Re: Docs: Encourage strong server verification with SCRAM

Поиск
Список
Период
Сортировка
От Daniel Gustafsson
Тема Re: Docs: Encourage strong server verification with SCRAM
Дата
Msg-id 69EC75B8-3A75-43D9-9A2A-61BF6571247B@yesql.se
обсуждение исходный текст
Ответ на Re: Docs: Encourage strong server verification with SCRAM  (Stephen Frost <sfrost@snowman.net>)
Ответы Re: Docs: Encourage strong server verification with SCRAM  (Jacob Champion <jchampion@timescale.com>)
Список pgsql-hackers
> On 23 May 2023, at 23:02, Stephen Frost <sfrost@snowman.net> wrote:
> * Jacob Champion (jchampion@timescale.com) wrote:

>> - low iteration counts accepted by the client make it easier than it
>> probably should be for a MITM to brute-force passwords (note that
>> PG16's scram_iterations GUC, being server-side, does not mitigate
>> this)
>
> This would be good to improve on.

The mechanics of this are quite straighforward, the problem IMHO lies in how to
inform and educate users what a reasonable iteration count is, not to mention
what an iteration count is in the first place.

> Perhaps more succinctly- maybe we should be making adjustments to the
> current language instead of just adding a new paragraph.

+1

--
Daniel Gustafsson




В списке pgsql-hackers по дате отправления:

Предыдущее
От: "Drouvot, Bertrand"
Дата:
Сообщение: Re: pgsql: TAP test for logical decoding on standby
Следующее
От: Robert Haas
Дата:
Сообщение: Re: Atomic ops for unlogged LSN