Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sojlj-00DSJN-TC for pgsql-general@arkaria.postgresql.org; Thu, 12 Sep 2024 13:21:57 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.94.2) (envelope-from ) id 1sojlj-0086Hh-JO for pgsql-general@arkaria.postgresql.org; Thu, 12 Sep 2024 13:21:55 +0000 Received: from magus.postgresql.org ([2a02:c0:301:0:ffff::29]) by malur.postgresql.org with utf8esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sojli-0086HZ-WA for pgsql-general@lists.postgresql.org; Thu, 12 Sep 2024 13:21:55 +0000 Received: from outbound.visena.net ([46.226.12.34]) by magus.postgresql.org with utf8esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from ) id 1sojlf-000p2k-3g for pgsql-general@lists.postgresql.org; Thu, 12 Sep 2024 13:21:54 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=visena.com; s=20141101.wh; h=Content-Type:MIME-Version:Subject:References:In-Reply-To: Message-ID:Cc:To:From:Date:Sender:Reply-To:Content-Transfer-Encoding: Content-ID:Content-Description; bh=G90h71Wyhu7REiS+lahQg/IQy7buwBRV6SA66F2ELBA=; b=No4NXhPpnEh1HqHwzgMysbmLex p3Z2VyX2lcvlTKZ72dd1fDOwcr0hkD/7+RMcKLKCvbgIiidHRoZf5/2Hij4kYCAGyCcg14ATbMz/y 7cTjerfLqJ9cu22zJap+Sc9O+u6F7xFbX3XPcJUWguBEJtgiZQLM9Hk/w6j4Pp9FqW9U=; Received: from batch01.services.internal.visena.net ([10.3.0.103]) by outbound.visena.net with utf8esmtp (Exim 4.93) (envelope-from ) id 1sojld-002TTc-Og; Thu, 12 Sep 2024 15:21:49 +0200 Date: Thu, 12 Sep 2024 15:21:49 +0200 (CEST) From: Andreas Joseph Krogh To: Greg Sabino Mullane Cc: Tom Lane , pgsql-general@lists.postgresql.org Message-ID: In-Reply-To: References: <3952715.1726115805@sss.pgh.pa.us> Subject: Re: Effects of REVOKE SELECT ON ALL TABLES IN SCHEMA pg_catalog FROM PUBLIC MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_63884_1534057763.1726147309672" X-Mailer: Visena Mail 3.2.747 List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk ------=_Part_63884_1534057763.1726147309672 Content-Type: multipart/related; boundary="----=_Part_63885_1027392967.1726147309672" ------=_Part_63885_1027392967.1726147309672 Content-Type: multipart/alternative; boundary="----=_Part_63886_1137625315.1726147309695" ------=_Part_63886_1137625315.1726147309695 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable P=C3=A5 torsdag 12. september 2024 kl. 15:05:48, skrev Greg Sabino Mullane = < htamfids@gmail.com >: On Thu, Sep 12, 2024 at 12:52=E2=80=AFAM Andreas Joseph Krogh > wrote: I know PG is not designed for this, but I have this requirement nonetheless= =E2=80=A6 I think preventing =E2=80=9Cmost users and tools" from seeing/presenting th= is=20 information is =E2=80=9Cgood enough=E2=80=9D. As pointed out, there are very many workarounds. This is security theater. Yes, it is theater, but that doesn't prevent =E2=80=9Ccompliance people=E2= =80=9D to care about=20 it. We have to take measures to prevent =E2=80=9Cinformation leaks=E2=80=9D= . -- Andreas Joseph Krogh CTO / Partner - Visena AS Mobile: +47 909 56 963 andreas@visena.com www.visena.com ------=_Part_63886_1137625315.1726147309695 Content-Type: text/html;charset=UTF-8 Content-Transfer-Encoding: quoted-printable
= P=C3=A5 torsdag 12. september 2024 kl. 15:05:48, skrev Greg Sabino Mullane = <htamfids@gmail.com>:
=
On Thu, Se= p 12, 2024 at 12:52=E2=80=AFAM Andreas Joseph Krogh <andreas@visena.com> wrote:
I know PG= is not designed for this, but I have this requirement nonetheless=E2=80=A6=
I think preventing =E2=80=9Cmost users and tools" from seei= ng/presenting this information is =E2=80=9Cgood enough=E2=80=9D.
=C2=A0<= /div>
=C2=A0
=C2=A0
As pointed out, th= ere are very many workarounds. This is security theater.
<= /blockquote>

=C2=A0

Y= es, it is theater, but that doesn't prevent =E2=80=9Ccompliance peop= le=E2=80=9D to care about it. We have to take measures to prevent =E2=80=9C= information leaks=E2=80=9D.

=C2=A0

=
--
<= strong>Andreas Joseph Krogh
CTO / Partner - Visena AS
Mobile: +47 909 = 56 963
=
=C2=A0
------=_Part_63886_1137625315.1726147309695-- ------=_Part_63885_1027392967.1726147309672 Content-Type: image/png Content-Transfer-Encoding: base64 Content-Disposition: inline Content-ID: iVBORw0KGgoAAAANSUhEUgAAAIUAAAAYCAYAAADUIj6hAAAABHNCSVQICAgIfAhkiAAABzBJREFU aEPtmNFxHDcMhmVP3i1VECpvnjzkVIHWFfhcgVcVRKrAUgWRK/C6Al8H3lTgy0PGbzFdQc4VJP/H ADs43q6kROeJNbOYgQACIAgCWJKng4MZ5gxUGXh0U0b+SIuF9G+EWXj2Q15vbrE/NPtk9uub7Gfd t5mBx1NhqSEo8HshjbEUtlO2yIM9tsx5dZP9rPt2MzDZFAqZE4LGcFjdsg3saQaHt7fY70X949On aS+OZidDBkavD33157L4xaw2os+Mp/DAC10l2XhOCeStj0W5ajrJL8WfCi80Xgf9vVlrhg9yRONe /f7xI2vNsIcM7JwU9o6oGyJrLT8JOA1aX9sKP4wl94bAniukEbo/n7YPmuTETzIab4Y9ZWCrKexd 8M58lxPCvvD6aihfvexbEQoPYO8NQRO0JnddGO6FJYaVsBde7cXj7KRk4LsqDxQzCYeGsJNgaXZe +JXkyGgWINq3Gp+bHNILz+wEYs5qH1eJrouNrpDXtk4O6x1IvtD40GWyJYYdkF0jIbYZlN16xygI gl9smbMDsmFdfAKb23xGB8H/mv3tOJfArs1kukk79DEPdQ5u0g1vCvvqKXIW8mZYW+F3Tg4r8HvZ kQCCLydK8EFMQCe5N8RgL9mRG0SqQFuNvdE6beSs0qPDBuCdg0+gvClso8SbTO4ki7mQzQqBrcMH QPwReg2wW8umEe/+L8T/LEzBGF9nXjzZ46s+ITHvhegW8LL39xm6App7KYL/GE+vcYnFbJiP/0aY hdiCnRC7jaj7eiK2ETInC5PRF6LYkSN0+HabF75WuT6syCyI0YkVGGMvUC33AmfZTDUEj8u6IVhu EhRUJ2U2g6UlugyNb03Hl9obHwlxJbcRzcYjO4QPjVfGFTQav4vrmp7cpMp2qbHnBxWJbisbho2Q XI6C1sIHDUFhH4Hij4UbIev66eANeiwbkA+LBsO36zAHzoXU7AhbqLAXEiOYTXcSdO8VS9L4wN8U BIYhBd6oSUgYMijOkecRuTdQa/YiBXhbXFcnCnI2SrfeBG9NydrLYMhGHa5qB9pQIxlzAE6Okjzx JO5afGe6kmhBicWKQNKuTZ5EW+MjQY8v/9rQ0bhJSJyNGUe/JH1t8h1iMbdSPAvxHYin6YmN9YBX QmTYZZNh14vHhhhal5vtcIrJjmvszPRJdExH3MWHvykoBEc9CoCGWJisOLOGoCORs1FvIMbYA8z3 kwM59oemy6LlWrLxFLmWgiQAfEGd8S+NssbK+EhyGLxUkhhiy717waBqHOJYSEacwBejkFNhjJNj v/gANOdQxPfciP/JVBCK2cOIcg3RRJ+CPrLPNVhhN6F38VKMF3XLlIJrjU5C8gMFxvKDvOcPc4rV NjCn7KM0BV+161V8viSCuJZ8SITGJGEh7IUUlxOFMYUH1kJOCN4Wh+I5pqCuK01k40kSNtnKiKIl UfxAgW5sU5JlS05rtt5YFJF1SWoqHv6BRgQcA4/bdb9WRjmMk3jyUMAbIoyJq9e4cVmgzKt9j5gN J/aYDhk+hhjExwaPcz5PObA5Zd9bvz5UzCTZuZDidu5AchpiKSwPR+TV1bCWqBQ9nCjJ5neivC82 Nr4LeS2j1gw5LUqwBuhGQQU5UwHeSslXkwIynz2U2A2yKDgG7OffwLA3TpGRpk0Tzpj3ZEJXi/GR a6GN0e0NtppChePdcAz1FTS+FN8Kpxoiykk+J8fC5tenjbu9kSqpHLu9jBrhUuhNwVGbpyZrzrl0 HPVD8SXj5EOOD/eDC64VjvYBZLuUbIVAfBN1t/C/SU+cAGtdGo+fVnzycUX5wmn6eCKPmWYJG2E/ ppTsuRCbvUD9fwquksG5GqLVKhzDQ3GrEyLKSXhsiK3T5j9EyxffCFOYi2wUlPyFFDQAhehESDjQ GoX0ho0oj8RPou6TxHJdcT0NTcWkO0AnG7+uXsnHqcas/72wvWF+mSf7N/Watp9kTXoluzeS0fB9 9CcZ/hvhSZTfh99pispZOXL9KrGrARkNUMu9ITbScZWs7xOYNt9pwxSZtYDsX/GE3xTkrXgwAsXm fud08FiTeC+m2/o7ppo+PTS/NBK5ARpDG5YHr++DpmVfreYdiX8mnp+DzPEG9WbqJON0JBenZofs sxBA1gj5NXGvfJu/Qh7HwQh/VDUEyUxCit5hH94QfKkEdu+GwK8BX0hvCF+D67xhjmXQCXMwJCZ+ olK0A1EKRCE4snsh42w8Mv/Zhxw9iD7Cjo7CyQC/KyF6oBfShL4PYgG+CHsYKyZxvxZSZBAgjhIz YDz+AbfD37GtbaoSKzgGt+lKfI/GZtay6vG4VXTpPsh+IcQhOk9I7WYeP5AM3HZ9+DaSGIp9HIuu huC4pCGGx+YD2fcc5tfIAA0h/Et4/jX8zz4fWAasIf4UbR9Y6HO4d8jAnd4U0Y8ageuCB+c+H5R3 CHU2mTMwZ+B/y8DfSMBLLOYXVuEAAAAASUVORK5CYII= ------=_Part_63885_1027392967.1726147309672-- ------=_Part_63884_1534057763.1726147309672--