Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah I read that. But it's strange, when I enter in information and hit "Pledge" it posts the fields to another insecure endpoint:

http://mayone.us/wp-admin/admin-ajax.php

Maybe I am missing something about how stripe works?



https://stripe.com/help/ssl

> Do I need to use SSL on my payment pages?

> Yes


I'm concerned about why they are posting to THEIR own server to begin with. Even if they were using SSL, it seems like some kind of misuse of stripe.js




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: