OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Should login pages be protected by SSL?

From: Steve Shah (sshahrisingedge.org)
Date: Tue Jun 21 2005 - 09:32:31 CDT


On Tue, Jun 21, 2005 at 12:07:34PM +0200, Amir Herzberg wrote:
> experts really agree here, but since some of the companies object, I am
> interested to see if there are some serious defenses of the unprotected
> login practice.

Even with my security hat on, I'd be pressed to justify the load of an
encrypted login for a content site that just needs to identify me to
extract some marketing data from their logs.

-Steve

--
Steve Shah
sshahRisingEdge.org