Re: md5 again - Mailing list pgsql-hackers

From Tom Lane
Subject Re: md5 again
Date
Msg-id 1406.963334886@sss.pgh.pa.us
Whole thread Raw
In response to Re: md5 again  (Vince Vielhaber <vev@michvhf.com>)
List pgsql-hackers
Vince Vielhaber <vev@michvhf.com> writes:
> By knowing what PG will do with the username and random salt, sniffing 
> the wire can make guessing the password trivial.

Not if the wire protocol is done correctly, ie, passwords are only
sent in hashed form.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Vince Vielhaber
Date:
Subject: Re: md5 again
Next
From: Tom Lane
Date:
Subject: Re: md5 again