Firefox gets complaint for labeling unencrypted login page insecure
arstechnica.com
arstechnica.com
Could we un-dupe it?
> You are not authorized to access bug 1348902. To see this bug, you must first log in to an account with the appropriate permissions.
0. http://www.oilandgasinternational.com/SSL_Subscribe/subscrib...
It's a risk roughly equivalent to speaking on the phone to a hotel registry and giving them your CC#, or a car rental agency. And in that case, at least one other person now has your number (and that's besides all the other people that already have the numbers and those that handled the card in your absence, waiters in restaurants and so on).
Credit Cards working without something along the lines of VBV is a bug, not a feature and the fact that 'just a number' is worth money is where the real problem lies, not in how it got transmitted, that's just a reduction of the risk, not an elimination.
All that said there is absolutely no excuse why they should not use HTTPS, and it also makes you very wary of doing business with this party at all, likely their other security sucks.