Hacker News new | ask | show | jobs
by tzs 5000 days ago
Verified. The credit card submission just does an AJAX transaction, over plain HTTP, to 37.46.127.180. My tcpdump revealed my plain fake credit card details sailing over the wire completely unencrypted.

I've dropped a note to RapidSSL about this.