We’d like to remind Forumites to please avoid political debate on the Forum.
This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide
Call 18866 POTENTIAL SECURITY HOLE!
Comments
-
Thanks for the support !ericpode wrote:If I understand your description correctly then he is not wrong.
SSL (used by browsers when the address begins with "https") is an end-to-end encryption scheme which means that the data remains encrypted from the browser to the end server. This means that the entire request be it a GET or POST is encrypted including the request URL which appears in the first line of the request message.
Having said that I don't think it's such a good idea to have details such as this in the query string of the URL because it can cause this sort of confusion to users.To infinity and beyond!0 -
spook wrote:I've just gone through the process myself and I can confirm that the site does use the secure https protocol. So there's no risk of your card details being seen by anyone else. As ericpode says, the request URI is also sent encrypted, so there's really no problem.
THis means that the transaction is secure when it happens - but is everyone here 100% sure that there url history is secure - I understood this was one of the easiest bits of information to fish for?I think....0 -
Always use a firewall !michaels wrote:THis means that the transaction is secure when it happens - but is everyone here 100% sure that there url history is secure - I understood this was one of the easiest bits of information to fish for?To infinity and beyond!0 -
michaels wrote:THis means that the transaction is secure when it happens - but is everyone here 100% sure that there url history is secure - I understood this was one of the easiest bits of information to fish for?
True - I've just checked my history out of interest and the URL containing my credit card details is still there! (Firefox browser)
(It's a fairly simple matter to delete your URL history, which is what I'll be doing now
)mike_paterson wrote:Always use a firewall !
And an up-to-date virus scanner.
And keep your operating system up to date.
And your browser.
:rolleyes:0
This discussion has been closed.
Confirm your email address to Create Threads and Reply
Categories
- All Categories
- 353.6K Banking & Borrowing
- 254.2K Reduce Debt & Boost Income
- 455.1K Spending & Discounts
- 246.6K Work, Benefits & Business
- 603K Mortgages, Homes & Bills
- 178.1K Life & Family
- 260.7K Travel & Transport
- 1.5M Hobbies & Leisure
- 16K Discuss & Feedback
- 37.7K Read-Only Boards

