4 ms·
If you view-source, you will notice that they are using stripe.com. This is actually a clever trick in that the form is intercepted by javascript, securely tran
by hax0r2112 14y ago
If you view-source, you will notice that they are using stripe.com. This is actually a clever trick in that the form is intercepted by javascript, securely transmitted to stripe for processing, then a token is returned to the calling web site with success codes, etc needed for future billing questions, refunds, etc. The issue is that we have (rightfully so) trained people to look for the lock icon, look for https, look for the green location bar, ... Stripe goes a long way in protecting the transaction and reduce the merchant's PCI-DSS scope (really important for small merchants and large alike...), but merchants must still convince their customers that the site the customer is interacting with is safe to deal with.
- mikeash 14y agoIt's more secure than transmitting the data in the clear, but still not really secure. A MITM could trivially rewrite the form to steal your data when submitted, and the user wouldn't be able to tell unless they inspected the source.