Re: How to securely transfer a text file to site owner?
| From: | Chris Adams | Date: | Thu, 03 Aug 2000 01:42:09 +0000 |
| Subject: | Re: How to securely transfer a text file to site owner? | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-9858@lists.php.net to get a copy of this message | ||
> I've considered several possibilities, such as putting the text file into
a
> password-protected ZIP archive before emailing it, but haven't come up
with
> a solution that I feel is sufficiently simple but still secure.
How about having them pull the page down using SSL? This could be automated
using a tool like cURL. It would have the advantage that you could configure
the server to only respond to requests from a certain IP address and the
data would never leave the server until they were ready to handle it.
However, my preferred approach would be public key encryption. You've got a
classic case since incoming data can be encrypted with a public key on the
server and decrypted with the private key on their end. This has the
advantage of remaining secure if someone breaks into your webserver, since
they still won't be able to retrieve old data since, by definition, you
could post the encrypted data on the homepage and be safe as long as nobody
else had a copy of the public key.
As far as implementing this in PHP goes, you could execute something like
pgp or see if the rumored extension featuring the OpenSSL libraries is
actually happening (if not, I'll need to scare up the CFT to do it myself).
Chris