We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Call 18866 POTENTIAL SECURITY HOLE!

2»

Comments

  • ericpode wrote:
    If I understand your description correctly then he is not wrong.

    SSL (used by browsers when the address begins with "https") is an end-to-end encryption scheme which means that the data remains encrypted from the browser to the end server. This means that the entire request be it a GET or POST is encrypted including the request URL which appears in the first line of the request message.

    Having said that I don't think it's such a good idea to have details such as this in the query string of the URL because it can cause this sort of confusion to users.
    Thanks for the support !
    To infinity and beyond!
  • michaels
    michaels Posts: 29,449 Forumite
    Part of the Furniture 10,000 Posts Photogenic Name Dropper
    spook wrote:
    I've just gone through the process myself and I can confirm that the site does use the secure https protocol. So there's no risk of your card details being seen by anyone else. As ericpode says, the request URI is also sent encrypted, so there's really no problem.

    THis means that the transaction is secure when it happens - but is everyone here 100% sure that there url history is secure - I understood this was one of the easiest bits of information to fish for?
    I think....
  • mike_paterson
    mike_paterson Posts: 1,473 Forumite
    Part of the Furniture 1,000 Posts Photogenic Combo Breaker
    michaels wrote:
    THis means that the transaction is secure when it happens - but is everyone here 100% sure that there url history is secure - I understood this was one of the easiest bits of information to fish for?
    Always use a firewall !
    To infinity and beyond!
  • spook
    spook Posts: 233 Forumite
    michaels wrote:
    THis means that the transaction is secure when it happens - but is everyone here 100% sure that there url history is secure - I understood this was one of the easiest bits of information to fish for?

    True - I've just checked my history out of interest and the URL containing my credit card details is still there! (Firefox browser)

    (It's a fairly simple matter to delete your URL history, which is what I'll be doing now :))
    Always use a firewall !

    And an up-to-date virus scanner.

    And keep your operating system up to date.

    And your browser.

    :rolleyes:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.6K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 603K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.