<korryd@enterprisedb.com> writes:
> I think you could effectively disable the pgpass file (for a given
> application) if the application always requires an explicit, non-blank
> password from the user.
If he does that, his users who do not use password-based authentication
will be after him with the proverbial villagers' implements.
regards, tom lane