It amazes me that still in 2011, the standard way web designers upload code to a server is FTP ("File transfer protocol"), a protocol that is completely insecure, easy to snoop, slow, hard to use, and often problematic through firewalls. There are many better ways.
If your web site designer connects via FTP to your web server over a public wifi network (and how many designers do you know make a coffee shop their second home?) they're potentially revealing the password to your server to everybody else in that coffee shop! With your password, it's trivial to upload malicious code to your site to intercept your customer's credit card numbers, passwords, or whatever the attacker chooses to exploit. Or vandalize your web site, change text, embed viruses and spyware, do things that could lose you business. This has happened to sites as big as the Miami Dolphins NFL team, and huge numbers of smaller sites.
We don't even install FTP on our servers. You can't log into our servers with a password, either -- you need to have a special encryption key on your computer that is allowed to make a connection. That means even if you get my password, you still can't log onto our production servers.
That's just one way we keep our environment more secure than a typical web host. We're constantly keeping up with how attackers break into sites, what tools they use to find vulnerable sites (which are surprisingly easy to use) and how we can stay ahead of the attacks. Sooner or later, though, everybody online gets tested, and even the best laid defenses get breached. Read on for what's next.
Secure the environment
More Like This
Ask Freelock: Why Is My Site Still Getting Hammered by Bots — Even on a Major Hosting Platform?
We recently heard from a former client who had moved their site to a major managed hosting platform, hoping for more stability and better protection.
Website Availability - handling an outage
How do you get a website back up, when it goes down?
Is your host a single point of failure?
Just ran across a sad story where Digital Ocean is accused of killing a startup:
Ask Freelock: "Traditional hosts" vs "cloud providers"
A client asks about yet another hosting option:
The VPS-2000HA-S includes the following resources:
6GB RAM (burstable)
150GB SSD Disk space
5TB Monthly Bandwidth
4 free dedicated IP's
Is your website safe from a cyber attack?
As I write, we're in the midst of a big Ransomware attack. Millions of computers have been infected, with their data encrypted, held ransom pending an extortion payment or deleted. Supposedly.
6 things to consider before the next AWS outage
Yesterday Amazon Web Services (AWS) had a major outage in their US-East datacenter, in Virgina. It made all sorts of national news, largely because it affected some major online services.
11 Questions Businesses need to ask themselves when choosing a Drupal host: The Comprehensive Freelock Hosting Guide
When choosing any service provider, a crucial question is, "What happens if something goes wrong?" When you're choosing a hosting provider, we like to dig a bit deeper, and ask what risks are likely to be an issue for you?
Here are some of our questions:
Add new comment