public inbox for [email protected]
help / color / mirror / Atom feedFrom: Ron Johnson <[email protected]>
To: pgsql-general <[email protected]>
Subject: Re: Enquiry about TDE with PgSQL
Date: Fri, 17 Oct 2025 08:47:40 -0400
Message-ID: <CANzqJaD=O-tsy7DWGTkT-mzyk_rQ6VrDGYTFYFY1oK65_n-hCA@mail.gmail.com> (raw)
In-Reply-To: <[email protected]>
References: <CACgMzfwSDRF+kQr59h0-xGUobCeFZxwVzE_tUxF18DkVb+vuDQ@mail.gmail.com>
<CAKAnmmKDCOdUT5JtJZz5papMO0zW1cnG4934d6aQVCQ_KdbUeg@mail.gmail.com>
<CANzqJaA41CzNjkiQex+A0u9z11i6R3WQZJ+fkXfJO7VJwOMWzg@mail.gmail.com>
<[email protected]>
On Fri, Oct 17, 2025 at 3:01 AM Laurenz Albe <[email protected]>
wrote:
> On Fri, 2025-10-17 at 00:49 -0400, Ron Johnson wrote:
> > On Thu, Oct 16, 2025 at 6:05 PM Greg Sabino Mullane <[email protected]>
> wrote:
> > >
> > > TDE, on the other hand, is a very complex and difficult thing to add
> into Postgres.
> >
> > TDE was added to SQL Server, with (to us, at least) minimally-noticed
> overhead.
> > Oracle has it, too, but I don't know the details.
> >
> > The bottom line is that requirements for TDE are escalating, whether you
> like it or
> > not, as Yet Another Layer Of Defense against hackers exfiltrating data,
> and then
> > threatening to leak it to the public.
>
> Bruce Momjian has interesting things to say about that in
> https://compiledconversations.com/6/ (unfortunately I don't remember where
> exactly in this 84 minute piece).
>
> It is a feature that users want (or need to comply with whatever they feel
> they have to comply with). On the other hand, it has very limited
> technical
> or security value, which hampers its acceptance into core.
>
I gave you a reason: "Yet Another Layer Of Defense against hackers
exfiltrating data". It's the same reason PgBackRest encrypts backups.
--
Death to <Redacted>, and butter sauce.
Don't boil me, I'm still alive.
<Redacted> lobster!
view thread (36+ messages) latest in thread
reply
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Reply to all the recipients using the --to and --cc options:
reply via email
To: [email protected]
Cc: [email protected]
Subject: Re: Enquiry about TDE with PgSQL
In-Reply-To: <CANzqJaD=O-tsy7DWGTkT-mzyk_rQ6VrDGYTFYFY1oK65_n-hCA@mail.gmail.com>
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox