> To me - not ONE backdoor should be left open, not one of my > clients should ever have to put up with a break-in to their site, > no matter what site or client.
Do they pay for this privilege? If so they should be able to save up & buy an SSL cert. Total Security is like the mythical Total Solution which in turn is like Santa & the tooth fairy. Every system has holes. SSL is one very easy way to close one big back door. Have you heard of the 80/20 rule? Security is very similar you don't need the level of security a bank has to run a weblog. Absolute terms like "not ONE" & "ever" are very hard to live up to. > And yes, the self-signed certificates are perfect for Admin > panels, but you even admit even then a secure process needs to be > in place. No - you're twisting my words. Most of our admin tools don't use SSL because its not worth the trouble. Why is someone going to break into a flower shops homepage & modify content? And even if they do is it a tragedy having incorrect content on the site for a couple of hours until someone notices & the previous version is restored? Anyway I've said pretty much all I've got to say. Security costs time & money. Security is not always required & is often overkill. SSL (or equivalent) is a prerequisite to any sort of web based security. Cheers Mark ------------------ Mark Stanton Technical Director Gruden Pty Ltd Tel: 9956 6388 Mob: 0410 458 201 Fax: 9956 8433 http://www.gruden.com --- You are currently subscribed to cfaussie as: [EMAIL PROTECTED] To unsubscribe send a blank email to [EMAIL PROTECTED] MXDU2004 + Macromedia DevCon AsiaPac + Sydney, Australia http://www.mxdu.com/ + 24-25 February, 2004
