• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 197
  • Last Modified:

Secure forms

I am working toward securing personal health information submitted by users in a form and processed by a PHP script which mails it directly to my web site customer (doctor) as an email.  There will be no storage of this info on the server.  I am working on SSL from the server to my doc's office but am concerned that if using the https:// route for client to server will be sufficient to prevent info theft.  I understand that packets are routed differently, rendering sniffer useless enroute and if the remote server is compromised they would have root and it would be moot (whoops, accidental poetry). So the only route I am in question about is from the user to the server. But any alternatives or known problems would be helpful.   Thanks.
0
insouciant
Asked:
insouciant
  • 2
1 Solution
 
maUruCommented:
https:// is more than enough for client to server encryption

if it wasnt then online banking systems would all go bankrupt

you cannot really encode it yourself as http is a plain text protocol, using ssl, you get 128 bits of encryption, which would roughly take by todays standards 1 million years to crack

which is long enough....i think
0
 
maUruCommented:
of course there are other factors that you must take care of:

1. making sure the 'back' button doesnt return to the form and causing the browser to autofill the previous fields
2. make sure no sessions are used that can be duped by a knowledgable hacker
3. using ssl /before/ a login script is used
4. make sure secure passwords are used, minimum 8 characters, include a number or two and some capitals and an asterix....the weakest link in security is usually the users themselves.
0
 
insouciantAuthor Commented:
Thanks for the very complete answer maUru.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now