[Zope-dev] Security is Hard (was Import from upload?)

Phillip J. Eby pje@telecommunity.com
Mon, 05 Jun 2000 15:39:19 -0500


At 12:05 PM 6/5/00 -0400, Evan Simpson wrote:
>
>Security is hard :-/
>

No kidding.  And just think, all the hard stuff that's been done to avoid
trojans in a portal-ish site can be defeated simply by a user making a page
that looks like the portal's login screen and asking the user to "verify"
their password before accessing the "secure content" at that location...