It amazes me that still in 2011, the standard way web designers upload code to a server is FTP ("File transfer protocol"), a protocol that is completely insecure, easy to snoop, slow, hard to use, and often problematic through firewalls. There are many better ways.
If your web site designer connects via FTP to your web server over a public wifi network (and how many designers do you know make a coffee shop their second home?) they're potentially revealing the password to your server to everybody else in that coffee shop! With your password, it's trivial to upload malicious code to your site to intercept your customer's credit card numbers, passwords, or whatever the attacker chooses to exploit. Or vandalize your web site, change text, embed viruses and spyware, do things that could lose you business. This has happened to sites as big as the Miami Dolphins NFL team, and huge numbers of smaller sites.
We don't even install FTP on our servers. You can't log into our servers with a password, either -- you need to have a special encryption key on your computer that is allowed to make a connection. That means even if you get my password, you still can't log onto our production servers.
That's just one way we keep our environment more secure than a typical web host. We're constantly keeping up with how attackers break into sites, what tools they use to find vulnerable sites (which are surprisingly easy to use) and how we can stay ahead of the attacks. Sooner or later, though, everybody online gets tested, and even the best laid defenses get breached. Read on for what's next.
Secure the environment
More Like This
🕑May 28, 2026 🖋John Locke
💬0
Every Night, Argo Watches
While your site is running, things change. A content editor tweaks a configuration setting. A security vulnerability surfaces in a dependency. A production fix gets applied directly instead of going through the normal release process.
🕑May 22, 2026 🖋John Locke
💬0
The Night the Internet Tried to Kill Your Website
May 2026
My name doesn't matter. Call me the op. I run a small shop — we keep websites alive, patch the holes before the wrong people find them, and make sure that when something goes sideways, there's always a way back. It's not glamorous work. But this spring? This spring was something else.
🕑May 19, 2026 🖋John Locke
💬0
Your Website Will Be Attacked. Here's How We Make Sure You Survive It.
The question used to be whether your website would face a serious security threat. That question has been answered. The question now is whether you'll be ready when it happens — and whether you can recover cleanly when something gets through.
🕑May 18, 2026 🖋John Locke
💬0
The Rules Have Changed: Security in the Age of AI-Assisted Attacks
Security is getting dramatically harder and more expensive. AI is simultaneously driving an explosion in vulnerability discovery and weaponizing the exploits that follow. The question for every organization with anything online is no longer whether to invest in resilience — it's whether that investment is already in place before the next incident arrives.
🕑Apr 15, 2026 🖋John Locke
💬0
Ask Freelock: Why Is My Site Still Getting Hammered by Bots — Even on a Major Hosting Platform?
We recently heard from a former client who had moved their site to a major managed hosting platform, hoping for more stability and better protection.
🕑Jun 12, 2025 🖋John Locke
💬0
Website Availability - handling an outage
How do you get a website back up, when it goes down?
🕑Jun 03, 2019 🖋John Locke
💬0
Is your host a single point of failure?
Just ran across a sad story where Digital Ocean is accused of killing a startup:
Add new comment