|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help. |
Share Thread: & Tags
|
||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
||||
|
My quick 5 cents worth
SSL or EV-SSL (the green stuff) seems the best. As for storing it, send it from the receiving web server to another server for storage, or encrypt the data before you save it to the local database. I would surely go with SSL above plain email if these were the two choices. |
|
||||
|
SSL is a must on the url where the information is collected. I would recommend a Linux host server, with cgi-bin. An application can write to a log file in the cgi-bin, protected with .htaccess and an additional index file in the directory where it's stored. Permissions on the file can be set to the highest security, and still allow the application to write to the log.
The information should be retrieved by direct FTP connection, or by a management interface also in the same cgi-bin, with no cache tags. If your host has a local MySQL server, you might be able to use that sort of database, but I would verify that the server is not remote, before using it. How many applications does your client take per day? If it's an extremely high number, then look at dedicated server hosting. If it's a small number, and not likely to grow a lot, then vps or shared hosting would work fine. The same kind of rules apply to sensitive credit card/financial data, when a shopping cart is using an 'offline' processing setup. Hope this helps... puamana
__________________
The difference between the right word and almost the right word is the difference between lightning and the lightning bug. - Mark Twain |
|
||||
|
It also occurs to me that the cheapest way for your client to go would be a contract with a web-based form processing service, especially if they offer a secure form data collection service.
- p
__________________
The difference between the right word and almost the right word is the difference between lightning and the lightning bug. - Mark Twain |
|
||||
|
I don't know that puamana's suggestion would be "cheapest" way to go, but it sounds like the safest.
Personally, I would recommend that the client not require especially sensitive information via the on-line form, such as SSN, DL no., Passport # and the like. Even if the company manages to get the information transmitted to it securely, there is still considerable liability in having it in their possession. Given that an applicant might be rejected for employment, and decide he has a bone to pick with the company, why give them any ammunition? Get that information in person, at the interview.
__________________
If I ever stop learning, just throw my carcass to the wolves! My Life's Disjointed Story | Car Forums and Classifieds |
|
|||
|
You can always encrypt your email. Or if your that worried you can always spilt it half & half i.e. half the info in the DB & half via the email and then join them later.
What happens once you receive the data though? Is it stored locally somewhere? This could be the same situation with storing on your webserver. |
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Secure and non-secure things on checkout pages | rjjj111 | eCommerce Discussion Forum | 2 | 07-10-2008 08:23 AM |
| employment | dm27 | Graphics & Design Discussion Forum | 1 | 01-23-2008 11:08 AM |
| Google Analytics on site with secure and non secure pages? | joer80 | Google Discussion Forum | 7 | 12-07-2005 12:15 AM |
| this page contain both secure and non secure item | asimkhaliq | Web Programming Discussion Forum | 2 | 09-29-2004 09:10 PM |
| Wireless networks - secure or not to secure? | Kilawa | IT Discussion Forum | 13 | 03-16-2004 10:29 PM |
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2010 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |