4 ms·
Technically, no. The payment happens within an iframe secured with https: https://www.simplegoods.co/embed/PKGTEISN https://www.simplegoods.co/embed/PKGTEISN
by sync 13y ago
Technically, no. The payment happens within an iframe secured with https: https://www.simplegoods.co/embed/PKGTEISN https://www.simplegoods.co/embed/PKGTEISN
- DaCapoo 13y agoThe issue with it however is that the initial page is delivered over an insecure connection, which allows any part of it to be modified in the usual MITM style. Nothing prevents an attacker from changing the link that is served to the client with something else that looks like that payment system and functions the same, but logs the payment information. There's a reason Firefox now disallows mixed HTTP/HTTPS content by default[0] [0] - https://blog.mozilla.org/tanvi/2013/04/10/mixed-content-blocking-enabled-in-firefox-23/ https://blog.mozilla.org/tanvi/2013/04/10/mixed-content-bloc...
- throwaway125 13y agoIn other words: yes, it's vulnerable to SSL stripping.
- jafaku 13y agoIf the main page is insecure, then everything is insecure.