[23508] in APO-L
[APO-L] Security
daemon@ATHENA.MIT.EDU (Robert Dean)
Tue Feb 4 10:42:37 2003
Date: Tue, 4 Feb 2003 10:42:22 -0500
Reply-To: rdean71@cs.com
From: Robert Dean <rdean71@cs.com>
To: APO-L@LISTSERV.IUPUI.EDU
jgrossi@attbi.com wrote:
>Let me make it clear... there is no such thing as complete
>computer security.
Let's not get nitpicky. If you want to be completely accurate, you should delete the "computer" from the above sentence. Physical security can be broken just like virtual security can. Paper copies can be stolen. In your other example, the private can be shot with a tranquilizer dart, the concrete broken, and the cables replaced. It's not a matter of what provides absolute security...it's a matter of what provides reasonable security.
.htaccess isn't secure because there are people out there with packet sniffers, and it's trivial for them to capture the information as it comes across their pipes. SSL is the most workable scenario because it encrypts the data, is a standard, and is reasonably easy to set up.
--Robert