Subject | Re: [firebird-support] RE: Security issues? |
---|---|
Author | Mark Rotteveel |
Post date | 2013-12-19T09:24:16Z |
On 19 Dec 2013 01:01:11 -0800, <hvlad@...> wrote:
Jaybird implementation :)
Mark
> ---In firebird-support@{{emailDomain}}, <mark@...> wrote:not
>
> On 18 Dec 2013 13:14:07 -0800, <hvlad@... mailto:hvlad@...> wrote:
> >>> Besides the documented limitation that passwords are 8 characters
> >>> (Firebird 3 will lift that limitation), the connection protocol is
>>>> encrypted meaning that people can sniff the traffic and determine theby
> >>> password.
> >>
> >> Password is never passed over the wire in open form. It is encrypted
>>> client...that
>
> > Yes, but that is still susceptible to a replay attack, so the fact
> > itTrue, but as always, I am usually thinking from the perspective of the
> > is encrypted doesn't actually matter for someone with the will and
> > means,
>
> You said above that *password* could be determined by sniffer. This is
> not true and i said it.
> I said nothing more.
Jaybird implementation :)
Mark