Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

Поиск
Список
Период
Сортировка
От Marko Kreen
Тема Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]
Дата
Msg-id 20001025233713.B12278@l-t.ee
обсуждение исходный текст
Ответ на Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]  (Bruce Guenter <bruceg@em.ca>)
Список pgsql-hackers
On Wed, Oct 25, 2000 at 10:27:15AM -0600, Bruce Guenter wrote:
> On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote:
> > I am forwarding this not to belittle MySQL, but to hopefully help in the
> > development of our own encryption protocol for secure password
> > authentication over the network.
> > 
> > The point being is that if we offer the protocol to do it, we had better
> > ensure its security, or someone WILL find the hole.  Hopefully it will
> > be people who want to help security and not exploit it.
> 
> IMO, anything short of a full SSL wrapped connection is fairly
> pointless.  What does it matter if the password is encrypted if
> sensitive query data flows in the clear?

Passwords are sensitive too.  They are actually orthogonal,
for data security we need something like SSL, but for
authentication/password security we need some strong authentication
scheme anyway.


-- 
marko



В списке pgsql-hackers по дате отправления:

Предыдущее
От: Marko Kreen
Дата:
Сообщение: Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]
Следующее
От: "andres mackiewicz"
Дата:
Сообщение: DBD::Pg::st execute failed: ERROR