Re: postgresql.key secure storage

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Sam Mason <sam(at)samason(dot)me(dot)uk>
Cc: pgsql-general(at)postgresql(dot)org
Subject: Re: postgresql.key secure storage
Date: 2009-09-14 16:17:55
Message-ID: 17404.1252945075@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

Sam Mason <sam(at)samason(dot)me(dot)uk> writes:
> On Mon, Sep 14, 2009 at 05:45:14PM +0200, Saleem EDAH-TALLY wrote:
>> Le Monday 14 September 2009 16:13:45, vous avez crit :
>>> "Secure wallet" is an exercise in self-delusion.
>>
>> Not really. How can a user extract data from a container, by whatever
>> name we call it, if he does not have the key to open it ?

> Exactly the same way that libpq does--debuggers are powerful tools!

Or even easier, modify the source code of libpq to print out the data
after it's extracted it. Security in an open-source world requires
a different set of tools than security in a closed-source world.

regards, tom lane

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Cory Isaacson 2009-09-14 16:23:08 Re: Checkpoint request failed, permission denied
Previous Message Tom Lane 2009-09-14 16:09:48 Re: Checkpoint request failed, permission denied