Re: MobileMe: http not https?
- From: Fry <me@xxxxxxxxxxx>
- Date: Sat, 30 Aug 2008 11:49:50 +0100
Er...http? Not https? Seems a little slack doesn't it?
Taken from http://www.appleinsider.com/articles/08/08/15/inside_mobileme_web_3_and_web_client_server_apps.html
What
No SSL?
Data transaction security in MobileMe's web apps is based upon authenticated handling of JSON data exchanges between the self contained JavaScript client apps and Apple's cloud, rather than the SSL web page encryption used by HTTPS. The only real web pages MobileMe exchanges with the server are the HTML, JavaScript, and CSS files that make up the application, which have no need for SSL encryption following the initial user authentication. This has caused some unnecessary panic among web users who have equated their browser's SSL lock icon with web security. And of course, Internet email is not a secured medium anyway once it leaves your server.
If Apple applied SSL encryption in the browser, it would only slow down every data exchange without really improving providing perfect security, and instead present what could be a false sense of security that distracts from real security threats.
One other advantage held by MobileMe in terms of security is that Apple runs the entire show. There's no third party ads being injected into Apple's MobileMe apps, no external scripts introducing search results, alerts, or buddy lists that could potentially intercept secure transactions with the server, nor any opportunities for Adobe Flash, Microsoft's Silverlight, or other potentially vulnerable plugins to expose unforeseen security threats. A simplified trust relationship equates to stronger security.
.
- Follow-Ups:
- Re: MobileMe: http not https?
- From: Ian McCall
- Re: MobileMe: http not https?
- References:
- MobileMe: http not https?
- From: Ian McCall
- MobileMe: http not https?
- Prev by Date: Re: MobileMe: http not https?
- Next by Date: Re: MobileMe: http not https?
- Previous by thread: Re: MobileMe: http not https?
- Next by thread: Re: MobileMe: http not https?
- Index(es):
Relevant Pages
|