Re: PHP newbie. Storing sensitive data



cbmeeks wrote:
Thanks guys. I'm not saying it has happened but it COULD happen. I
have been using Pair for a long time (generally pleased).

But how could anyone trust their host 100%? I guess if my service got
so big that I could afford co-lo then problem solved. But until then,
I rely (like so many other people) on "cheap" or shared hosting.

I mean, no matter how reliable and trust-worthy a host is they could
always get an evil admin that could browse source code files.

cbmeeks
http://www.codershangout.com



Sadly, even a co-lo wouldn't help you. The people who have physical access to your server can still get at your password if it's on the machine.

The only way to keep it safe is to lock it in a vault to which only you have the combination.

At some point you have to put your trust in someone. For instance, the sysadmins at your bank have complete access to all of your account information. So do you stop using banks?

--
==================
Remove the "x" from my email address
Jerry Stuckle
JDS Computer Training Corp.
jstucklex@xxxxxxxxxxxxx
==================
.



Relevant Pages

  • Re: Here come da judge
    ... that when you host an event of anything near that size you assume some ... private party with people you *know* you can trust. ... those unknown guests. ... I'll take the ultimate responsibility, ...
    (rec.motorcycles.harley)
  • Re: CLiki and ALU Wiki sites massively spammed
    ... It also requires you trust Wiki authors not to make ... making a fake package if your current version has known exploits. ... >> Assuming that the host they're using is safe from compromise, ... If my DNS has been hit by spoofing or the host they use is ...
    (comp.lang.lisp)
  • Re: CLiki and ALU Wiki sites massively spammed
    ... If my DNS has been hit by spoofing or the host they use is ... it will have alerted me to the fact that a package might not ... > physical connection with the PGP Web of Trust, but it in no way relies ... that whoever it was using his old PGP key is someone I trust to write ...
    (comp.lang.lisp)
  • Re: CLiki and ALU Wiki sites massively spammed
    ... If my DNS has been hit by spoofing or the host they use is ... >> physical connection with the PGP Web of Trust, but it in no way relies ... > that whoever it was using his old PGP key is someone I trust to write ... should feel slightly better if there's a web of trust connection. ...
    (comp.lang.lisp)