3 ms·
It is, although Stripe does only use https. When you post that form stripe.js captures the form submission and submits to its server, returning instead some tok
by heelhook 13y ago
It is, although Stripe does only use https. When you post that form stripe.js captures the form submission and submits to its server, returning instead some tokens to identify the charge, so what is submitted through http is actually just a mostly worthless token (assuming that the credentials for the app are secure).
I'm not disagreeing with you, but the site running on https only is important in the context of the user not being thrown away by the lack of https, sensitive information is only transmitted through https.
- smilliken 13y agoThere's more to it than that, re-read jackowayed's comment. Man-in-the-middle attacks are a real threat that should be considered.
- aaronblohowiak 13y agoYou don't know (as a normal user) that the submission is going to go to Stripe with any high degree of certainty. Someone MITMs the plain http form and changes it to direct the cc info to a malicious server.