Re: [Fwd: Bug#184566: security threat to postgresql

Поиск
Список
Период
Сортировка
От Tom Lane
Тема Re: [Fwd: Bug#184566: security threat to postgresql
Дата
Msg-id 15720.1048284003@sss.pgh.pa.us
обсуждение исходный текст
Ответ на Re: [Fwd: Bug#184566: security threat to postgresql  (Neil Conway <neilc@samurai.com>)
Список pgsql-hackers
Neil Conway <neilc@samurai.com> writes:
> On Fri, 2003-03-21 at 16:06, Oliver Elphick wrote:
>> Is this paranoia, or is it a valid security point.  Any comments,
>> please?

> A little from column A, a little from column B, IMHO.

Mostly column A, IMHO.  The presumption is that an attacker (a) knows
that program X contains an embedded password and (b) is able to control
the environment in which the program is executed.  Given that
combination I can think of hardly anything that would *not* be
vulnerable.  For one thing, setting up a man-in-the-middle situation
would be pretty easy.

I can't imagine any situation in which I'd recommend embedding a
password into a postgres client app anyway.
        regards, tom lane


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Tom Lane
Дата:
Сообщение: keys_are_unique optimization causes out-of-buffers failure
Следующее
От: Barry Lind
Дата:
Сообщение: Re: A bad behavior under autocommit off mode