Re: WIP: SCRAM authentication - Mailing list pgsql-hackers

From Greg Stark
Subject Re: WIP: SCRAM authentication
Date
Msg-id CAM-w4HOm-kRnz7Fe9nnoOdeO6OQWti42GhTNcXO17uWRjE5Scw@mail.gmail.com
Whole thread Raw
In response to Re: WIP: SCRAM authentication  (Heikki Linnakangas <hlinnaka@iki.fi>)
List pgsql-hackers
On Sat, Aug 8, 2015 at 6:23 PM, Heikki Linnakangas <hlinnaka@iki.fi> wrote:
> Like Joe and Stephen, I actually find it highly confusing that we call the
> MD5 hash an "encrypted password". The term "password verifier" is fairly
> common in the specifications of authentication mechanisms. I think we should
> adopt it.

Speaking as someone who hasn't read the specifications I found
"password verifier" surprising. I would have known what "password
hash" was but I misread "verifier" to be something functional like a
PAM plugin. I tend to agree we should just use terminology out of the
specs though even if it's a little opaque, better one opaque piece of
terminology than having to learn and translate between multiple
terminologies.


-- 
greg



pgsql-hackers by date:

Previous
From: Bruce Momjian
Date:
Subject: Re: 9.5 release notes
Next
From: Bruce Momjian
Date:
Subject: Re: 9.5 release notes