Lawrence and crew just responded to my tweet on this. They use Stripe, which is encrypted. The SSL certs for the page that is unencrypted will be up later today.
https://twitter.com/Boyko4TX/status/461902353105317891
EDIT: forgot to link the tweet.
https://twitter.com/Boyko4TX/status/461902353105317891
EDIT: forgot to link the tweet.
The HTML of the form shows as POSTing to the same page, but the Stripe JS captures the submit event and cancels it, then makes an API call to Stripe's server via a secure connection. It works, but it is still somewhat vulnerable to MitM attacks.
I like @lessig's latest response. Much more firm and reassuring:
https://mayone.us/fec_compliance/
Sincere thanks to everybody who complained to them about this - I wouldn't have donated without HTTPS.