Hacker News new | ask | show | jobs
by paulgb 4885 days ago
Just a heads up, you and your clients are taking credit card information over unencrypted HTTP.

Here are two examples of clients that are accepting credit card info over plain HTTP: http://vox-hotels.com/ http://www.sonnseit.at/

1 comments

Hey thanx for pointing that out. The booking tool is actually tied in via https and the transmission back to the system happens via https. I need to pester my clients to set up the cert for their domain. I will also the insert a another step in the dialogue - to collect that info.