Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

From: Lamar Owen <lamar(dot)owen(at)wgcr(dot)org>
To: Bruce Guenter <bruceg(at)em(dot)ca>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]
Date: 2000-10-25 17:56:17
Message-ID: 39F71EC1.4E11F769@wgcr.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Bruce Guenter wrote:
> On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote:
> > The point being is that if we offer the protocol to do it, we had better
> > ensure its security, or someone WILL find the hole. Hopefully it will
> > be people who want to help security and not exploit it.

> IMO, anything short of a full SSL wrapped connection is fairly
> pointless. What does it matter if the password is encrypted if
> sensitive query data flows in the clear?

I tend to agree. SSL is a fully worked out means of doing secure
connections. It is portable, it is robust, and it is relatively secure.
--
Lamar Owen
WGCR Internet Radio
1 Peter 4:11

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Tom Lane 2000-10-25 18:04:38 Re: Unneccessary cmax in heap tuple ?
Previous Message Ross J. Reedstrom 2000-10-25 17:52:17 Re: failed runcheck