Re: sha1, sha2 functions into core? - Mailing list pgsql-hackers

From Andrew Dunstan
Subject Re: sha1, sha2 functions into core?
Date
Msg-id 5032D289.4090103@dunslane.net
Whole thread Raw
In response to Re: sha1, sha2 functions into core?  (Tom Lane <tgl@sss.pgh.pa.us>)
Responses Re: sha1, sha2 functions into core?
List pgsql-hackers
On 08/20/2012 07:08 PM, Tom Lane wrote:


> Moreover, as Josh just mentioned, anybody who
> thinks it might be insufficiently secure for their purposes has got
> plenty of alternatives available today (SSL certificates, PAM backed
> by whatever-you-want, etc).
>

Yeah, I think we need to emphasize this lots more. Anyone who wants 
really secure authentication needs to be getting away from password 
based auth altogether. Another hash function will make very little 
difference.

cheers

andrew





pgsql-hackers by date:

Previous
From: Tatsuo Ishii
Date:
Subject: Re: Outdated Japanse developers FAQ
Next
From: "Kevin Grittner"
Date:
Subject: Re: temporal support patch