RE: [split] MyPlus! Logs Security
They'll have to rewrite stuff on the server-side if they add encryption. Yes, you could easily use client-side encryption which Plus! already has and upload .ple files. But those files will still have to be decrypted somewhere at some point for the online logging feature to be useful. Decrypting files server-side wouldn't be very sufficient since then decrypted files will still reach the server, how much security does that actually add? The good way to do it IMO is perform both encryption and decryption client-side. Why they didn't add something like that already? Who knows. But Jieff did say they are considering adding encryption to online logging in the future. I rather see them taking some extra time to do it right than doing it in a way which doesn't really add much extra security in the first place.
|