Re: OT, security of non-https transaction



Dave wrote:
I want to order some software via the net.
I click Pay, and get connected to the vendors web site.
I trust the person running the site (for reasons not worth going into). However
that site uses http (not https). The page I am asked to complete **includes my
credit card details!**

Anyone tell me what I am missing here?
Thanks

A link to the website in question would help, but I'll see if the crystal ball is working today...

An SSL certificate is fairly expensive for an individual or small business, so many people use an alternative method of accepting credit card details. One is to take the order details over an insecure link and then forward the user to a payment portal over an HTTPS link. This sounds like it isn't the method being used in your question, however.

An alternative method offered by some 'shopping cart' software (and one I have seen used in three or four online stores) is to have an IFRAME within the page which loads a javascript applet. This applet connects to the payment portal via HTTPS (or an SSL encrypted stream of some sort, usually with a self-issued certificate) invisibly to the user (i.e. you'll still see an unsecured HTTP connection in your address bar). This method has become somewhat unpopular in these days of phishing, but some sites still stick with it.

As I say, without visiting the site in question we (TINW) can offer limited advice.

--
Gareth Halfacree
http://gareth.halfacree.co.uk
.



Relevant Pages

  • Re: Outlook wont connect locally when configured for HTTP
    ... the lan it connects via RPC over HTTPS perfectly. ... HTTPS connection it fails because our firewall won't allow an internal ... starts up the laptop until he can actually start working. ...
    (microsoft.public.windows.server.sbs)
  • Re: Issue with IE 6 on XP Home SP2.
    ... state would suppress that or at least change your symptom in some ... are you using the check for https: ... will be less informative than for a regular http: connection. ... > trusted sites and turned on the Windows firewall. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: RPC over HTTPs
    ... and I did make the changes in the registry. ... on the server told me that store.exe was not actually listening on port 6001 ... THAT will break RPC over HTTPS for sure. ... I can see the 'mail' connection tries to ...
    (microsoft.public.exchange.connectivity)
  • Re: cannot login to support.microsoft.com page
    ... HTTP, HTTPS, FTP connectivity ... connection with the server was reset ... info HTTP: Successfully connected to www.microsoft.com. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Cant connect to internet after reboot
    ... How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com ... info HTTPS: Successfully connected to www.microsoft.com. ... Wireless - User SSID ... info Using home Internet connection ...
    (microsoft.public.windowsxp.network_web)