WebApp Sec mailing list archives

RE: Should login pages be protected by SSL?


From: "Cowles, Robert D." <rdc () slac stanford edu>
Date: Tue, 21 Jun 2005 20:21:44 -0700

 



There may not be an advantage in breaking into that account
but consider that when grandmother registered at the web
site she probably picked the same userid and password
and password hint as she has at lots of other sites ..

And SSL does nothing to mitigate that risk.

-Steve

-- 
Steve Shah
sshah () RisingEdge org 


SSL mitigates the risk of being able to sniff the userid/password
from the unsecured wireless WAPs.


Current thread: