NYCPHP Meetup

NYPHP.org

[nycphp-talk] client doesn't want security: what to do?

David Mintz dmintz at davidmintz.org
Wed Jan 7 17:19:11 EST 2004


On Wed, 7 Jan 2004, Chris Shiflett wrote:

> --- David Mintz <dmintz at davidmintz.org> wrote:
> > Geek has declared that the status quo is OK because the page through
> > which the sensitive data is retrieved is SSL-encrypted.
>
> Are you sure Geek is wrong?
>
> Maybe you need to start giving some details. :-)

I'd like to. OTOH is it wise to get to detailed about your weaknesses on a
list that is publicly available and archived? Granted, this is paranoia in
the extreme, but....


---
David Mintz
http://davidmintz.org/

        "Anybody else got a problem with Webistics?" -- Sopranos 24:17



More information about the talk mailing list