Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic
1 | 2 | 3 | 4
itxtme
2102 posts

Uber Geek


  #884557 26-Aug-2013 11:13
Send private message

Can someone explain to me the worst case scenario of this particular page not being encrypted?? I would have thought all of the information is publicly available anyway, from this page.



freitasm
BDFL - Memuneh
79295 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #884561 26-Aug-2013 11:17
Send private message

Someone intercepting your credit card number, expiry, name and CCV in transit to TM servers?




Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


scowie
2 posts

Wannabe Geek


  #884575 26-Aug-2013 11:41
Send private message

Nope, it's a different page, you can try it here


Jebus, so they manage to use ssl in one place but not the other.



Zeon
3916 posts

Uber Geek

Trusted

  #884605 26-Aug-2013 12:28
Send private message

freitasm: Someone intercepting your credit card number, expiry, name and CCV in transit to TM servers?


Still pretty unlikely but not good either way.




Speedtest 2019-10-14


sleemanj
1490 posts

Uber Geek


  #884646 26-Aug-2013 13:17
Send private message

Zeon:
freitasm: Someone intercepting your credit card number, expiry, name and CCV in transit to TM servers?


Still pretty unlikely but not good either way.


Geekzone users know better, but Joe Public is quite likely to be accessing trademe and use this page over random wifi networks for a start :-)







---
James Sleeman
I sell lots of stuff for electronic enthusiasts...


1080p
1332 posts

Uber Geek
Inactive user


  #884710 26-Aug-2013 14:27
Send private message

sleemanj:
Zeon:
freitasm: Someone intercepting your credit card number, expiry, name and CCV in transit to TM servers?


Still pretty unlikely but not good either way.


Geekzone users know better, but Joe Public is quite likely to be accessing trademe and use this page over random wifi networks for a start :-)





This would be hilarious to demonstrate over TradeMe's free wi-fi in Wellington. :)

freitasm
BDFL - Memuneh
79295 posts

Uber Geek

Administrator
ID Verified
Trusted
Geekzone
Lifetime subscriber

  #884828 26-Aug-2013 16:31
Send private message

I am told this has now been fixed by Trade Me. Anyone care to check please?




Please support Geekzone by subscribing, or using one of our referral links: Quic Broadband (free setup code: R587125ERQ6VE) | Samsung | AliExpress | Wise | Sharesies | Hatch | GoodSync 


 
 
 

Move to New Zealand's best fibre broadband service (affiliate link). Free setup code: R587125ERQ6VE. Note that to use Quic Broadband you must be comfortable with configuring your own router.
sleemanj
1490 posts

Uber Geek


  #884840 26-Aug-2013 16:43
Send private message

freitasm: I am told this has now been fixed by Trade Me. Anyone care to check please?


Yes, fixed.





---
James Sleeman
I sell lots of stuff for electronic enthusiasts...


itxtme
2102 posts

Uber Geek


  #884952 26-Aug-2013 20:10
Send private message

freitasm: Someone intercepting your credit card number, expiry, name and CCV in transit to TM servers?


I understood if you choose the credit card pay option it redirected to SSL, so the only details that could be intercepted would be what you purchased..  Thats why I thought it was somewhat out of proportion..

kyhwana2
2566 posts

Uber Geek


  #884962 26-Aug-2013 20:30
Send private message

itxtme:
freitasm: Someone intercepting your credit card number, expiry, name and CCV in transit to TM servers?


I understood if you choose the credit card pay option it redirected to SSL, so the only details that could be intercepted would be what you purchased..  Thats why I thought it was somewhat out of proportion..


As per the OP screenshot, they'd already chosen the credit card option? Even if the iFrame is SSL, it doesn't matter since the actual page is loaded over HTTP and you can just replace that iframe with whatever you want when you MITM someone. (2degree's used to have this problem with their topup page too)


sleemanj
1490 posts

Uber Geek


  #884963 26-Aug-2013 20:34
Send private message

itxtme:
freitasm: Someone intercepting your credit card number, expiry, name and CCV in transit to TM servers?


I understood if you choose the credit card pay option it redirected to SSL, so the only details that could be intercepted would be what you purchased.


No.  The page where you entered your CC details, and the url that form submitted to was not SSL secured in any way.

From what I can see only applied to MQL (Multi Quantity Listings) with Pay Now as an option (which switches on the "new" integrated checkout process introduced last month).






---
James Sleeman
I sell lots of stuff for electronic enthusiasts...


grasshoper

164 posts

Master Geek


  #884967 26-Aug-2013 20:48
Send private message

yep, definitely fixed. Glad to see trademe listening to the public :D

PaulBags
809 posts

Ultimate Geek
Inactive user


  #884980 26-Aug-2013 21:22
Send private message

Would still appreciate secured logins & for https to not just redirect to http.

Oh well, I don't think much of trademe anyway. Been years since I bought anything there, and longer still since I sold anything.

lyonrouge
1993 posts

Uber Geek

Trusted
Lifetime subscriber

  #990493 19-Feb-2014 14:28
Send private message

PaulBags: Would still appreciate secured logins & for https to not just redirect to http.

Oh well, I don't think much of trademe anyway. Been years since I bought anything there, and longer still since I sold anything.


They requested I login and update my address valuidation, but it's still unencrypted. I wonder if their mobile application is also unencrypted? Is their a way to tell?

kenkeniff
628 posts

Ultimate Geek


  #990504 19-Feb-2014 14:51
Send private message

lyonrouge:
PaulBags: Would still appreciate secured logins & for https to not just redirect to http.

Oh well, I don't think much of trademe anyway. Been years since I bought anything there, and longer still since I sold anything.


They requested I login and update my address valuidation, but it's still unencrypted. I wonder if their mobile application is also unencrypted? Is their a way to tell?


Wireshark

1 | 2 | 3 | 4
Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.