Re: PATCH: warn about, and deprecate, clear text passwords - Mailing list pgsql-hackers

From Greg Sabino Mullane
Subject Re: PATCH: warn about, and deprecate, clear text passwords
Date
Msg-id CAKAnmmLqM7ud31MWq2SZGn5WYodudJZSLp0kxwjnqqRewCVjGA@mail.gmail.com
Whole thread Raw
In response to Re: PATCH: warn about, and deprecate, clear text passwords  (Nathan Bossart <nathandbossart@gmail.com>)
Responses Re: PATCH: warn about, and deprecate, clear text passwords
Re: PATCH: warn about, and deprecate, clear text passwords
List pgsql-hackers
I'd rather not sit on this another year, if we can help it. We really should be warning people about this practice. The exact wording of the hint can be up for debate (or postponed - we technically don't have to say anything other than 'bad idea').

Having the ability to disable clear text passwords seems an immediate win for those that want to enable it. Sure, we could be doing more, but I don't see any of the proposed future changes interfering with this patch.

Cheers,
Greg

--
Enterprise Postgres Software Products & Tech Support

pgsql-hackers by date:

Previous
From: Hao Zhang
Date:
Subject: how to see the generated nodetags.h
Next
From: Florents Tselai
Date:
Subject: Re: encode/decode support for base64url