Re: Replay attack of query cancel

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: Replay attack of query cancel
Дата
Msg-id 17823.1218228313@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: Replay attack of query cancel  (Alvaro Herrera <alvherre@commandprompt.com>)
Ответы Re: Replay attack of query cancel  (Zdenek Kotala <Zdenek.Kotala@Sun.COM>)
Список pgsql-hackers
Alvaro Herrera <alvherre@commandprompt.com> writes:
> I wonder if we can do something diffie-hellman'ish, where we have a
> parameter exchanged in the initial SSL'ed handshake, which is later used
> to generate new cancel keys each time the previous one is used.

Seems like the risk of getting out of sync would outweigh any benefits.
Lose one cancel message in the network, you have no hope of getting any
more accepted.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: IN vs EXISTS equivalence
Следующее
От: Magnus Hagander
Дата:
Сообщение: Re: Replay attack of query cancel