Re: contrib: auth_delay module

Поиск
Список
Период
Сортировка
От Robert Haas
Тема Re: contrib: auth_delay module
Дата
Msg-id AANLkTinLoJSTNOpPUoOC1Q=dGRT7LRxv5gr1Xez1DAha@mail.gmail.com
обсуждение исходный текст
Ответ на Re: contrib: auth_delay module  (Jeff Janes <jeff.janes@gmail.com>)
Список pgsql-hackers
On Sun, Nov 28, 2010 at 7:10 PM, Jeff Janes <jeff.janes@gmail.com> wrote:
> Oh, I wasn't complaining.  I think that having max_connections be
> charged for the duration even if the socket is dropped is the only
> reasonable thing to do, and wanted to verify that it did happen.
> Otherwise the module wouldn't do a very good job at its purpose, the
> attacker would simply wait a few milliseconds and then assume it got
> the wrong password and kill the connection and start new one.

Good point.

> Preventing the brute force password attack by shunting it into a DOS
> attack instead seems reasonable.

OK.

--
Robert Haas
EnterpriseDB: http://www.enterprisedb.com
The Enterprise PostgreSQL Company


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Jeff Janes
Дата:
Сообщение: Re: contrib: auth_delay module
Следующее
От: Tom Lane
Дата:
Сообщение: Re: Report: Linux huge pages with Postgres