magazine resources subscribe about advertising

New Architect Daily
Commentary and updates on current events and technologies

CMP Media E-Book

Download your copy today.

Research
Search for reports and white papers from industry vendors and analysts.

This Week at NewArchitect.com Subscribe now to our free email newsletter and get notified when the site is updated with new articles







Day of Defeat Online Gaming

 New Architect > Archives > 1996 > 09 > Webmaster's Domain  

Web Security, Part Three

The project will not aim...to use sophisticated network authorization systems. Data will be either readable by the world (literally), or will be readable only on one file system. All network traffic will be public.
—Tim Berners-Lee

The occasion for this quote was a proposal to the CERN administration to create a new hypertext system called "WorldWideWeb." This excerpt illustrates that document confidentiality was not the top thing on the World Wide Web creators' minds when the protocols were invented. Web servers were originally designed for maximum promiscuity—anybody could read any Web document anywhere in the world.

Outside of academics, however, most of the world demands graded levels of confidentiality. Some documents, such as marketing literature, are completely public. Others, such as departmental budgets, must be restricted to a small groups of authorized individuals. Still others, such as an individual's electronic bank statement, are for a single person's eyes only.

There are two ways that confidential Web documents can fall into the wrong hands:

  1. An unauthorized user can connect to your Web site and download a private document.
  2. A private document can be intercepted "in flight" as it travels over the Internet using widely available "packet-sniffer" programs running on any of the machines on the route between client and host.

To keep documents truly private, you have to close both holes.




  Day of Defeat Online Gaming

home | daily | current issue | archives | features | critical decisions | case studies | expert opinion | reviews | access | industry events | newsletter | research | careers | info centers | advertising | subscribe | subscriber service | editorial calendar | press | contacts


Copyright © 2006 CMP Media, LLC Read our privacy policy, your California privacy rights, terms of service.
SDMG Web sites: BYTE.com, C/C++ Users Journal, Developer Pipeline, Dr. Dobb's Journal, DotNetJunkies, MSDN Magazine, Sys Admin,
SD Expo, SD Magazine, SqlJunkies, The Perl Journal, Unixreview, Windows Developer Network, New Architect

web2