We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

website taking cc details on unsecure page

I found a site that takes cc payments using an unsecure page, looks like just a standard html form with no security certificate, while it states in big letters that it's a secure page
(not using it myself, as I bumped into it by chance while looking for something else).

what is the quickest way of getting them out of action? excluding the ICO because when I contacted them a while back they said I needed to contact the other party myself first and wait for a month before they did anything.
«13

Comments

  • earthstorm
    earthstorm Posts: 2,134 Forumite
    I found a site that takes cc payments using an unsecure page, looks like just a standard html form with no security certificate, while it states in big letters that it's a secure page
    (not using it myself, as I bumped into it by chance while looking for something else).

    what is the quickest way of getting them out of action? excluding the ICO because when I contacted them a while back they said I needed to contact the other party myself first and wait for a month before they did anything.

    ICO wont do anything as technically their is no law saying the payments need to be placed on a secure page.

    i.e. they may have a std HTML page where you add your details etc, and a pay here button that directs to somewhere like Paypal.
    It is paypal that needs to be secure and PCI compliant as they are the ones actually taking the money.

    although the cost of a dedicated IP ( £2 a month) and SSL certificate from £5 a year is nothing to secure a site.

    The ICO will only do something if the business is not registered under the Data Protection Act and then all they will do at first is contact the business owner with a copy of their booklet and application form for them to join with their £35 fee
  • Nilrem
    Nilrem Posts: 2,565 Forumite
    Part of the Furniture 1,000 Posts
    It is worth noting that you can have a secure frame within a webpage - one of the most common payment interfaces for a lot of smaller stores uses (or used to use*) a java app within a frame.
    It was secure, but didn't show as https or a padlock in most browsers as it was only the payment area of the page (a little like th VBV/Securecode window), that was actually secured as that was the area where the information was entered.



    *Not sure if it still does, I can't remember seeing it for a while.
  • earthstorm
    earthstorm Posts: 2,134 Forumite
    Nilrem wrote: »
    It is worth noting that you can have a secure frame within a webpage - one of the most common payment interfaces for a lot of smaller stores uses (or used to use*) a java app within a frame.
    It was secure, but didn't show as https or a padlock in most browsers as it was only the payment area of the page (a little like th VBV/Securecode window), that was actually secured as that was the area where the information was entered.



    *Not sure if it still does, I can't remember seeing it for a while.
    not seen one of them for years, they went out when SSL become coppers to get and when you could just add a Paypal/Nochec.Google Checkout payment button on your site then you are not taking the payments and some people think this is the only reason for secure pages.
    As a webhost i would be worth millions if i have £1 for evertime i have informed clients that ssl secure pages are needed on pages where customers add any of their details and not just on the payment pages.
  • terra_ferma
    terra_ferma Posts: 5,484 Forumite
    They don't take Paypal, just cards. It's just a simple form with a submit button.
    Didn't realise taking cc details on an unsecure page is allowed, but this site states secure online payment, so it's misleading.
  • browneyedbazzi
    browneyedbazzi Posts: 3,405 Forumite
    I've been Money Tipped!
    Is the site for a UK business or is the business based abroad?

    If the site is for a business based in the UK then the misleading claim that it offers secure online payment can be reported to the ASA which will be able to make them remove that claim.
    Common sense?...There's nothing common about sense!
  • arcon5
    arcon5 Posts: 14,099 Forumite
    Part of the Furniture 10,000 Posts Combo Breaker
    I'm betting they are breaching their merchant accounts T&Cs. Many now charge fees for non-compliancy.
  • corbyboy
    corbyboy Posts: 1,169 Forumite
    Part of the Furniture
    How certain are you that the details are being submitted into an unencrypted page? The page that contains all the boxes for you to fill in doesn't need to be secure, just the page that the information is submitted to.

    Let us know the site and we can look at it.
  • earthstorm
    earthstorm Posts: 2,134 Forumite
    corbyboy wrote: »
    The page that contains all the boxes for you to fill in doesn't need to be secure, just the page that the information is submitted to.

    Let us know the site and we can look at it.


    No thats wrong. ANY page where your personal details are added MUST be secure. you seem to be someone that thinks its just the actual payment page that needs to be secure.

    The payment page needs to be Secure and PCI Compliant, this is why most ecommerce sites direct payments to a 3rd party site like paypal/worldpay etc. as PCI Compliance is a long complicated and expensive process. But if you have a page that takes down customers details (name/address etc.) then this must be secure.

    Yes if we have the site details then we could check this out
  • corbyboy
    corbyboy Posts: 1,169 Forumite
    Part of the Furniture
    earthstorm wrote: »
    No thats wrong. ANY page where your personal details are added MUST be secure. you seem to be someone that thinks its just the actual payment page that needs to be secure.

    The payment page needs to be Secure and PCI Compliant, this is why most ecommerce sites direct payments to a 3rd party site like paypal/worldpay etc. as PCI Compliance is a long complicated and expensive process. But if you have a page that takes down customers details (name/address etc.) then this must be secure.

    Yes if we have the site details then we could check this out

    I am not saying you are wrong, but why is this the case? In what way would that be insecure?
  • CC-Warrior
    CC-Warrior Posts: 323 Forumite
    Let us take a look at this site..
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.9K Banking & Borrowing
  • 254.3K Reduce Debt & Boost Income
  • 455.2K Spending & Discounts
  • 246.9K Work, Benefits & Business
  • 603.5K Mortgages, Homes & Bills
  • 178.3K Life & Family
  • 261.1K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.