> To me - not ONE backdoor should be left open, not one of my
> clients should ever have to put up with a break-in to their site,
> no matter what site or client.

Do they pay for this privilege? If so they should be able to save up & buy
an SSL cert. Total Security is like the mythical Total Solution which in
turn is like Santa & the tooth fairy. Every system has holes. SSL is one
very easy way to close one big back door.

Have you heard of the 80/20 rule? Security is very similar you don't need
the level of security a bank has to run a weblog. Absolute terms like "not
ONE" & "ever" are very hard to live up to.

> And yes, the self-signed certificates are perfect for Admin
> panels, but you even admit even then a secure process needs to be
> in place.

No - you're twisting my words. Most of our admin tools don't use SSL because
its not worth the trouble. Why is someone going to break into a flower shops
homepage & modify content? And even if they do is it a tragedy having
incorrect content on the site for a couple of hours until someone notices &
the previous version is restored?

Anyway I've said pretty much all I've got to say. Security costs time &
money. Security is not always required & is often overkill. SSL (or
equivalent) is a prerequisite to any sort of web based security.


Cheers

Mark


------------------
Mark Stanton
Technical Director
Gruden Pty Ltd
Tel: 9956 6388
Mob: 0410 458 201
Fax: 9956 8433
http://www.gruden.com


---
You are currently subscribed to cfaussie as: [EMAIL PROTECTED]
To unsubscribe send a blank email to [EMAIL PROTECTED]

MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia
http://www.mxdu.com/ + 24-25 February, 2004

Reply via email to