Home  |  Forums  |  914 Info  |  Blogs
 
914World.com - The fastest growing online 914 community!
 
Porsche, and the Porsche crest are registered trademarks of Dr. Ing. h.c. F. Porsche AG. This site is not affiliated with Porsche in any way.
Its only purpose is to provide an online forum for car enthusiasts. All other trademarks are property of their respective owners.
 

Welcome Guest ( Log In | Register )

> AutoAtlanta, just a suggestion
stateofidleness
post Jun 11 2008, 11:10 PM
Post #1


Senior Member
***

Group: Members
Posts: 810
Joined: 1-September 07
From: Canyon Lake, Texas!
Member No.: 8,065
Region Association: None



Just made my first order with AutoAtlanta and noticed that, once you go to checkout, for new customers where you fill out your Shipping and Billing as well as credit card info, the page is not a secure page??

So.. I would advise that if you are making a purchase with them, add an "s" after the "http" in the address bar before filling out the form.

computer security major... kinda bugs me when i see stuff like that... so just a heads up

maybe the AA webmaster can fix this (IMG:style_emoticons/default/wink.gif) would take all of 2 seconds

anyways, can't wait to get the stuff!!
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
 
Reply to this topicStart new topic
Replies
Jason.H
post Jun 12 2008, 01:57 PM
Post #2


Newbie
*

Group: Members
Posts: 16
Joined: 22-November 05
From: Marietta, Ga
Member No.: 5,168



QUOTE(stateofidleness @ Jun 12 2008, 08:33 AM) *

Wow jason, thanks for the fix.
I think by not being an SSL page when entering the information leaves it susceptible to being spoofed more easily? Because, someone won't know they're "secure" until they hit submit might deter some people. It would be harder to spoof an ALREADY SSL encrypted page than it would be to spoof the current page.

Just throwin that out there, but awesome turn-around.

OT: hey jason, do ya'll have company stickers or logos? I like to show support for who is aiding me in this addiction lol



No problem. Any time you come across something that seems odd, or you have a question, you can let me know directly: jason<!at!>autoatlanta.com

Generally SSL is more for sniffers than spoofing. Spoofing would be if someone got you to go to a malicious website designed to look like ours with the intent of collecting your information. Anyone with a few bucks can have an SSL set up so having https won't make much difference. Heck, when was the last time you inspected the security certificate issued by the server?

Sniffers are designed to pull packets from the network for inspection. The packets carry the information you filled into the form. A secure connection encrypts the transmission so that anyone listening in can't tell what's being said, at least that's the idea.

Again, the transmission has always been encrypted, I just made it a bit more obvious.

I'm not sure if we have much in the way of stickers. I'll see if I can dig something up, otherwise I'll put it in the suggestions box.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Posts in this topic


Reply to this topicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 



- Lo-Fi Version Time is now: 9th July 2025 - 12:03 PM