Re: SSL cleanups/hostname verification - Mailing list pgsql-hackers

From Martijn van Oosterhout
Subject Re: SSL cleanups/hostname verification
Date
Msg-id 20081021154125.GC5062@svana.org
Whole thread Raw
In response to Re: SSL cleanups/hostname verification  (Peter Eisentraut <peter_e@gmx.net>)
List pgsql-hackers
On Tue, Oct 21, 2008 at 02:41:11PM +0300, Peter Eisentraut wrote:
> >Preventing casual snooping without preventing MitM is a rational choice
> >for system administrators.
>
> I am not an expert in these things, but it seems to me that someone who
> can casually snoop can also casually insert DHCP or DNS packages and
> redirect traffic.  There is probably a small niche where just encryption
> without server authentication prevents information leaks, but it is not
> clear to me where this niche is or how it can be defined, and I
> personally wouldn't encourage this sort of setup.

The example I know of is where there is a passive monitoring system
which monitors and logs all network traffic. In this case MitM is not
an issue because that's being monitored for. But avoiding the extra
duplication of confidential data is worth something.

It's not exactly a huge user group, but it exists.

Have a nice day,
--
Martijn van Oosterhout   <kleptog@svana.org>   http://svana.org/kleptog/
> Please line up in a tree and maintain the heap invariant while
> boarding. Thank you for flying nlogn airlines.

pgsql-hackers by date:

Previous
From: Gianni Ciolli
Date:
Subject: Bitmap Indexes: request for feedback
Next
From: David Fetter
Date:
Subject: Re: automatic parser generation for ecpg