Re: Localhost vs. Unix Domain Sockets?

From: John R Pierce <pierce(at)hogranch(dot)com>
To: pgsql-general(at)postgresql(dot)org
Subject: Re: Localhost vs. Unix Domain Sockets?
Date: 2014-08-19 01:51:46
Message-ID: 53F2ADB2.40404@hogranch.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-general

On 8/18/2014 6:45 PM, Ken Tanzer wrote:
> Thanks. I'm not really worried about this particular vulnerability,
> just wondering about the more general idea that having db user name =
> os user could reduce your security, even if only slightly. Is it just
> as conceivable that a vulnerability could come along that was more
> exploitable only if the two names were _different_?

what I read on that vunerability, it was talking about dbuser == dbname,
not os user. and frankly, I didn't get their rationale for that.

--
john r pierce 37N 122W
somewhere on the middle of the left coast

In response to

Responses

Browse pgsql-general by date

  From Date Subject
Next Message Matt S 2014-08-19 01:58:44 Re: Localhost vs. Unix Domain Sockets?
Previous Message Ken Tanzer 2014-08-19 01:45:47 Re: Localhost vs. Unix Domain Sockets?