TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Sundance asks for credit card info without SSL, says it has SSL anyways

4 pointsby magic5227over 12 years ago
http://www.sundance.org/festival/tickets/registration/<p>Just bothers me that companies can get away with this given the recent history with Sony etc getting hacked.<p>http://www.box.com/shared/vdqv03hfgxri5ocreohz

2 comments

boksioraover 12 years ago
Not quite true...<p>If you noted your order is processed inside an &#60;iframe&#62; element which is secured with https to <a href="https://webtix1.sundance.org/WebTixsNet/OrderFormPage.aspx?dtticks=634878250741441833" rel="nofollow">https://webtix1.sundance.org/WebTixsNet/OrderFormPage.aspx?d...</a>
评论 #4754302 未加载
magic5227over 12 years ago
actually "false, I checked that already. the iframe src is <a href="http://webtix1.sundance.org/webtixsnet/?key=RegPublic-PITW" rel="nofollow">http://webtix1.sundance.org/webtixsnet/?key=RegPublic-PITW</a> the form's action is "OrderFormPage.aspx?dtticks=634878773966587077" which means that the form submits to <a href="http://webtix1.sundance.org/webtixsnet/OrderFormPage.aspx?dtticks=634878773966587077" rel="nofollow">http://webtix1.sundance.org/webtixsnet/OrderFormPage.aspx?dt...</a><p>so the iframe isn't ssl, and the form doesn't submit to an SSL page either.<p>furthermore! even if the iframe were over ssl (which it isn't), that still wouldn't be secure. since the outer page isn't over ssl, an attacker could replace the iframe with one that has the same content but points to a non-ssl page. this is why SSL is useless unless the user checks the browser SSL indicator (the green lock in the URL bar)."