Re: [HACKERS] Updated TODO list

Поиск
Список
Период
Сортировка
От Bruce Momjian
Тема Re: [HACKERS] Updated TODO list
Дата
Msg-id 199907141501.LAA22755@candle.pha.pa.us
обсуждение исходный текст
Ответ на Re: [HACKERS] Updated TODO list  ("Gene Sokolov" <hook@aktrad.ru>)
Список pgsql-hackers
> > Doing the random salt over the wire would still be a problem.
> 
> There is absolutely no technical problem with storing hashed passwords and
> still sending salted hash over the wire. It was recently discussed in detail
> in "Hashing passwords" thread in pgsql-hackers list.

But you are hashing it with a secret known by the database adminstrator,
and someone knows any password, like their own, can guess the secret by
looking at the hashed version, no?

--  Bruce Momjian                        |  http://www.op.net/~candle maillist@candle.pha.pa.us            |  (610)
853-3000+  If your life is a hard drive,     |  830 Blythe Avenue +  Christ can be your backup.        |  Drexel Hill,
Pennsylvania19026
 


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Michael Richards
Дата:
Сообщение: Re: [HACKERS] Counting bool flags in a complex query
Следующее
От: Bruce Momjian
Дата:
Сообщение: Re: [HACKERS] MAX Query length