SFTP and FTPS as secure upload paths in web hosting
Summary
Manuel Schmitt points out that web hosting customers have been able to transfer files via SFTP or FTPS instead of unencrypted FTP for some time. On 26 October 2016, SFTP and FTPS had already been available for a while. Both methods were used for uploads to web hosting packages.
Ideas
- SFTP and FTPS protect credentials and payload data during transfer.
- Both methods achieve the same goal with different protocol stacks.
- An existing security feature helps little as long as documentation and customer advice are missing.
Insights
- Secure standards must not only be available but be made the obvious path.
- Similar names hide considerable operational differences between SFTP and FTPS.
Facts
- That day, support was also documented on the website.
Recommendations
- Disable plain-text FTP as soon as legacy clients have been replaced.
- Document ports, host keys or certificates and passive data connections.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.