Re: Page-Level Encryption

From: Chris Browne <cbbrowne(at)acm(dot)org>
To: pgsql-general(at)postgresql(dot)org
Subject: Re: Page-Level Encryption
Date: 2006-01-20 22:23:59
Message-ID: 60bqy6pmgw.fsf@dba2.int.libertyrms.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

jd(at)commandprompt(dot)com ("Joshua D. Drake") writes:
>> IF they've got root, and the unencrypted data or the password / key is
>> on the machine or in memory on it, you've lost. It may make it harder
>> for them to get it, but they can.

> This is true but in answer to your question you can use something like
> cryptfs. Note that you will loose performance.

cryptfs doesn't forcibly help, because Someone Nefarious who has root
can connect to the box, and get access to the unencrypted mount point
that the postmaster is connected to.
--
let name="cbbrowne" and tld="acm.org" in String.concat "@" [name;tld];;
http://cbbrowne.com/info/spreadsheets.html
When you awake, you will remember nothing of what I have told you.

In response to

Browse pgsql-general by date

  From Date Subject
Next Message Ron 2006-01-20 22:29:46 Re: [GENERAL] Creation of tsearch2 index is very slow
Previous Message Steinar H. Gunderson 2006-01-20 22:16:55 Re: [GENERAL] Creation of tsearch2 index is very slow