"Albe Laurenz" <laurenz.a...@wien.gv.at> writes: > I thought about it some more, and I think that a password checking > hook might still be somewhat useful even for MD5-encrypted passwords; > the function could guess and exclude at least that dreadful > all-too-frequent case of username = password.
True. You could probably even run through a moderate-size dictionary of weak passwords, depending on how long you're willing to make the user wait. (CHECK_FOR_INTERRUPTS inside the loop would be polite ;-)) regards, tom lane -- Sent via pgsql-hackers mailing list (pgsql-hackers@postgresql.org) To make changes to your subscription: http://www.postgresql.org/mailpref/pgsql-hackers