Home > Ask the Security Experts > Platform Security Questions & Answers > The pros and cons of FTP over SSL
Ask The Security Expert: Questions & Answers
EMAIL THIS

The pros and cons of FTP over SSL

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 30 December 2005
We have a requirement to receive files (25-40 mb a piece) from a variety of hosts. Currently, time is of the essence. What, if any, risks do we take by having the hosts send PGP-encrypted files to an existing FTP site versus building an ad hoc FTP server on an Aptiva (200 mhz) running Redhat Linux 7.0 and using SSL?

>
EXPERT RESPONSE
You face two problems when you send or receive files to an FTP server. The first is securing files while they are uploading, and second, how to keep them secure while they sit on the FTP server while you wait for the recipient to download. Your second option --creating an FTP server that supports SSL --would allow your hosts to upload the files using an FTPS (FTP over SSL) connection. This would involve the use of an SSL layer below the FTP protocol to encrypt the control and data channels. An alternative to FTPS is the Secure File Transfer Protocol (SFTP), which uses the SSH file transfer protocol to secure an FTP connection from client to server.

However, the problem you have with FTPS and SFTP is although the files are securely transferred to your server, once they're uploaded, anyone who accesses the server can see them, because they aren't encrypted. With this in mind, I prefer your first solution, which is to have your hosts encrypt the files using the recipients public PGP key. This option not only ensures the files are encrypted while in transit, and when at rest, but also only the intended recipient can decrypt and view the files. The best solution to your problem, however, is probably a combination of both PGP-encrypted files and a secure FTP connection. Because even if your PGP encrypted files are secure, if your hosts use plain FTP to upload files to your server the username and password used to access the server are sent in the clear. An attacker could potentially steal this information and use it to gain access to the FTP server and upload malicious files or delete existing files.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Platform Security
Is attack code valuable for vulnerabilities or just a publicity stunt?
Will the features of Windows Vista SP1 encourage wider adoption of the OS?
Is a Master Boot Record (MBR) rootkit completely invisible to the OS?
Are open recursive DNS servers inherently insecure?
Should whole disk encryption products be used with data backup software?
Which operating system can best secure an FTP site?
Is desktop virtualization a realistic enterprise option?
Does FTPS encrypt data packets at the hardware or software level?
Should disks be encrypted at the hardware level?
Is Triple DES a more secure encryption scheme than DUKPT?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts