Re: [HACKERS] Updated TODO list

From: Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
To: Bruce Momjian <maillist(at)candle(dot)pha(dot)pa(dot)us>
Cc: Gene Sokolov <hook(at)aktrad(dot)ru>, Jan Wieck <jwieck(at)debis(dot)com>, pgsql-hackers(at)postgreSQL(dot)org
Subject: Re: [HACKERS] Updated TODO list
Date: 1999-07-13 17:20:18
Message-ID: 23644.931886418@sss.pgh.pa.us
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers

Bruce Momjian <maillist(at)candle(dot)pha(dot)pa(dot)us> writes:
>> DB admin has no business knowing other's passwords. The current security
>> scheme is seriously flawed.

> But it is the db passwords, not the Unix passwords.

I think the original point was that some people use the same or related
passwords for psql as for their login password.

Nonetheless, since we have no equivalent of "passwd" that would let a
db user change his db password for himself, it's a little silly to
talk about hiding db passwords from the admin who puts them in.

If this is a concern, we'd need to add both encrypted storage of
passwords and a remote-password-change feature.

regards, tom lane

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Bruce Momjian 1999-07-13 18:05:47 Re: [HACKERS] Updated TODO list
Previous Message Bruce Momjian 1999-07-13 16:55:59 Re: [HACKERS] Updated TODO list