Re: SCRAM with channel binding downgrade attack

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: SCRAM with channel binding downgrade attack
Дата
Msg-id 5586d6d1-7804-84da-a9ff-fdf6eaa7df75@2ndquadrant.com
обсуждение исходный текст
Ответ на Re: SCRAM with channel binding downgrade attack  (Michael Paquier <michael@paquier.xyz>)
Ответы Re: SCRAM with channel binding downgrade attack  (Heikki Linnakangas <hlinnaka@iki.fi>)
Список pgsql-hackers
Aren't we attacking this on the wrong level?  We are here attempting to
prevent a SCRAM-SHA-256-PLUS -> SCRAM-SHA-256 downgrade, but we are not
preventing a SCRAM-SHA-256-PLUS -> anything-else downgrade.

-- 
Peter Eisentraut              http://www.2ndQuadrant.com/
PostgreSQL Development, 24x7 Support, Remote DBA, Training & Services


В списке pgsql-hackers по дате отправления:

Предыдущее
От: "David G. Johnston"
Дата:
Сообщение: libpq compression
Следующее
От: Andrew Gierth
Дата:
Сообщение: Re: Why is fncollation in FunctionCallInfoData rather than fmgr_info?