Remote MySQL Connections - security implications

Tiger Technologies: Remote MySQL Connections: "Unfortunately, remote access to MySQL is not very secure. When your remote computer first connects to your MySQL database, the password is encrypted before being transmitted over the Internet. But after that, all data is passed as unencrypted 'plain text'. If someone was able to view your connection data (such as a 'hacker' capturing data from an unencrypted WiFi connection you're using), that person would be able to view part or all of your database.

In particular, never store any sensitive data such as credit card numbers in unencrypted format within the database. Such data should always be encrypted, even if it's never going to be transmitted over the Internet. Encrypting the data will ensure that it stays confidential even if the raw database file is ever stolen or compromised."

About this entry

