Yes, SSL is better

But as I noted, there are many different levels of solution, and one that forces all sites that take passwords to go to SSL is quite a high level of change. You can't thrust that on the net all at once.

If you're going to go to that level, requiring changes at half the sites on the net, you might as well do a number of better changes. And are you going to force every site to buy an "official" cert? Or will there be free certs, or self-signed certs? If you make self-signed certs the norm, you are losing the benefits of authentication because now people don't notice them. Self-signed certs are useful, for starting up encryption and internal use, but they provide no auth the first time.

Reply

Please enter Brad's last name above. Case doesn't matter
Please make up a name if you do not wish to give your real one.
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.

More information about formatting options