Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

OP here. That's entirely correct, Postgres deployed correctly is secure against a MitM, but since Heroku has not issued a trust root, they are not.

Edited to add: As a user of Heroku Postgres you can't configure Postgres correctly, Heroku is supposed to do that for you.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: