Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]

From: Marko Kreen <marko(at)l-t(dot)ee>
To: Lamar Owen <lamar(dot)owen(at)wgcr(dot)org>
Cc: pgsql-hackers(at)postgresql(dot)org
Subject: Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]
Date: 2000-10-25 21:27:25
Message-ID: 20001025232725.A12278@l-t.ee
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

On Tue, Oct 24, 2000 at 10:25:14AM -0400, Lamar Owen wrote:
> I am forwarding this not to belittle MySQL, but to hopefully help in the
> development of our own encryption protocol for secure password
> authentication over the network.
>
> The point being is that if we offer the protocol to do it, we had better
> ensure its security, or someone WILL find the hole. Hopefully it will
> be people who want to help security and not exploit it.

Better not try to create it ourselves ;)

http://srp.stanford.edu/

It has even RFC's assigned to it. RFC2945, RFC2944
I put it into my TOLOOK list but have not found the time yet. :)

--
marko

In response to

Browse pgsql-hackers by date

  From Date Subject
Next Message Marko Kreen 2000-10-25 21:37:13 Re: [Fwd: [CORE SDI ADVISORY] MySQL weak authentication]
Previous Message Patrick Welche 2000-10-25 20:22:23 Re: failed runcheck