Suggestion: Secure file upload

Discussion in 'Suggestions and Feedback' started by apo, Jun 16, 2005.

  1. apo

    apo

    I am new to discount ASP.net and I am pretty impressed with your hosting package/price. I also see a lot of ongoing improvements from what I see on this forum. On the website you alsoexhibits a very (physically) secure datacenter that can combat bullets, earthquakes, fires, and power outages. However, I think something is missing here. We are still uploading our files through FTP, with passwords sent in vulnerable clear text. We also don't want to risk letting peoplegrabbing our asp.net source codes while it is being transferred to the web server. I noticed that backin 2003 someone asked about this issue, but it has not been addressed yet.

    I understand that Windows 2003 and IIS 6 does not come with SFTP capability, so it might be more trouble to support that feature. Thereare War_FTP (free)and Serv-U, which are good 3rd party FTP servers that support SFTP. OpenSSH (free) or SSH Secure Shellwould also be good and enable SCP access (file transfer is all that matters).

    I think you can add significant value to your product with a very small cost.
     
  2. Bruce

    Bruce DiscountASP.NET Staff

    THank you for your suggestion.

    This is much harder to implement that most would think. Our hosting system is tightly intergrated with Windows and switching FTP server require us to make major tweak to the hosting architecture.

    Bruce

    DiscountASP.NET
    www.DiscountASP.NET
     
  3. Bruce

    Bruce DiscountASP.NET Staff

    We are hoping that MS IIS 7.0 would include sFTP

    Bruce

    DiscountASP.NET
    www.DiscountASP.NET
     
  4. Does this mean that secure transfer isn't on the docket at all or just not right now? Also, do you have any plans for anything similar to rsync such that updates and/or backups would be easier/less bandwidth intensive?
     

Share This Page