Results 1 to 8 of 8
  1. #1
    Join Date
    Jul 2006
    Posts
    308
    Plugin Contributions
    0

    Default unsecured payment page?

    A customer visiting my website claimed that the payment page did not have https in the url and was not secured. I'm trying to figure out how he could have encountered such a problem, because in 6 years I have never seen it nor heard of this problem from any other customer. Every time I get to even step 1 of checkout, it's secured. The SSL certificate is not expired. I don't know what browser he was using.

    The only way I can recreate the problem is by manually changing the https to http in the address bar. I guess I could create a redirect to force it to always be https on those pages, but it seems like an unnecessary failsafe.

    Has anyone ever encountered such a problem?

    www.adamantbarbell.com
    user dummy##########################, pass dummy

  2. #2
    Join Date
    Feb 2005
    Location
    Lansing, Michigan USA
    Posts
    20,024
    Plugin Contributions
    3

    Default Re: unsecured payment page?

    Never. My guess is the customer was confused or is messing with you. I went as far as Checkout Payment on your site and was on secured pages the whole way.

  3. #3
    Join Date
    Sep 2003
    Location
    Ohio
    Posts
    69,402
    Plugin Contributions
    6

    Default Re: unsecured payment page?

    Doesn't make sense to me either as I checked login/checkout and all is secure ... nothing makes the paranoid me think "good grief! get me out of here non-scure stuff" and no way to trigger that that I could discover other than for me to manually change the url from https: to http: and hit enter ... and that only results in yes the page looks, based on url, to be http: but hit submit I am https: ... view source, and I see it is https on what I click ...

    And nothing when I try to fake things out or manually force pages to be https via URL anywhere on the site trigger https errors/warnings/etc.

    So I think your customer is confused ...

    Maybe ask for a screen shot of why they think they are not secure ...
    Linda McGrath
    If you have to think ... you haven't been zenned ...

    Did YOU buy the Zen Cart Team a cup of coffee and a donut today? Just click here to support the Zen Cart Team!!

    Are you using the latest? Perhaps you've a problem that's fixed in the latest version: [Upgrade today: v1.5.5]
    Officially PayPal-Certified! Just click here

    Try our Zen Cart Recommended Services - Hosting, Payment and more ...
    Signup for our Announcements Forums to stay up to date on important changes and updates!

  4. #4
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: unsecured payment page?

    Very odd.
    And, even if your customer were to remove the "s" from https:// to visit the page, the <form> action parameter tells it to use https for transmission of whatever he enters, thus treating the data he enters as secured and encrypted.

    And, while it's possible he could further hack the page to trick the browser into using http instead of https on the form action parameter, if he's hacking around on your site then he's also not a legitimate customer making a legitimate purchase where he legitimately wants to transmit secure information securely.

    So either he's using a browser that's not capable of SSL (which means he's using a commodore 64 or something ancient) or he's misunderstanding how his browser even displays SSL (remember, Firefox and others recently started skipping the display of http or https in favor of using an icon instead ... really stupid IMO but does make for shorter URLs on mobile devices), or he's an amateur hacker trying to cause fear about something that's rather moot in normal use.

    Of course, I'm commenting based on the assumption that you're using original ZC code and haven't altered the way ZC handles these things.
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  5. #5
    Join Date
    Dec 2008
    Posts
    11
    Plugin Contributions
    0

    Default Re: unsecured payment page?

    We've seen some customers who are still using Win XP/Vista and have not updated before December 2012 have the same issue. We think it's due to a root certificate update Microsoft did that either trimmed or disabled old root certificates.

    Though it's more work than it's worth, If you are still in contact with your customer I would try to let them know they might need to update their computer.

    I can't seem to find the article anymore, but that's what was causing our issues earlier this year. Haven't had one for a good 3 or 4 months now

  6. #6
    Join Date
    Jul 2006
    Posts
    308
    Plugin Contributions
    0

    Default Re: unsecured payment page?

    My customer followed up and said he was actually using his ipad to visit the site before when he saw the alleged problem and admitted that he likely misinterpreted what his browser was indicating for SSL, expecting it to look like his home computer.

  7. #7
    Join Date
    Jan 2004
    Posts
    66,373
    Blog Entries
    7
    Plugin Contributions
    274

    Default Re: unsecured payment page?

    Thanks for the follow-up.

    I can imagine how different an iPad would appear vs a Commodore 64.




    (Sorry, just meant as a funny, no disrespect to your customer!)
    .

    Zen Cart - putting the dream of business ownership within reach of anyone!
    Donate to: DrByte directly or to the Zen Cart team as a whole

    Remember: Any code suggestions you see here are merely suggestions. You assume full responsibility for your use of any such suggestions, including any impact ANY alterations you make to your site may have on your PCI compliance.
    Furthermore, any advice you see here about PCI matters is merely an opinion, and should not be relied upon as "official". Official PCI information should be obtained from the PCI Security Council directly or from one of their authorized Assessors.

  8. #8
    Join Date
    Feb 2005
    Location
    Lansing, Michigan USA
    Posts
    20,024
    Plugin Contributions
    3

    Default Re: unsecured payment page?

    Quote Originally Posted by DrByte View Post
    I can imagine how different an iPad would appear vs a Commodore 64.
    Raid Over Moscow would look great on both, though.

 

 

Similar Threads

  1. v151 'Unsecured Items' with SSL
    By sle39lvr in forum General Questions
    Replies: 2
    Last Post: 6 Mar 2015, 03:19 AM
  2. Replies: 2
    Last Post: 6 Jul 2011, 01:22 PM
  3. Issue with Zen-Cart >> Secured/Unsecured Pages >> SSL >> HTTPS
    By satzin123 in forum Basic Configuration
    Replies: 9
    Last Post: 23 Mar 2009, 04:03 AM
  4. NOT Skipping Payment Page (Express Checkout: Skip Payment Page = Yes)
    By 1100101 in forum PayPal Express Checkout support
    Replies: 2
    Last Post: 22 Sep 2008, 01:33 PM
  5. Unsecured Checkout
    By dejavu in forum Basic Configuration
    Replies: 5
    Last Post: 19 Apr 2008, 04:01 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
disjunctive-egg
Zen-Cart, Internet Selling Services, Klamath Falls, OR