为什么PostgreSQL默认将用户密码存储在MD5哈希中,这不是安全漏洞?(Why is it not a security hole that PostgreSQL by default stor

编程入门 行业动态 更新时间:2024-10-11 17:23:00
为什么PostgreSQL默认将用户密码存储在MD5哈希中,这不是安全漏洞?(Why is it not a security hole that PostgreSQL by default stores user passwords in an MD5 hash?)

为什么PostgreSQL默认将用户密码存储在MD5哈希中,这不是安全漏洞? 我正在研究PostgreSQL的内部并且已经到了系统catelog pg_authid ,当我读到有关MD5哈希加密时,它似乎被认为是过时的。 在我的想法中,如果管理员或用户能够访问底层文件存储,那么他们可能会假设破解密码并执行所述凭据将启用的任何内容。

我问为什么它不是一个安全漏洞,因为显然PostgreSQL已被“通用标准认证”,根据它的wiki,它注意到它来自西方国防组织,它似乎是军用级安全的。

谢谢!

Why is it not a security hole that PostgreSQL by default stores user passwords in an MD5 hash? I am studying the internals of PostgreSQL and have gotten to the system catelog pg_authid and when I read about the MD5 hash encryption it appears that it is regarded as antiquated. In my thinking if an admin or a user is able to access the underlying file store then they could hypothetically crack the passwords and do whatever said credentials would enable.

I ask why it is not a security hole because apparently PostgreSQL has been "Common Criteria Certified" which seems to be military grade secure according to it's wiki which notes it's provenance from western defense organizations.

Thanks!

更多推荐

本文发布于:2023-08-02 08:03:00,感谢您对本站的认可!
本文链接:https://www.elefans.com/category/jswz/34/1372723.html
版权声明:本站内容均来自互联网,仅供演示用,请勿用于商业和其他非法用途。如果侵犯了您的权益请与我们联系,我们将在24小时内删除。
本文标签:这不是   安全漏洞   用户密码   哈希中   PostgreSQL

发布评论

评论列表 (有 0 条评论)
草根站长

>www.elefans.com

编程频道|电子爱好者 - 技术资讯及电子产品介绍!