SCRAM with channel binding downgrade attack - Mailing list pgsql-hackers

From Bruce Momjian
Subject SCRAM with channel binding downgrade attack
Date
Msg-id 20180517140525.GC546@momjian.us
Whole thread Raw
In response to Re: Postgres 11 release notes  (Magnus Hagander <magnus@hagander.net>)
Responses Re: SCRAM with channel binding downgrade attack
List pgsql-hackers
On Thu, May 17, 2018 at 03:38:36PM +0200, Magnus Hagander wrote:
>     What's the take of others?  Magnus, Stephen or Heikki perhaps (you've
>     been the most involved with SCRAM early talks)?
> 
> Saw it by luck. It would probably be better if it wasn't hidden deep in a
> thread about release notes.

Agreed.  The problem was so glaring that I assumed I was not
understanding it.  I have modified this email subject so users will
hopefully read back in this thread to see the details.

-- 
  Bruce Momjian  <bruce@momjian.us>        http://momjian.us
  EnterpriseDB                             http://enterprisedb.com

+ As you are, so once was I.  As I am, so you will be. +
+                      Ancient Roman grave inscription +


pgsql-hackers by date:

Previous
From: Robert Haas
Date:
Subject: Re: [PROPOSAL] Shared Ispell dictionaries
Next
From: Tom Lane
Date:
Subject: Re: lazy detoasting