Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just a heads up, you and your clients are taking credit card information over unencrypted HTTP.

Here are two examples of clients that are accepting credit card info over plain HTTP: http://vox-hotels.com/ http://www.sonnseit.at/



Hey thanx for pointing that out. The booking tool is actually tied in via https and the transmission back to the system happens via https. I need to pester my clients to set up the cert for their domain. I will also the insert a another step in the dialogue - to collect that info.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: