douchui4459 2009-10-20 15:47
浏览 21
已采纳

如何保护用户注册?

What is the most secure way of registering new users?

I know SSL is a good pick. But can I have SSL on user registration only?

Take Wordpress for example. User registration is at http://en.wordpress.com/signup/. And the user registration form is sent to https://en.wordpress.com/wp-login.php.

The same goes for login.

How can I make just registration / and login use SSL ? I don't want SSL for any other parts of the site (yet).

  • 写回答

2条回答 默认 最新

  • dongshao1873 2009-10-20 16:35
    关注

    My recommendation would be to use SSL for the page that contains the login/signup form, as well as for the page that is being posted to. Using SSL only for the posted-to page is already very good, but if you want to add more protection then the form-containing page should be served over an authenticated channel.

    This is to guard, of course, against the possible (even if, perhaps, unprobable) modification of the form-containing page by an adversary; but what may be more important is that it would make the user aware that their personal information is being kept secret, before they actually have to submit that information. If you have SSL only for the posted-to page, the user may not have a way of telling whether their personal details will go over a secure channel.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(1条)

报告相同问题?

悬赏问题

  • ¥50 potsgresql15备份问题
  • ¥15 Mac系统vs code使用phpstudy如何配置debug来调试php
  • ¥15 目前主流的音乐软件,像网易云音乐,QQ音乐他们的前端和后台部分是用的什么技术实现的?求解!
  • ¥60 pb数据库修改与连接
  • ¥15 spss统计中二分类变量和有序变量的相关性分析可以用kendall相关分析吗?
  • ¥15 拟通过pc下指令到安卓系统,如果追求响应速度,尽可能无延迟,是不是用安卓模拟器会优于实体的安卓手机?如果是,可以快多少毫秒?
  • ¥20 神经网络Sequential name=sequential, built=False
  • ¥16 Qphython 用xlrd读取excel报错
  • ¥15 单片机学习顺序问题!!
  • ¥15 ikuai客户端多拨vpn,重启总是有个别重拨不上