Re: Encryption in pg_dump

From: Stephen Frost <sfrost(at)snowman(dot)net>
To: Ron <ronljohnsonjr(at)gmail(dot)com>
Cc: pgsql-admin(at)lists(dot)postgresql(dot)org
Subject: Re: Encryption in pg_dump
Date: 2020-07-23 15:02:01
Message-ID: 20200723150201.GT12375@tamriel.snowman.net
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-admin

Greetings,

* Ron (ronljohnsonjr(at)gmail(dot)com) wrote:
> TDE, though, protects against hackers who break in and try to slurp out as
> much data as possible.  Still pretty unlikely, but within the realm of
> reason.

That's an unfortunate misconception- TDE won't help with that as the key
will be in the server's memory and therefore accessible to the attacker.

Certainly, if the server is doing the decryption and is compromised in
an online fashion, then the attacker is going to have access to that
data.

Thanks,

Stephen

In response to

Browse pgsql-admin by date

  From Date Subject
Next Message Rui DeSousa 2020-07-23 15:34:34 Re: Encryption in pg_dump
Previous Message Stephen Frost 2020-07-23 14:56:04 Re: Encryption in pg_dump