Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

Поиск
Список
Период
Сортировка
От Lamar Owen
Тема Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]
Дата
Msg-id 39F71EC1.4E11F769@wgcr.org
обсуждение исходный текст
Ответ на [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]  (Lamar Owen <lamar.owen@wgcr.org>)
Список pgsql-hackers
Bruce Guenter wrote:
> On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote:
> > The point being is that if we offer the protocol to do it, we had better
> > ensure its security, or someone WILL find the hole.  Hopefully it will
> > be people who want to help security and not exploit it.
> IMO, anything short of a full SSL wrapped connection is fairly
> pointless.  What does it matter if the password is encrypted if
> sensitive query data flows in the clear?

I tend to agree.  SSL is a fully worked out means of doing secure
connections.  It is portable, it is robust, and it is relatively secure.
--
Lamar Owen
WGCR Internet Radio
1 Peter 4:11


В списке pgsql-hackers по дате отправления:

Предыдущее
От: Magnus Hagander
Дата:
Сообщение: RE: Re: [INTERFACES] RE: JDBC now needs updates for lar ge objects
Следующее
От: Tom Lane
Дата:
Сообщение: Re: length coerce for bpchar is broken since 7.0