|
From: Patricia J. <jab...@cl...> - 2005-03-23 21:53:43
|
<FONT face=3D"Default Sans Serif,Verdana,Arial,Helvetica,sans-serif" size= =3D2><div>Hello,</div><DIV> </DIV><DIV>Yes, I believe when I talked to= Professor Horn about htaccess before</DIV><DIV>(correct me if I'm wrong) t= hat he said with htaccess the password is</DIV><DIV>sent in the clear. = ; But, he mentioned to me that besides that problem,</DIV><DIV>which would = only be detected when the password is typed and if </DIV><DIV>someone was u= sing a program like Ethereal, that it is unhackable. Like,</DIV>= <DIV>for example, the hidden .htaccess, .htgroup, .htpasswd, are not</DIV><= DIV>accessible directly from the web (by typing in their file name) and the= </DIV><DIV>password that is stored in the .htpasswd file is encrypted, so i= t is safe.</DIV><DIV>It is an OK way to quickly keep a directory restricted= , but SSL, from</DIV><DIV>what I am learning about it would be better. = ; Mike, isn't SSL open?</DIV><DIV>And if so, then why would the statio= ns even have to buy it? That </DIV><DIV>doesn't make sense to me= . Isn't installing SSL on a server just like</DIV><DIV>installing PHP= , MySQL and Apache? Those are required for this project</DIV><DIV>(an= d others), so adding SSL should not be a problem, I wouldn't think.</DIV><D= IV>It would be just like the PHP, MySQL and Apache requirement - pretty</DI= V><DIV>necessary for security.</DIV><DIV> </DIV><DIV>- Patty -</DIV></= FONT>= |