From: | "Greg Sabino Mullane" <greg(at)turnstep(dot)com> |
---|---|
To: | pgsql-admin(at)postgresql(dot)org |
Subject: | Re: [ANNOUNCE] IMPORTANT: two new PostgreSQL security problems found |
Date: | 2005-05-04 23:44:18 |
Message-ID: | 18991d8228b39e43384ac760ebf5b84d@biglumber.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-admin pgsql-announce pgsql-general |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
> Considering that this is a security-related system catalog update, is
> there any way of providing some sort of signature for a message like
> this such that the community can feel that issuing some arcane commands
> as a superuser won't open a hole rather than close one?
An excellent point. Ideally someone (Tom) would be using GnuPG to sign
important messages like this with a digital signature. However, there are
a few checks one could do until that happens. One, compare his headers with
previous ones. Second, check the page at www.postgresql.org for a matching
announcement. Third, wait five minutes for the real Tom Lane to denounce any
fake email sent in his name. :)
If it makes you feel better, I'm 100% sure that was a legitimate email, and
I am going to sign this. :)
- --
Greg Sabino Mullane greg(at)turnstep(dot)com
PGP Key: 0x14964AC8 200505040739
http://biglumber.com/x/web?pk=2529DF6AB8F79407E94445B4BC9B906714964AC8
-----BEGIN PGP SIGNATURE-----
iD8DBQFCeLTwvJuQZxSWSsgRAtACAKDvyylXy1MliqSs8Jsoz7XicXmBagCgoprg
qKPTIVv55E3ne19OGvtOTHM=
=IFvp
-----END PGP SIGNATURE-----
From | Date | Subject | |
---|---|---|---|
Next Message | Gourish Singbal | 2005-05-05 12:22:56 | Need help in data migration |
Previous Message | Tom Lane | 2005-05-04 21:14:35 | Re: Anything like varchar_pattern_ops in 7.3.x? |
From | Date | Subject | |
---|---|---|---|
Next Message | David Fetter | 2005-05-09 07:11:04 | == PostgreSQL Weekly News - May 08 2005 == |
Previous Message | Jeff - | 2005-05-04 14:28:19 | Re: [ANNOUNCE] pgtop, display PostgreSQL processes in `top' style |
From | Date | Subject | |
---|---|---|---|
Next Message | Vlad | 2005-05-05 00:49:59 | postgresql replication |
Previous Message | Tom Lane | 2005-05-04 23:27:38 | Re: [INTERFACES] calculated identity field in views, |