| 
 Posted by Sanders Kaufman on 12/19/06 09:01 
Rik wrote: 
 
> Yup, it breaks down to some very simple rules: 
> 1. HTTPS. No discussion, don't assume anything if you haven't got it. 
 
Amen.  That IS number one rule.  Every other rule takes a  
backseat to it. 
 
No matter how tight your security is, if users login over HTTP,  
their credentials can be tooooo easily intercepted - making all  
other security measures worthless.
 
[Back to original message] 
 |