Loading…
Tuesday, May 17 • 11:30am - 12:20pm
Get Your Insecure PostgreSQL Passwords to SCRAM!

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
PostgreSQL 10 introduced SCRAM (Salted Challenge Response Authentication Mechanism) to securely authenticate passwords. The SCRAM algorithm lets a client and server securely validate a password without ever exchanging the password using a series of cryptographic methods!

In this talk, we will look at:

  • A history of password storage and authentication in PostgreSQL
  • Flaws in each of the legacy PostgreSQL password-based authentication methods
  • How SCRAM works with a guided deep dive into the algorithm
  • Channel binding, which helps prevent authentication MITM attacks
  • How to safely set and modify your passwords, and how to upgrade to SCRAM-SHA-256

Speakers
avatar for Jonathan Katz

Jonathan Katz

Principal Product Manager - Technical, Amazon Web Services
Jonathan Katz is a Principal Product Manager – Technical on the Amazon RDS team and is based in New York. He is a Core Team member of the open source PostgreSQL project and an active open source contributor.


Tuesday May 17, 2022 11:30am - 12:20pm CDT
Salon 2 Zlotnik L