Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vEsYq-002M3s-TK for pgsql-general@arkaria.postgresql.org; Fri, 31 Oct 2025 17:05:12 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1vEsYp-00GX7H-RH for pgsql-general@arkaria.postgresql.org; Fri, 31 Oct 2025 17:05:10 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1vEsYp-00GX79-GV for pgsql-general@lists.postgresql.org; Fri, 31 Oct 2025 17:05:10 +0000 Received: from smtp78.iad3a.emailsrvr.com ([173.203.187.78]) by makus.postgresql.org with smtp (Exim 4.96) (envelope-from ) id 1vEsYm-004lgU-1c for pgsql-general@postgresql.org; Fri, 31 Oct 2025 17:05:09 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=g001.emailsrvr.com; s=feedback; t=1761930307; bh=QRVTdZr1PnwHRGkTjnUWS6IUbOfh8nYAa6HVDOn48Nk=; h=Subject:From:Date:To:From; b=mBgSLCH6UvMUvU+ReHPyAzE1wmvrdJaNFi8Sd8kFRRNabkIjA+nJlaU735x4LCiia HZygFp5pAWlkn1xaOcTgImkJ9m0SSNbKnk1ZOzrlKgk9eTfRWfjMHKfkLh/adZh2vW j2klIb0TKB0qFigXSNvUbDjywvPk75YWk+15laV8= X-Auth-ID: xof@thebuild.com Received: by smtp10.relay.iad3a.emailsrvr.com (Authenticated sender: xof-AT-thebuild.com) with ESMTPSA id D3EDD6369; Fri, 31 Oct 2025 13:05:06 -0400 (EDT) Content-Type: text/plain; charset=us-ascii Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3776.700.51.11.4\)) Subject: Re: Enquiry about TDE with PgSQL From: Christophe Pettus In-Reply-To: Date: Fri, 31 Oct 2025 10:04:35 -0700 Cc: Bruce Momjian , Kai Wagner , Laurenz Albe , Ron Johnson , pgsql-general Content-Transfer-Encoding: quoted-printable Message-Id: References: To: Adrian Klaver X-Mailer: Apple Mail (2.3776.700.51.11.4) X-Classification-ID: 1a20c029-756b-4d8d-ba06-95975c0cf8c5-1-1 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk > On Oct 31, 2025, at 08:21, Adrian Klaver = wrote: > Yeah, what I would like to know is how many of the data breaches = actually grab directly from the storage versus getting it through the = database or other software above the storage? Essentially zero. PCI, like a lot of data security standards, are a magpie's assemblage of = things that the authors have heard about all of which sound "secure" to = them. However, since these particular magpies have machine guns = (metaphorically) and can do serious damage to businesses, we must play = along with the masquerade.=