Re: Password issue revisited

From: Shane Ambler <pgsql(at)007Marketing(dot)com>
To: Michael Schmidt <michaelmschmidt(at)msn(dot)com>
Cc: PostgreSQL General <pgsql-general(at)postgresql(dot)org>
Subject: Re: Password issue revisited
Date: 2007-01-28 14:02:03
Message-ID: 45BCACDB.5050702@007Marketing.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-docs pgsql-general

Michael Schmidt wrote:
> Fellow PostgreSQL fans,

> 1. I don't see that this would pose a major security risk. In
> fact, in applications where the user enters the password for each
> session, the password need never be saved to disk, which seems a
> definite security advantage. Some folks have noted that .pgpass is
> a plain text file, hence it could be vulnerable.

Yes it is a plain text file but if you want to use it then you need to
ensure the security is sufficient on the file or it won't be used.

As per the manual -

> The permissions on .pgpass must disallow any access to world or
group; > achieve this by the command chmod 0600 ~/.pgpass. If the
permissions
> are less strict than this, the file will be ignored. (The file
> permissions are not currently checked on Microsoft Windows, however.)

So this security feature should be something that gets added to the
windows version. But otherwise the security of the user's account that
has a .pgpass file is the decider on whether it is vulnerable.

--

Shane Ambler
pgSQL(at)007Marketing(dot)com

Get Sheeky @ http://Sheeky.Biz

In response to

Responses

Browse pgsql-docs by date

  From Date Subject
Next Message Michael Schmidt 2007-01-28 17:06:58 Re: Password issue revisited
Previous Message Bruce Momjian 2007-01-28 02:20:00 Re: Password issue revisited

Browse pgsql-general by date

  From Date Subject
Next Message Joris Dobbelsteen 2007-01-28 14:11:45 Re: counting query
Previous Message Shane Ambler 2007-01-28 13:39:35 Re: Predicted lifespan of different PostgreSQL branches