RE: Security WAS RE: [HACKERS] Updated TODO list - Mailing list pgsql-hackers

From Ansley, Michael
Subject RE: Security WAS RE: [HACKERS] Updated TODO list
Date
Msg-id 1BF7C7482189D211B03F00805F8527F70ED047@S-NATH-EXCH2
Whole thread Raw
In response to Security WAS RE: [HACKERS] Updated TODO list  ("Ansley, Michael" <Michael.Ansley@intec.co.za>)
List pgsql-hackers
I know that you can do both.  It seemed from previous postings, however,
that there was an issue about the urgency of each, if they are actually
separate issues.  I would have thought that the two are linked, and would be
solved as such.

MikeA


>> I have no idea where this misconception came from, but it's 
>> just plain
>> incorrect. You can do both - store hashes instead of 
>> plaintext passwords and
>> send logins securely over the network. Yes, the current 
>> authentication
>> scheme does not allow for it. But it just means that the 
>> scheme is outdated.
>> There are plenty of good secure solutions. It's just a 
>> matter of choosing
>> one.
>> 
>> Gene Sokolov.
>> 


pgsql-hackers by date:

Previous
From: Zeugswetter Andreas IZ5
Date:
Subject: AW: [HACKERS] RE: [GENERAL] Transaction logging
Next
From: Michael Richards
Date:
Subject: Re: [HACKERS] Counting bool flags in a complex query