Educause Security Discussion mailing list archives

Re: Secure file transfers


From: Harrold Ahole <madman () MYEASTSIDE COM>
Date: Mon, 7 May 2007 10:07:29 -0700

SFTP and SCP may suffer from bad passwords, but that's not a function of
those tools, but of users.  All password based systems are thus equally
bad, but that's absurd as PINs and passwords are the de facto user
authentication scheme no matter how much security gurus lambaste them.

SCP can be configured to only allow public key crypto logins, so it
allows for greater security.  Unlike FTP, SCP is secure end-to-end,
including the password handshake.

Of course, there are web services out there that allow for secure file
transfers (secure messaging and the like), but they cost money
naturally.  The upside is you can do the transfers without requiring
people have/use SFTP/SCP, something few people would have available.
I've used Yozons and found it worthwhile, but it's also password-based
authentication, so if that's the stumbling block, then you can forget it.

Harrold

Current thread: