Hacker News new | ask | show | jobs
by rplnt 4462 days ago
I hope you don't mind some feedback. The LEARN MORE button is visually broken (I assume). When I want to learn more I don't actually learn more. I really have no idea how your service works. Then there is the issue of non-existing SSL which is a big no (even though it might not be needed for this service) for any kind of payment provider. And of course the twitter login. Though I understand you don't want to mess with your own account system.
1 comments

SSL is unnecessary for accepting Bitcoin payments, there's no reason at all for SSL to be used on this site.
What if I MITM the site and replace the seller's address with mine?
that typically would be a concern, but our first version is built only with a Coinbase integration, and all payments are handle through their merchant services and their payment iframes. Once we implement our own payments we will have to handle this appropriately.
What if I replace the iFrame URL with an URL of a cloned page? How can the user be sure that it's really Coinbase's form?