A few months ago, I was at a round table luncheon with a few senior-level security and IT folks. I casually asked them what they were doing to secure their Web applications. They replied with full confidence, “We have SSL.” When I described, in detail, how hackers attack via Web applications, and how SSL doesn’t protect them against those attacks, they were shocked. I can understand that small website owners might not have an in-depth knowledge of security issues. But,...

