3 ms·
OK. So you use encryption. +1 Have you had a vulnerability assessment done? Do you protect against SQL Injection? Do you protect against Cross-Site Scripting?
by dacort 17y ago
OK. So you use encryption. +1
Have you had a vulnerability assessment done?
Do you protect against SQL Injection?
Do you protect against Cross-Site Scripting?
How about Cross-Site Request Forgery?
What preventative measures have you taken to lock down your servers?
I know most users don't care about all of those and you're trying to be friendly by saying you use "bank-level" encryption, but some more info would be nice for those of us that care.
- sailormoon 17y agoYes to all of that. And .. We use the latest in bank-level 256-bit SSL encryption to protect your information, and your passwords are securely encrypted. Right. 256 bits, like everyone else, like it makes some critical difference over 128 unless you're the freaking NSA, and like anyone even bothers trying to break into a TLS session. Not encouraging. First thing I always check is whether the site's behind a gateway, so let's try and connect on 22: $ ssh etacts.com The authenticity of host 'etacts.com (173.203.202.141)' can't be established. RSA key fingerprint is ec:c2:2f:fe:ef:7e:06:a3:a5:f0:a3:54:04:79:2a:16. Are you sure you want to continue connecting (yes/no)? yes Warning: Permanently added 'etacts.com,173.203.202.141' (RSA) to the list of known hosts. sailormoon@etacts.com's password: Permission denied, please try again. Tsk. Early days I know, but .. if you become popular for storing a large database of people's login creds for gmail .. that's a nice juicy target. And I actually found the mention that they're encrypting the passwords, like that means anything (the key is obviously somewhere on the server, and once they're in, they're in) to be more worrisome than not.
- deleted 17y ago[deleted]