Re: Rejecting weak passwords - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: Rejecting weak passwords
Date
Msg-id 1255952095.19430.30.camel@fsopti579.F-Secure.com
Whole thread Raw
In response to Re: Rejecting weak passwords  (Robert Haas <robertmhaas@gmail.com>)
Responses Re: Rejecting weak passwords
List pgsql-hackers
On Thu, 2009-10-15 at 13:19 -0400, Robert Haas wrote:
> But I don't understand why everyone is
> so worked up about having an *optional* *flag* to force plaintext
> instead of MD5.

It would be pretty bad usability.  Users would be faced with the choice:
you can have secure authentication or good passwords, but not both.
(For some values of "secure" and "good".)  I think most people would
want both.



pgsql-hackers by date:

Previous
From: Pavel Stehule
Date:
Subject: Re: Application name patch - v2
Next
From: Pavel Stehule
Date:
Subject: Re: Application name patch - v2