Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 04-02-2010, 05:49 AM   #1
Juicy D. Links
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: N.Y. -Long Island --
Posts: 122,992
(Biz Related) Help me settle a debate in reference to SSL and Using Gateways

My friend is starting to sell some his shit online , He wanted to initially use paypal web payments to start (ie : person is sent to PP secure pages to use his CC or login using his PP account) then sent back upn order to his site for the order confirmation...


I told him to add a SSl Cert on the order process no matter what cause he will need it eventually when it gets a merc account....so when customer enters his name , addy and so on to register on site to create account to order he will be on HTTPS

He think cause the person is being sent to PP and he isnt collecting CC info he doesnt need it....

Now anybody want to shed some light on this cause I am not a expert and told him what I think should be done.

-JDL
Juicy D. Links is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-02-2010, 07:45 AM   #2
sextoyking
Confirmed User
 
Industry Role:
Join Date: Dec 2001
Location: Portland, OR.
Posts: 6,034
Hi Juicy,

It's allways best practices to have all signup / acct creation process in secure mode (https)

Some sites don't secure signup, etc but I think it's best for the consumer, etc.. If he is going to use a cert for the cart anyways best to use it it for all..... It's cheap btw and is professional to the customer...
__________________
ICQ: 52344098
--------------------------------------
50% Commissions on all Product Sales. http://www.wishing.com/money
sextoyking is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-02-2010, 07:51 AM   #3
munki
Do Fun Shit.
 
munki's Avatar
 
Industry Role:
Join Date: Dec 2004
Location: OC
Posts: 13,393
If you are transferring any personal information whatsoever, go SSL. No reason not to with how cheaply they area available to boot. Near 15-20 dollar range at godaddy if memory serves.
__________________

I have the simplest tastes. I am always satisfied with the best.” -Oscar Wilde
munki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-02-2010, 07:57 AM   #4
Serge Litehead
Confirmed User
 
Serge Litehead's Avatar
 
Industry Role:
Join Date: Dec 2002
Location: Behind the scenes
Posts: 5,190
when any sensitive/private/personal information is being passed by web site's forms over "public" pipes it always best idea to carry this communication in SSL encrypted envelope.

always got amazed how sponsors would collect SS#'s over HTTP in the past, i'm sure many sponsors still don't use SSL on their webmaster signup forms even today
__________________
Serge Litehead is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-02-2010, 08:02 AM   #5
baddog
So Fucking Banned
 
Industry Role:
Join Date: Apr 2001
Location: the beach, SoCal
Posts: 107,090
I cancel any request like that that does not go to a secured page.
baddog is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-02-2010, 09:10 AM   #6
kacy
Confirmed User
 
kacy's Avatar
 
Join Date: Oct 2002
Location: So Cal
Posts: 877
You are all correct, everything submited on the page should be secure, but what Juicy is saying is that friend feels nothing is being submitted on HIS website, which is true. It's like saying that adult pay sites should have an SSL when they are using CCBill. Most do not have their own SSL because nothing is being entered on the non secure page, they are directed over the payment provider's website, which is secure.

So, your friend is technically right, but like you said, if he plans to use his own merchant account at some point, he will need an SSL. At this point there is nothing to secure. The add to cart and order now links will all take the customer to PayPal where they will login securely.
__________________
~Kacy
kacy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-02-2010, 09:41 AM   #7
munki
Do Fun Shit.
 
munki's Avatar
 
Industry Role:
Join Date: Dec 2004
Location: OC
Posts: 13,393
Quote:
Originally Posted by kacy View Post
You are all correct, everything submited on the page should be secure, but what Juicy is saying is that friend feels nothing is being submitted on HIS website, which is true. It's like saying that adult pay sites should have an SSL when they are using CCBill. Most do not have their own SSL because nothing is being entered on the non secure page, they are directed over the payment provider's website, which is secure.

So, your friend is technically right, but like you said, if he plans to use his own merchant account at some point, he will need an SSL. At this point there is nothing to secure. The add to cart and order now links will all take the customer to PayPal where they will login securely.
Even the express paypal checkout methods still transmit personal information... maybe not cc#s... address alone, hell name transfer alone would cause for warranting ssl. And with how cheap ssl is... it shouldn't even be debate, if you run a website that includes any user forms whatsoever... just get it.
__________________

I have the simplest tastes. I am always satisfied with the best.” -Oscar Wilde
munki is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 04-02-2010, 09:43 AM   #8
kacy
Confirmed User
 
kacy's Avatar
 
Join Date: Oct 2002
Location: So Cal
Posts: 877
Agreed

Quote:
Originally Posted by munki View Post
Even the express paypal checkout methods still transmit personal information... maybe not cc#s... address alone, hell name transfer alone would cause for warranting ssl. And with how cheap ssl is... it shouldn't even be debate, if you run a website that includes any user forms whatsoever... just get it.
__________________
~Kacy
kacy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.