Is ServerXMLHTTP secure?
We used ServerXMLHTTP to send https POST for credit card processing. Recently, one of our users had an issue causing an "Internal error in Microsoft Windows HTTP Services" error. The issue was resolved by updating IE. The user now claims that our use of "Internet explorer dll's" is a security issue. Of course I know the problem is with MS XML core services. So my question is, is it safe to use MS XML core services, especially the ServerXMLHTTP object for sending https POSTs?
As much as I dislike this kind of thing, since you are dealing with a user's credit card, it might be wise to prevent them from sending their information to overly outdated browsers. This will prevent such senarios in the future, helping to protect you from potential litigation and will have an additional impact on protecting your users, your site, and other users.
In my experience with IT for several years, the most important thing you can do to protect your computer is to update it - far more important than protecting against antivirus or firewall.
* Obviously they are still very important, don't get me wrong.
a source to share
ServerXMLHTTP uses WinHTTP (not IE dll), which for SSL in turn uses Windows services to create a secure socket. You may also ask, "Are protected windows safe?" I'm not sure how far away from the network stack code in other browsers, but I suspect many of them still rely on the underlying operating system for this service level.
It's safe? Of course, answering yes will bring up stories or examples where this is not the case. How secure is it (conditionally on a client machine that hasn't been compromised in some way)? Yes.
a source to share