Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Their is a login form on the website on a page without HTTPS. You should change that.


Also, no HTTPS when you are supposed to enter the credit card details. This stopped me from buying the logo.


Actually it is an iframe with https (using stripe)


But if the host traffic is compromised you can serve malicious payment gateways/forms.


If the host is compromised HTTPS isn't going to save you.


it will if it's the host /traffic/ that is compromised




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: