Re: securing html forms

We are talking about 2 different kinds of security here:

1. Security of your server.  It is your responsibility to your clients
to ensure that your server is as secure as possible so that they feel
safe in giving you confidential information.  If your server is
insecure, the customer information that you are storing on your server
is liable to be compromised, leading to Bad Things happening.

2. HTTP security.  Many customers will demand or prefer a secure
(encrypted) channel when they transmit confidential information like
credit card numbers or passwords to your server.  You definitely need
HTTPS for that.  Having said that, guess how many of the millions of
credit card numbers which have been stolen on the 'net were stolen
while being transmitted to a server?  Yes, that's right: None!  The
problems associated with snooping confidential information on public
networks are so many, that 999 times out of 1000 it's much easier to
just crack into the server where the CC numbers are stored and pick
them up from there.  In other words, HTTPS/SSL is (usually) mostly
marketing hype.


-- Raju

