Re: SCRAM with channel binding downgrade attack

From: Robert Haas <robertmhaas(at)gmail(dot)com>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Michael Paquier <michael(at)paquier(dot)xyz>, Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com>, Heikki Linnakangas <hlinnaka(at)iki(dot)fi>, Postgres hackers <pgsql-hackers(at)postgresql(dot)org>, Stephen Frost <sfrost(at)snowman(dot)net>, Bruce Momjian <bruce(at)momjian(dot)us>
Subject: Re: SCRAM with channel binding downgrade attack
Date: 2018-06-15 21:23:27
Message-ID: CA+Tgmoabj_L5a4o3R_EY7gum0tSYZ=7x3CBTjvWf5qnAuU8D-Q@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-www

On Thu, Jun 14, 2018 at 7:43 AM, Magnus Hagander <magnus(at)hagander(dot)net> wrote:
> I still think that the fact that we are still discussing what is basically
> the *basic concepts* of how this would be set up after we have released
> beta1 is a clear sign that this should not go into 11.

+1.

--
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Robert Haas 2018-06-15 21:36:10 Re: Making all nbtree entries unique by having heap TIDs participate in comparisons
Previous Message Alvaro Herrera 2018-06-15 20:23:28 Re: [HACKERS] Statement-level rollback

Browse pgsql-www by date

  From Date Subject
Next Message Darafei Komяpa Praliaskouski 2018-06-16 12:56:05 Re: Postgres 11 release notes
Previous Message Daniel Gustafsson 2018-06-15 08:40:36 Fix grouping headers in CF app