4 ms·
>throwing PCI compliance and SSL encryption out the window If they were using Stripe or similar, then they don't have access to your credit cards. Only the las
by SomeCallMeTim 11y ago
>throwing PCI compliance and SSL encryption out the window
If they were using Stripe or similar, then they don't have access to your credit cards. Only the last four digits and expiration.
- danhak 11y agoHow bout the part where they're sending expiration date and last 4 digits over http?
- __P 11y agoThat isn't secure information... Emails often contain that info, which is kind of worse than HTTP.
- slantedview 11y agoBut it is secure information. If I recall, last 4 digits were part of how the CIA chief's e-mail was hacked recently.
- SomeCallMeTim 11y agoNo, it's not secure information. Any time you use last-4 as something secure, you're doing it wrong. As mentioned above, last-4 is sent by email frequently, and email passes, unencrypted, through intermediate servers all over the Internet. Any compromised host can observe all of the email that passes through it. Any process that uses last-4 to unlock a password or otherwise as a secure token is broken by design.
- CamperBob2 11y agoAny time you use last-4 as something secure, you're doing it wrong. It's not a question of what I use those digits for, it's a question of what everyone else uses them for.
- manigandham 11y agoYet without HTTPS anyone changing or entering new credit card info is at risk on this site. There's also personal information like where to find spare keys and stuff; it should be a lot more secure than this.
- SomeCallMeTim 11y agoStripe won't let you submit a credit card except through their form, which will be submitted through https. Not defending the rest of the site. Just pointing out what I felt was not a problem. There are plenty of problems to go around, though.