4 ms·
Yep, although the form posts to a secure URL: https://api.stripe.com/v1/tokens https://api.stripe.com/v1/tokens
by daw___ 11y ago
Yep, although the form posts to a secure URL: https://api.stripe.com/v1/tokens https://api.stripe.com/v1/tokens
- Gurrewe 11y agoDoesn't make it better tough, a MITM could change the action URL of the form.
- staticfish 11y agonot if it's pinned at the web app level.
- tyre 11y agoAgain, MITM. If you mean the front-end web (JS) app, MITM the request from the server to the client browser and replace the hardcoded submission url in the JS.
- staticfish 10y agoNot really. I used Play Framework which is also its own webserver. SSL is at both the app and webserver level.
- jgalt212 11y agoMITM requires a man in the middle. For the most part, a state level adversary is required for a generalized MITM attack.
- megabytemike 11y agoCome join my wifi network at the coffee shop :-D
- jgalt212 11y agoYes, but that's not a general MITM attack as the NSA has pulled off. Only the folks at that particular coffee shop are placed at risk from this particular adversary.
- ryanbertrand 11y agoUsually Stripe throws warnings into the console for using their JS lib while on a HTTP site.
- ataylor32 11y agoSee http://www.troyhunt.com/2013/05/your-login-form-posts-to-https-but-you.html http://www.troyhunt.com/2013/05/your-login-form-posts-to-htt...