Re: Black Hat: New database attack revealed
От | Dave Page |
---|---|
Тема | Re: Black Hat: New database attack revealed |
Дата | |
Msg-id | 46B1CDAA.8050902@postgresql.org обсуждение исходный текст |
Ответ на | Re: Black Hat: New database attack revealed (Peter Eisentraut <peter_e@gmx.net>) |
Ответы |
Re: Black Hat: New database attack revealed
Re: Black Hat: New database attack revealed |
Список | pgsql-advocacy |
Peter Eisentraut wrote: > Am Donnerstag, 2. August 2007 13:31 schrieb Robert Bernier: >> New timing attack doesn't need application bugs to work >> >> http://www.computerworlduk.com/management/security/cybercrime/news/index.cf >> m?RSS&newsid=4344 > > This is complete BS, as evidenced by this statement: > > """ > their attack involves performing record insertion operations, typically > available to all database users - including anonymous users of front-end web > applications - and analysing the time it takes to perform different kinds of > insertions. > """ > > In principle, attacks of this kind would be possible, but it's not quite as > simple as they make it appear. > That was roughly my thought as well. In our case, would it even be possible given WAL? Regards, Dave.
В списке pgsql-advocacy по дате отправления: