Posted by Sanders Kaufman on 12/19/06 09:01
Rik wrote:
> Yup, it breaks down to some very simple rules:
> 1. HTTPS. No discussion, don't assume anything if you haven't got it.
Amen. That IS number one rule. Every other rule takes a
backseat to it.
No matter how tight your security is, if users login over HTTP,
their credentials can be tooooo easily intercepted - making all
other security measures worthless.
[Back to original message]
|