SSL is a Lousy Band Aid

Security practitioners love SSL, and with good reason. It is well designed with support for multiple encryption protocols, and is easily reconfigured in case any should get cracked or outdated. It is an incredibly useful tool, protecting transactions as they cross otherwise insecure channels such as the Internet. It’s also great for certificate-based bilateral authentication, provided of course you actually have the cash and personnel resources to maintain it.

If anything, SSL is too well implemented, and people think it covers all their needs, like a giant security blanket. They forget there is much more to security than just using SSL.

Read the rest of this informative article here

Leave a Reply