M
Martin
Hi all,
We have an administrative application that we are considering to rewrite in
aspx with vb2005. I think the marketing possibilities are enourmous.
In our standard app, the user logs in by entering his/her user name and
password. In the online version that would be Client ID / user ID /
Password. So far so good. But I'm just wondering... how secure is this? I
guess not very. Every disgruntled employee can go online at home enter their
name and password and do whatever they like.
Now for clients with a fixed IP address I can check the IP-address as a part
of the authentication. But what if my client has a dynamic IP-address?
I would love to hear your thoughts on this matter,
Thanks,
Martin
We have an administrative application that we are considering to rewrite in
aspx with vb2005. I think the marketing possibilities are enourmous.
In our standard app, the user logs in by entering his/her user name and
password. In the online version that would be Client ID / user ID /
Password. So far so good. But I'm just wondering... how secure is this? I
guess not very. Every disgruntled employee can go online at home enter their
name and password and do whatever they like.
Now for clients with a fixed IP address I can check the IP-address as a part
of the authentication. But what if my client has a dynamic IP-address?
I would love to hear your thoughts on this matter,
Thanks,
Martin