Re: Rejecting weak passwords - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Rejecting weak passwords
Date
Msg-id 14583.1255536514@sss.pgh.pa.us
Whole thread Raw
In response to Re: Rejecting weak passwords  (Dave Page <dpage@pgadmin.org>)
Responses Re: Rejecting weak passwords
List pgsql-hackers
Dave Page <dpage@pgadmin.org> writes:
> You've twice asserted it's a reduction without providing any arguments
> to back that up.

You quoted two good arguments why it's insecure in your original
message, neither of which your proposed GUC does anything to protect
against; and you also admitted that there might be other leakage paths
we haven't thought of.  That seems to me to be more than sufficient
reason to not encourage people to go back to passing unencrypted
passwords around.
        regards, tom lane


pgsql-hackers by date:

Previous
From: Tom Lane
Date:
Subject: Re: [PATCH] Largeobject access controls
Next
From: Dave Page
Date:
Subject: Re: Rejecting weak passwords