RE: What features shall be handled by SLiMP3 andwhat features shouldn't?

Jason Snell <jsnell-AANFnQOTzEpWk0Htik3J/[email protected]> Mon, 17 Feb 2003 13:21:04 -0800
Newsgroups gmane.music.equipment.slimp3.dev
Message-ID <p06000609ba7702389d9e@[10.0.1.31]>
Kevin Walsh wrote:

>HTTP Basic Authentication sends the username and password in the
>clear, so you only get the illusion of security, rather than an actual
>secure setup.

You're wrong.

It's not the "illusion" of security, it's just _extremely limited_ 
security. It means that your system is secure from people who are 
just passing by, but not from people who are intercepting packets.

There's a HUGE difference between the two. If someone wants to 
intercept packets so they can see my Slimp3 library, I'm fine with 
that -- it's not worth their effort, in my opinion, nor is it really 
worth my effort to stop them. But if someone just plugs in my IP 
address and the proper port and gets a wide-open web interface, 
that's unacceptable to me.

I understand what you're saying, and it's among the basics of web 
security, but in this case I think you're being way too black and 
white about this issue.

-- 
Jason Snell / Editor, Macworld / jsnell-AANFnQOTzEpWk0Htik3J/[email protected]
415-243-3565 / AIM-iChat: MW jsnell

------------------------ Yahoo! Groups Sponsor ---------------------~-->
Get 128 Bit SSL Encryption!
http://us.click.yahoo.com/FpY02D/vN2EAA/xGHJAA/rIp0lB/TM
---------------------------------------------------------------------~->

To unsubscribe from this group, send an email to:
[email protected]

 

Your use of Yahoo! Groups is subject to http://docs.yahoo.com/info/terms/