in reply to In a web app, is using ssl, encrypting request data, and validating request data after decryption overkill?
"If you make it 'idiot proof', the Universe will develop a better Idiot" -- The Darwinian Rule of Software Development.
Seriously, it is very hard to go over-board in checking what an unknown (and possibly malicious) User has sent you. Bear in mind that from time to time new attack vectors appear and encryption methods are compromised. Having your suspenders buttoned on tight as well as buckling your belt can be the difference between sleeping the night through and the O'Dark Hundred phone call ....
----
I Go Back to Sleep, Now.
OGB
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: In a web app, is using ssl, encrypting request data, and validating request data after decryption overkill?
by Fletch (Bishop) on Jul 02, 2007 at 16:02 UTC |