Re: Password complexity/history - credcheck?

Поиск
Список
Период
Сортировка
От Greg Sabino Mullane
Тема Re: Password complexity/history - credcheck?
Дата
Msg-id CAKAnmmL7a20MKmjJuQZsrZPqCoSfdi5xpCtL4eqTxmcCKefC6Q@mail.gmail.com
обсуждение исходный текст
Ответ на Re: Password complexity/history - credcheck?  (Martin Goodson <kaemaril@googlemail.com>)
Ответы 2FA - - - was Re: Password complexity/history - credcheck?
Список pgsql-general
On Sun, Jun 23, 2024 at 5:30 AM Martin Goodson <kaemaril@googlemail.com> wrote:
I believe that our security team is getting most of this from our
auditors, who seem convinced that minimal complexity, password history
etc are the way to go despite the fact that, as you say, server-side
password checks can't really be implemented when the database receives a
hash rather than a clear text password and password minimal complexity
etc is not perhaps considered the gold standard it once was.

In fact, I think they see a hashed password as a disadvantage.

Wow, full stop right there. This is a hill to die on.

Push back and get some competent auditors. This should not be a DBAs problem. Your best bet is to use Kerberos, and throw the password requirements out of the database realm entirely.

Also, the discussion should be about 2FA, not password history/complexity.

Cheers,
Greg

В списке pgsql-general по дате отправления:

Предыдущее
От: Xu Haorong
Дата:
Сообщение: 回复: Stack Smashing Detected When Executing initdb
Следующее
От: Tom Lane
Дата:
Сообщение: Re: Stack Smashing Detected When Executing initdb