Maybe naive, but that's a showstopper for me.
Maybe naive, but that's a showstopper for me.
https://twitter.com/Boyko4TX/status/461902353105317891
EDIT: forgot to link the tweet.
The HTML of the form shows as POSTing to the same page, but the Stripe JS captures the submit event and cancels it, then makes an API call to Stripe's server via a secure connection. It works, but it is still somewhat vulnerable to MitM attacks.
I like @lessig's latest response. Much more firm and reassuring:
https://mayone.us/fec_compliance/
Sincere thanks to everybody who complained to them about this - I wouldn't have donated without HTTPS.
If you try to use SSL you will find a certificate mismatch with the host as well.
Ok. Don't donate, put a reminder in your planner to come back and try to change the world next week.
I submitted a comment on their feedback form letting them know, but I'm very surprised that Stripe would be involved and not help them avoid such a significant goof-up.
We have decided upon using Stripe as our payment processor. Stripe has offered us a very competitive rate (for which we thank them), and Stripe is compliant with PCI requirements and no sensitive data hits our servers. When you enter in your credit card information, it is not stored on the mayone.us site and goes directly to Stripe via the Stripe.js API.
Or in short: Yes, your money and info are safe. "
They are relying on the stripe.js code to abort the standard form submission and submit via SSL to Stripe's server. What you said still stands though and it is possible for that JS to be circumvented by design or by accident which could cause the information to be sent over an unsecured connection where it could be intercepted.