专用 IP 和 SSL 证书的替代方案?
我想在共享托管服务器上的网站上为我的客户设置一个登录区域。
我目前没有专用 IP 或 SSL 证书。
是否有其他方法可以安全可靠处理我可能想要收集的登录信息和其他敏感信息,而无需花费专用 IP 和 SSL 证书?
I would like to set up a login area for my clients at my web site that is on a shared hosting server.
I do not currently have a dedicated IP or SSL certificate.
Is there an alternative way to safely and securely handle logins and other sensitive information I may want to collect without the expense of a dedicated IP and SSL certificate?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(3)
从实际角度来看,答案是您需要使用 SSL/TLS。它是行业标准,众所周知,并且(正确实施)提供了良好的安全性。虽然理论上可以编写自己的加密和安全协议,但它几乎肯定会存在容易被利用的缺陷和漏洞。
From a practical standpoint, the answer is that you need to use SSL/TLS. It is the industry standard and is well-known and (implemented properly) provides good security. While it is theoretically possible to write your own encryption and security protocols, it will almost certainly have flaws and holes that can be easily exploited.
据我所知,没有 TSL/SSL 的任何内容都意味着客户端和服务器应用程序之间的“明文”通信 - 这意味着任何人都可以监视流量以获取敏感信息或冒充攻击。
To the best of what I know, anything without TSL/SSL would imply "cleartext" communication between your client and your server application - that would mean anyone can monitor the traffic to get sensitive information or impersonate an attack.
不。
No.