Re: Passwords in clear text in server log

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello,

 

Why was my message flagged via fraud detection? What do I need to do to prevent that so I can reply?

 

We have several email aliases at my work location: awilliams@xxxxxxxxxxx , awilliams@xxxxxxxxxxxxxx and awilliams@xxxxxxxxxxxxxxxxxxx – I believe my outlook client was reconfigured recently to use @teamdrg.com, but I have posted here before, but I think that was using @dresources.com

 

Thanks,

 

Alex

 

From: pgsql-admin-owner@xxxxxxxxxxxxxx [mailto:pgsql-admin-owner@xxxxxxxxxxxxxx] On Behalf Of Williams, Alex
Sent: Wednesday, October 11, 2017 4:18 PM
To: Tom Lane <tgl@xxxxxxxxxxxxx>; Ervin Weber <webervin@xxxxxxxxx>
Cc: Alvaro Herrera <alvherre@xxxxxxxxxxxxxx>; Don Seiler <don@xxxxxxxxx>; pgsql-admin <pgsql-admin@xxxxxxxxxxxxxx>
Subject: Re: Passwords in clear text in server log

 

This sender failed our fraud detection checks and may not be who they appear to be. Learn about spoofing

Feedback

"We have heard many times from people who don't have enough insight, or
enough debug support client-side, to know exactly what queries their
apps are issuing.  Disabling query logging would be a horrible setback
for debuggability of such apps.  How many times have you said "consult
the postmaster log to find out what's going on"?
"

 

I completely agree. There are many cases, not just edge cases, where this has been vital to isolate and resolve issues.


From: pgsql-admin-owner@xxxxxxxxxxxxxx <pgsql-admin-owner@xxxxxxxxxxxxxx> on behalf of Tom Lane <tgl@xxxxxxxxxxxxx>
Sent: Wednesday, October 11, 2017 4:01:10 PM
To: Ervin Weber
Cc: Alvaro Herrera; Don Seiler; pgsql-admin
Subject: Re: Passwords in clear text in server log

 

Ervin Weber <webervin@xxxxxxxxx> writes:
> Alvaro Herrera  wrote:
>> Actually, I do wonder why we log statements that fail to parse.  Surely
>> the client ought to know that it failed, but what is the value of
>> additionally storing the query in the server log?

> To debug clients who claim it is working on their end, but data does not change.

We have heard many times from people who don't have enough insight, or
enough debug support client-side, to know exactly what queries their
apps are issuing.  Disabling query logging would be a horrible setback
for debuggability of such apps.  How many times have you said "consult
the postmaster log to find out what's going on"?

                        regards, tom lane


--
Sent via pgsql-admin mailing list (pgsql-admin@xxxxxxxxxxxxxx)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-admin


[Index of Archives]     [KVM ARM]     [KVM ia64]     [KVM ppc]     [Virtualization Tools]     [Spice Development]     [Libvirt]     [Libvirt Users]     [Linux USB Devel]     [Linux Audio Users]     [Yosemite Questions]     [Linux Kernel]     [Linux SCSI]     [XFree86]

  Powered by Linux