On 1 okt 2009, at 06.53, Tom Lane <t...@sss.pgh.pa.us> wrote:

Peter Eisentraut <pete...@gmx.net> writes:
On Wed, 2009-09-30 at 22:08 -0400, Tom Lane wrote:
(Note that you would still need a non-default setting of
listen_addresses for "-h machine_name" to actually work.)

Which makes this proposal kind of uninteresting.

Although come to think of it ... is there any reason besides sheer
conservatism to not make the default listen_addresses value '*'?
It won't result in letting in any outside connections unless you
also add pg_hba.conf entries.

Absolutely. One less opportunity to DOS the server - it's certainly cheaper to deal with connection floods by never even answering the socket. Also, showing up in portscans for example.

Now, that trust authentication is a different issue ;)

/Magnus


--
Sent via pgsql-hackers mailing list (pgsql-hackers@postgresql.org)
To make changes to your subscription:
http://www.postgresql.org/mailpref/pgsql-hackers

Reply via email to