02-19 22:47:59 Re: [HACKERS] Solution to the pg_user passwd problem !?? (c)