Re: How to encrypt data in Postgresql - Mailing list pgsql-general

From Richard Welty
Subject Re: How to encrypt data in Postgresql
Date
Msg-id E19g31z-00041W-MV@skipper.averillpark.net
Whole thread Raw
In response to Re: How to encrypt data in Postgresql  ("Reuben D. Budiardja" <techlist@voyager.phys.utk.edu>)
List pgsql-general
On Fri, 25 Jul 2003 09:33:30 -0400 "Reuben D. Budiardja" <techlist@voyager.phys.utk.edu> wrote:

> I think if you encrypt MD5 before storing it into the table, then there
> is no
> way to retrieve the corresponding clear text right? since MD5 is one-way
> encryption..

yes, but normally when doing passwords, one encrypts and compares the
encrypted form. being able to decrypt stored passwords is generally
considered to be a "bad thing".

this goes back to the earliest days of Un*x, at the very least. i know it
was standard in V7, it probably was standard in V6, and likely was being
done that way even before then (V7 is where my Un*x experience starts.)

one of the raps on Windows NT & friends is that the password hashes are
easily reversable, which means that if you manage to steal them, you're
well positioned to take ownership of the system.

but this is kind of OT for a postgresql list now...

richard
--
Richard Welty                                         rwelty@averillpark.net
Averill Park Networking                                         518-573-7592
    Java, PHP, PostgreSQL, Unix, Linux, IP Network Engineering, Security

pgsql-general by date:

Previous
From: Ron Johnson
Date:
Subject: Re: Hardware selection
Next
From: Doug McNaught
Date:
Subject: Re: Solaris, Postgresql and Problems