> Bruce Momjian <pgman(at)candle(dot)pha(dot)pa(dot)us> writes:
> > I will document the security problem with PGPASSWORD and add a TODO item
> > to remove it in 7.3. Is that OK with everyone?
> I don't think we should remove it. Documenting that using it is a
> security risk on some platforms seems a good idea, however.
OK, new text is:
sets the password used if the backend demands password
authentication. This is not recommended because the password can
be read by others using <command>ps -e</command>.
I am unsure if Linux has this problem but it seems most other Unix's do.
Bruce Momjian | http://candle.pha.pa.us
pgman(at)candle(dot)pha(dot)pa(dot)us | (610) 853-3000
+ If your life is a hard drive, | 830 Blythe Avenue
+ Christ can be your backup. | Drexel Hill, Pennsylvania 19026
In response to
pgsql-hackers by date
|Next:||From: Bruce Momjian||Date: 2001-11-28 20:13:55|
|Subject: Re: FW: [ppa-dev] Severe bug in debian - phppgadmin opens|
|Previous:||From: Tom Lane||Date: 2001-11-28 19:55:34|
|Subject: Re: FW: [ppa-dev] Severe bug in debian - phppgadmin opens |