Basic point that Web service security is not going to solve the security problem. I think every body understands that, WSS will solve authentication and authorization. For rest of the things like
- Validate your input
- Set size limits on your incoming data
- Ensure the attachments do not have any "viruses", etc.
No comments:
Post a Comment