Re: plpgsql by default - Mailing list pgsql-hackers

From Andreas Pflug
Subject Re: plpgsql by default
Date
Msg-id 443D0E8E.9080701@pse-consulting.de
Whole thread Raw
In response to Re: plpgsql by default  ("Dave Page" <dpage@vale-housing.co.uk>)
List pgsql-hackers
Dave Page wrote:
>  

> 
> Keeping PostgreSQL as secure as possible out of the box pretty much
> requires us to do the same in my mind - if an major feature such as
> pl/pgsql is easy for the user to enable should they want it, then it
> should be disabled by default to minimise the number of attack vectors
> for all those users that do not want it.

I wonder if Oracle ever recommended disabling PL/SQL (not to mention MS 
Transact-SQL)...

Regards,
Andreas


pgsql-hackers by date:

Previous
From: Richard Huxton
Date:
Subject: Re: Get explain output of postgresql in Tables
Next
From: "Bort, Paul"
Date:
Subject: Re: plpgsql by default