Re: Maximum password length - Mailing list pgsql-hackers

From Tom Lane
Subject Re: Maximum password length
Date
Msg-id 373.1539379370@sss.pgh.pa.us
Whole thread Raw
In response to Re: Maximum password length  (Isaac Morland <isaac.morland@gmail.com>)
List pgsql-hackers
Isaac Morland <isaac.morland@gmail.com> writes:
> On Fri, 12 Oct 2018 at 16:52, Stephen Frost <sfrost@snowman.net> wrote:
>> I'm also trying to figure out why it makes sense to support an 8k
>> password and if we've really tried seeing what happens if pg_authid gets
>> a toast table that's actually used for passwords...

> ...
> It's also obvious that past a certain point, longer passwords don't help
> anyway, because it's already enough to have a password that can't be
> guessed in, say, the expected duration of the Earth's existence using all
> the computing power currently available in the world.

And, of course, who is really going to type a password longer than a
couple dozen characters?  And get it right reliably, when they can't
see what they're typing?  But even if you assume the password is never
manually entered but just lives in somebody's .pgpass, it's pointless
to make it so long.  Then the attacker will just switch to brute-forcing
the user's login password, or whereever along the chain there actually
is a manually-entered password.

I concur that we might as well standardize on something in the range
of 64 to 100 characters.  1K is silly, even if somewhere there is a
spec that allows it.

            regards, tom lane


pgsql-hackers by date:

Previous
From: Stephen Frost
Date:
Subject: Re: Maximum password length
Next
From: Stephen Frost
Date:
Subject: Re: Maximum password length