In advance, I apologize for the long post. This is not an arduino issue per se, as everything is working properly, rather, I am seeking advice. I have basically an Iot server running on a mega w/ethernet shield, connected to a 4G router to monitor/control a remote solar power system. Everything works as it should, but I have 2 areas of concern, one is security. I'd like to password-protect the server. A hacker can't really cause too much trouble, but could be annoying, so it's not like I'm protecting Ft. Knox, but a problem foreseen is a problem solved, as they say.
The second area of concern is that I'd like to limit server access to one user at a time, since 2 users can contradict each other and cause a nuisance. I can probably figure this one out eventually....
I am thinking of switching to a W32 eth01, but would rather stay with the mega if I can.
Back to security, as an experiment, I added a virtual number pad, and request the user enter a PIN before commands are revealed, and it works well, but being an HTML novice, I don't know how secure it really is. I do know a man-in-the-middle attack would reveal the PIN, but I figure a hacker would not expend that much effort on such a trivial return....maybe I'm mistaken?
Thoughts or advice welcome. TIA.