Re: SCRAM with channel binding downgrade attack

From: Magnus Hagander <magnus(at)hagander(dot)net>
To: Peter Eisentraut <peter(dot)eisentraut(at)2ndquadrant(dot)com>
Cc: Michael Paquier <michael(at)paquier(dot)xyz>, Heikki Linnakangas <hlinnaka(at)iki(dot)fi>, Postgres hackers <pgsql-hackers(at)postgresql(dot)org>, Robert Haas <robertmhaas(at)gmail(dot)com>, Stephen Frost <sfrost(at)snowman(dot)net>, Bruce Momjian <bruce(at)momjian(dot)us>
Subject: Re: SCRAM with channel binding downgrade attack
Date: 2018-06-28 07:33:09
Message-ID: CABUevExMo5jNw1Jvw+t2dbMYg+dBY_=5o0m=OrmpT=MOhfyn7g@mail.gmail.com
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-hackers pgsql-www

On Wed, Jun 27, 2018 at 6:55 PM, Peter Eisentraut <
peter(dot)eisentraut(at)2ndquadrant(dot)com> wrote:

> On 6/14/18 13:43, Magnus Hagander wrote:
> > I still think that the fact that we are still discussing what is
> > basically the *basic concepts* of how this would be set up after we have
> > released beta1 is a clear sign that this should not go into 11.
>
> Other than some naming and handling of some nonsensical combinations,
> what is unclear?
>
>
Should there be one or more parameters? How should they interact? At which
level should they be controlled? Limited to SCRAM or other channel
bindings? Are the different levels of SCRAM to be considered different
protocols or the same protocol with a tweak? etc.

--
Magnus Hagander
Me: https://www.hagander.net/ <http://www.hagander.net/>
Work: https://www.redpill-linpro.com/ <http://www.redpill-linpro.com/>

In response to

Responses

Browse pgsql-hackers by date

  From Date Subject
Next Message Magnus Hagander 2018-06-28 07:35:57 Re: SCRAM with channel binding downgrade attack
Previous Message Masahiko Sawada 2018-06-28 07:20:53 Re: Changing the autovacuum launcher scheduling; oldest table first algorithm

Browse pgsql-www by date

  From Date Subject
Next Message Magnus Hagander 2018-06-28 07:35:57 Re: SCRAM with channel binding downgrade attack
Previous Message Alvaro Herrera 2018-06-27 17:24:15 Re: SCRAM with channel binding downgrade attack