Re: Password safe web application with postgre*s*

From: <ludwig(at)kni-online(dot)de>
To: <pgsql-general(at)postgresql(dot)org>
Subject: Re: Password safe web application with postgre*s*
Date: 2008-05-15 14:43:11
Message-ID: 17828909.280181210862591570.JavaMail.servlet@pustefix159.kundenserver.de
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

<span style="font-family: Verdana">In our web-based-solution (PHP)&nbsp; the database credentials (username and password) are encrypted and </span><span style="font-family: Verdana">stored </span><span style="font-family: Verdana">by PHP as session-Variables.<br /><br />Yes, there is the risk, they could be read by someone, who has access to the </span><span style="font-family: Verdana">apache-sessions-</span><span style="font-family: Verdana">directory, but this user also must have access to the php-scripts with the encrypt-functions to get the unencryption-keys and he must be able to work with these informations.<br /><br />But I think, this solution is much more save then storing or comitting the credentials as clear-text in cookies, hidden formular-elements or as sessions. <br />But
when you try to login to the database, somehow the credentials must be cleartext, so you can&#39;t get rid of this lack of security </span><span style="font-family: Verdana">in my opinion.<br /><br />By the way, this is an *intra*net-solution, and we don&#39;t have hackers in our staff, I hope...<br /><br />Ludwig<br type="_moz" /></span>

Attachment Content-Type Size
unknown_filename text/html 1.1 KB

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Justin 2008-05-15 14:45:36 Re: Need for help!
Previous Message Eliot, Christopher 2008-05-15 14:38:14 Re: Populating a sparse array piecemeal in plpgsql