MD5 passwords - Mailing list pgsql-docs

From Andre Majorel
Subject MD5 passwords
Date
Msg-id 20100708104622.GA2132@aym.net2.nerim.net
Whole thread Raw
Responses Re: MD5 passwords  (Thom Brown <thombrown@gmail.com>)
List pgsql-docs
The doc says « if you are at all concerned about password
"sniffing" attacks then md5 is preferred. » but does not say why.
It would seem that an MD5 hash can be sniffed and replayed just as
well as a clear-text password.

Maybe the doc needs to explain why "md5" is more secure than
"password". Or, if it isn't, say so.

--
André Majorel http://www.teaser.fr/~amajorel/

pgsql-docs by date:

Previous
From: Satoshi Nagayasu
Date:
Subject: Re: ECPG Documentation Improvement
Next
From: Thom Brown
Date:
Subject: Re: MD5 passwords