Re: Deprecating plans for PGPASSWORD environment variable as insecure

Поиск
Список
Период
Сортировка
От Khushboo Vashi
Тема Re: Deprecating plans for PGPASSWORD environment variable as insecure
Дата
Msg-id CAFOhELcZo6nDY2MErntD+_VCkzGz7vveieqKgniZ7BVrHBUFQA@mail.gmail.com
обсуждение исходный текст
Ответ на Deprecating plans for PGPASSWORD environment variable as insecure  (Alexey Murz Korepov <murznn@gmail.com>)
Список pgadmin-support
Hi,

This group is for pgAdmin4 related queries, you can send the postgres related queries to pgsql-general@postgresql.org 

Thanks,
Khushboo

On Mon, Dec 27, 2021 at 2:07 PM Alexey Murz Korepov <murznn@gmail.com> wrote:
MySQL in version have deprecated the `MYSQL_PWD` environment variable, because they considers this way as insecure, quote from https://dev.mysql.com/doc/refman/8.0/en/environment-variables.html#idm45429554761920:

>  Use of MYSQL_PWD to specify a MySQL password must be considered extremely insecure and should not be used. Some versions of ps include an option to display the environment of running processes. On some systems, if you set MYSQL_PWD, your password is exposed to any other user who runs ps. Even on systems without such a version of ps, it is unwise to assume that there are no other methods by which users can examine process environments.

So I want to ask - is there the same plan for PostgreSQL with it's `PGPASSWORD` environment variable for future versions, or will it stay as non-deprecated for future versions, and we can continue to use it without worrying?

--
Best regards,
Alexey Murz Korepov.
E-mail: murznn@gmail.com
Messengers: Matrix - https://matrix.to/#/@murz:ru-matrix.org Telegram - @MurzNN

В списке pgadmin-support по дате отправления:

Предыдущее
От: Alexey Murz Korepov
Дата:
Сообщение: Deprecating plans for PGPASSWORD environment variable as insecure
Следующее
От: Elvia Gomez
Дата:
Сообщение: Re: I cannot get PGAdmin to load the servers.