惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
GbyAI
GbyAI
Jina AI
Jina AI
博客园_首页
Y
Y Combinator Blog
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
M
MIT News - Artificial intelligence
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
MyScale Blog
MyScale Blog
MongoDB | Blog
MongoDB | Blog
雷峰网
雷峰网
罗磊的独立博客
博客园 - Franky
Last Week in AI
Last Week in AI
Vercel News
Vercel News
Martin Fowler
Martin Fowler
Stack Overflow Blog
Stack Overflow Blog
Microsoft Security Blog
Microsoft Security Blog
月光博客
月光博客
WordPress大学
WordPress大学
W
WeLiveSecurity
Apple Machine Learning Research
Apple Machine Learning Research
TaoSecurity Blog
TaoSecurity Blog
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
Schneier on Security
Schneier on Security
Engineering at Meta
Engineering at Meta
Simon Willison's Weblog
Simon Willison's Weblog
博客园 - 【当耐特】
宝玉的分享
宝玉的分享
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
P
Proofpoint News Feed
C
Cyber Attacks, Cyber Crime and Cyber Security
博客园 - 叶小钗
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
LINUX DO - 最新话题
S
Security @ Cisco Blogs
B
Blog RSS Feed
B
Blog
爱范儿
爱范儿
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Tailwind CSS Blog
Attack and Defense Labs
Attack and Defense Labs
V
Visual Studio Blog
NISL@THU
NISL@THU
U
Unit 42
Hugging Face - Blog
Hugging Face - Blog
A
Arctic Wolf

The Register - Special Features

Troops’ phones gave away location data to foreign adversaries Qualcomm picks bad time to pitch a $300 laptop platform AI agents get their own phone directory built atop DNS Carnival confirms ShinyHunters cruised off with 6M customer records after April breach Google engineer accused of turning Year in Search secrets into Polymarket payday Are we human? India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat Broadcom gets early start on WiFi 8 with next-gen wireless routing kit Are we human? Microsoft Excel champ proves he still has the formula Anthropic co-founder hallucinates ghost in the machine Anthropic co-founder hallucinates ghost in the machine NASA plans Moon Base buildout with rovers, drones, cargo landers MyPillow must decide whether to be firm or soft as ransomware crims demand pay Starship shows it can deploy satellites, but Moon mission clock still ticks Huawei's chip law looks less like Moore and more like marketing Experts pour cold borscht on Farage's Russian hack claim Logitech unveils a cushioned mouse for all-day use AI eyes scanning for bugs create a worrisome Linux security trend A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets AI datacenter boom collides with US grid reality Media giant settles for $930k amid user-snooping allegations AT&T sues to ditch Cali copper phone lines to save billions FBI warns of Kali365 as device code phishing soars Techie claims Trump Mobile website was leaking thousands of people's data BOFH: Vibe-coded solutions arrive for problems nobody has Dems slam Trump for making cybersecurity hold out the tin cup while splurging on ballroom and Jan. 6 'slush fund' Google explains how it will infuse ads into AI answers AI is getting pricey, but relief is coming, but not for you Deus ex machina: Half of US Christians trust AI's spiritual advice Attackers spill plaintext passwords of 46k Myspace93 users after 2021 breach Apple adds AI smarts to Voice Control, VoiceOver and Magnifier ahead of Accessibility Day Microsoft open-sources agentic AI safety tools OpenAI wants upfront cash for guaranteed AI capacity Fedora: Microsoft is all aboard, but Deepin is dumped Bye-bye, Gemini CLI; Google nudges devs toward Antigravity Plex appeal fades as Lifetime Pass jumps to $750 AI sackings reach New Zealand, which will use it to eject 14 percent of government staff Anthropic’s Stainless steal tightens grip on AI dev tooling Are we human? Google touts tokenmaxxing, huge capex, and AI agents at I/O America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames America's top cyber-defense agency left a GitHub repo open with passwords, keys, tokens – and incredibly obvious filenames Shadow AI invades the workplace, up 4x in the last year Microsoft refreshes Surface for Business lineup, starts AI PC upsell at $1,499 Broadcom finds a VMware customer willing to stick around: London Stock Exchange 468k records allegedly stolen from Portugal’s postal carrier Baidu says the quiet part out loud – you can’t build AI infrastructure, so clouds can cash in Shai-Hulud copycat worm infects yet another npm package Uncle Sam's next big super might not use GPUs Are we human? Datacenters slurping up so much juice they boosted prices 75% in largest US energy market MPs want social media treated more like unsafe toys than harmless apps Cerebras’ wafer-scale AI bet delivers blockbuster IPO Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Anthropic tosses agents into the API billing pool Jen Easterly, cybersecurity's 'relentless optimist,' hopes feds come back to RSAC next year Jen Easterly, cybersecurity's 'relentless optimist' Smooth criminals talking their way into cloud environments, Google says Voice phishing skyrockets as smooth crims talk their way in RSAC 2026: Uncle Sam backs out, AI agents everywhere RSAC 2026: Uncle Sam backs out, AI agents everywhere Decoding Nvidia's Groq-powered LPX and the rest of its new rack systems A closer look at Nvidia's Groq-powered LPX rack systems Nvidia slaps $20B Groq tech into massive new LPX racks to speed AI response time Nvidia slaps Groq into new LPX racks for faster AI response AI Burning Man happens next week – what to expect at Nvidia GTC 2026 Nvidia GTC 2026: What to expect at AI Burning Man Unaccounted-for AI agents are being handed wide access Unaccounted-for AI agents are being handed wide access Google to foist Gemini pane on Chrome users Google to foist Gemini pane on Chrome users Yes, you can build an AI agent – here's how, using LangFlow How to build an AI agent using LangFlow Clawdbot becomes Moltbot, but can’t shed security concerns Clawdbot becomes Moltbot, but can’t shed security concerns Gartner questions if Salesforce AI will stay all-you-can-eat Gartner questions if Salesforce AI will stay all-you-can-eat Claude supports MCP Apps, presents UI within chat window Claude supports MCP Apps, presents UI within chat window Cursor is better at marketing than coding Cursor is better at marketing than coding Feds skipping infosec industry's biggest conference, RSAC AI is rewriting how power flows through the datacenter All aglow about DCs, investors launch $300M at microreactor startup Radiant bags $300M-plus to commercialize its microreactors Why do bit barns keep bumping up our bills, Senators ask DC operators Senate trio questions DC operators over rising energy costs Building the AI factory datacenter Delays? What delays? Oracle insists its $300B cloud contract with OpenAI is on track Oracle insists its $300B contract with OpenAI is on schedule Salesforce willing to lose money on AI to lock in customers Salesforce willing to lose money on AI to lock in customers Galactic Brain space datacenter coming in 2027, pledges startup Aetherflux Galactic Brain space datacenter promised in 2027 Activist groups urge Congress to pause datacenter buildouts Activist groups urge Congress to pause datacenter buildouts Bezos-backed Unconventional AI addresses datacenter power Bezos-backed Unconventional AI addresses datacenter power AWS re:Invent keynote: Matt Garman bores, then thrills
The database that refused to die: How Postgres survived its own creators
Joab Jackson · 2026-06-23 · via The Register - Special Features

FEATURE Today Postgres is one of the most widely used database systems, but its launch and subsequent development were inauspicious to say the least.

If it weren’t for a league of exceptionally devoted open source contributors, it probably would be another forgotten also-ran just like Ingres, the database system on which it was based (“Postgres” was shorthand for “Post-Ingres”). 

The creator of both systems, Michael Stonebraker, is perhaps the preeminent database pioneer in the field. Earlier this month, he spoke at PGDay, a conference in Boston hosted by the U.S. PostgreSQL Association, where he detailed the complicated history of the open source database system, which actually existed long before the term "open source" was even uttered.  

In a sense, “Postgres is the epitome of open source software, because it doesn't belong to anybody. It was picked up by this team of programmers without any specific affiliation,” Stonebraker said.   

Stonebraker essentially abandoned Postgres in the mid-1990s. But instead of fading into obscurity, the codebase was salvaged by a fiercely-dedicated volunteer community that bolted on standard SQL while preserving Stonebraker’s revolutionary extensible architecture. 

Three decades later, this stubbornly-independent database has become the bedrock of modern cloud infrastructure.

Data should be relational 

When it comes to relational database systems, British computer scientist and then-IBM employee Ted Codd got the ball rolling in 1970. A database is where you store your data so it can be queried in a predictable way. A database system is the software that manages the database (don’t confuse the two). 

That year, Codd decreed that all data should be stored in tables and accessed using a high-level query language. IBM implemented Codd’s idea in System R, and created SQL as the query language. The results were eventually rolled into IBM's DB2. 

Stonebraker, then an assistant professor at UC Berkeley, also implemented Codd’s ideas. Stonebraker and his team of grad students created not only a working prototype, but a full-scale implementation – he later cofounded a startup, Relational Technology, to sell Ingres commercially. Ingres did not use SQL, but instead employed another query language, QUEL (Query Language), although the fundamentals were similar.  

A relatively primitive version of Ingres was even released gratis for academic research. But by the early 1980s, Stonebraker had “pushed the code off a cliff” and started building something new. 

Thus, Postgres was born. 

Beyond Ingres: Postgres

At the time, Stonebraker explained, the business world was pushing for databases to hold additional data types beyond the integers, floats, and character strings required for basic business accounting. There was complicated CAD data and GIS data, with multiple data points that needed to be stored and reasoned against. 

It was clear to Stonebraker and his colleagues that the ideal database system needed to be extended with more data types, user-defined data types, user-defined operators, and user-defined functions. 

Adding more data types and such might seem simple enough, but the “devil is in the details,” he noted. “You need to be able to teach the query optimizer about new types, and that's not exactly easy.”  Commutative rules had to be worked out, and they had to be optimized. 

This led to what was probably Postgres’ most successful feature: support for abstract data types (ADTs).

Stonebraker had other ambitions for Postgres as well. He also wanted to incorporate new work from Chris Date on referential integrity, which brought “semantic consistency between foreign keys and primary keys” to the relational model. He wanted to add in a rules engine, which would continually monitor for changes and make decisions based on those changes. Also, he wanted crash recovery. 

The crash recovery and the rules engine never quite worked out, but the ADTs took root, and now most database systems support this extensibility, pretty much exactly like they were devised by Stonebraker and Co. in 1983. 

“We pretty much got it right,” he said. In fact, he reckons that his work on ADTs was probably the major reason he landed the Association for Computing Machinery’s 2014 A.M. Turing Award

Stonebraker and his mates were eager to make money from their creation. So they rolled Postgres into a start-up, Illustra, which was eventually purchased by Informix, which promptly digested the technology into its own database server. 

But they also maintained an open source version…barely. It wasn’t even called open source (which wasn’t a formal term until 1998). It was considered freely available academic software, something for fellow researchers to tinker with. And it was based on the very-permissive BSD license.  

The architecture that refused to die

In 1995, two Berkeley graduate students, Andrew Yu and Jolly Chen, resurrected Postgres from the last 4.2 academic release. They jettisoned the poorly-running rules engine and disaster recovery features, and, most importantly, swapped out QUEL for the then industry standard of SQL, releasing the software as Postgre95 (and later PostgreSQL). 

“I didn't know any of these people,” Stonebraker said of this all-volunteer development crew. They were “a collection of super programmers who picked up this open source project and started shepherding it forward, and they've been shepherding it for the last 30 years.”

This sovereignty made Postgres safe for anyone to use and modify. Postgres’ wire interface has been widely used as the base for building other database systems, including CockroachDB, YugoByteDB, and TimeScale. Amazon Web Services, Microsoft Azure, and Google Cloud each have their own database-as-a-service built on Postgres. Chief selling point? Each is fully Postgres compatible. 

 “The elephants have basically bet the ranch on Postgres,” he said.

Even AWS’ graph database service is built on Postgres  (“the relational implementation of [a graph database] is almost always faster, usually substantially faster, than doing it natively,” Stonebraker quipped.)

Top of the heap

These days, Postgres sits near the top of the DB-Engines ranking of the world’s most popular database systems, just below Oracle, MySQL and Microsoft SQL Server. Unlike those rivals however, Postgres continues to steadfastly gain market share. 

Tom Kincaid helped organize the PGDay meetup – and is a vice president of EDB, a Postgres service company. He offered several reasons why Postgres made such a big impact, despite its initial lack of support from any of the IT giants (unlike the fellow open source MySQL, now managed by Oracle, which many open sourcerers distrust for that reason alone).

Extensibility was a major help in adoption, especially as the role of databases expanded beyond basic business accounting. ADTs gave the database system an easy entry into an expanding geospatial market, and later, document databases. 

“Postgres was quickly able to provide developers exactly what they needed for storing, retrieving and searching JSON documents,” Kincaid told The Register. “The fact that you could combine SQL with many different data types allowed it to thrive with every new trend in application development.”

Also helping was the quality of the codebase (“It is held to the highest standard of review,” Kincaid said) which attracted top developers, as did the quality of the optimizer. The permissive licensing also helped, allowing start-ups and project leaders to build derivative products without fear of legal repercussions. 

Why Postgres still doesn’t have file-level encryption

Despite all the love from the open source community, Postgres is still missing features that it might need to maintain parity with commercial database systems. 

This was the focus of another illuminating PGDay talk by long-time Postgres contributor (and always dapper) Bruce Momjian. He ran down a long list of missing features, most of which the development team are currently grappling with. 

The database system could use 64-bit transaction IDs to accommodate very large databases. It could also use support for columnar storage, which is all the rage for large-scale data analysis. Global indexing, server-threading, internal connection pooling and sharding are also features in various stages of assembly.   

The major feature Postgres currently lacks, however, is file-level encryption, or “transparent data encryption,” as it is called in the industry. TDE is supported by all commercial database vendors, and it is required by the latest Payment Card Industry (PCI DSS) specifications for storing financial transaction data. Currently, Postgres lets the operating system handle the encryption. 

Current development on Postgres file-level encryption is stalled “in many ways,” Momjian said. “The code changes became too heavy for the value of the feature,” he said. Not only would the functions touching the data files themselves need modification, but all the other functions scattered through the system that write temporary files must be altered as well. This would be a “monstrous” job, he said.

Still, missing features allow commercial entities to fill in the gaps. Percona, for instance, offers the feature as part of its own Postgres commercial distribution. 

Commercial database companies are very sensitive to customer requirements, whether those requirements are truly necessary in a practical or technical sense, or if they are merely external or regulatory in nature.

It’s the latter set of requirements that don’t make it to the top of the Postgres to-do list as quickly, Momjian said.  “We don't want to add a feature unless it really has technical value,” he said.

Momjian pointed out that the PCI mandate itself also has questionable value purely from a technical view. Once the contents are copied into the server’s memory, the encryption protection vanishes. If an attacker can bypass a system’s file system permissions, they can probably read the raw working memory and get the encryption key.

“If we're trying to lock down the file system, we'd also have to lock down memory. We don't know how to do that,” he said.

But the missing TDE may not even be a bug at all, but an actual feature of Postgres's fundamental philosophy. 

“While proprietary databases target the workloads of their largest customers, Postgres targets the workloads of general users,” he said. 

And that may be the best kind of success for an open source project. ®