Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

Поиск
Список
Период
Сортировка
От Bruce Guenter
Тема Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]
Дата
Msg-id 20001025102715.A19298@em.ca
обсуждение исходный текст
Ответ на [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]  (Lamar Owen <lamar.owen@wgcr.org>)
Ответы Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]  (Marko Kreen <marko@l-t.ee>)
Список pgsql-hackers
On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote:
> I am forwarding this not to belittle MySQL, but to hopefully help in the
> development of our own encryption protocol for secure password
> authentication over the network.
>
> The point being is that if we offer the protocol to do it, we had better
> ensure its security, or someone WILL find the hole.  Hopefully it will
> be people who want to help security and not exploit it.

IMO, anything short of a full SSL wrapped connection is fairly
pointless.  What does it matter if the password is encrypted if
sensitive query data flows in the clear?
--
Bruce Guenter <bruceg@em.ca>                       http://em.ca/~bruceg/

В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: Re: Re: [INTERFACES] RE: JDBC now needs updates for lar ge objects
Следующее
От: Larry Rosenman
Дата:
Сообщение: Re: --with-perl=/path/to/prefered/perl?