Security

Got any questions about club merchandise, or the shop? Got an idea for a new item? Then post away in here.

Moderator: Forum Staff

Post Reply
Message
Author
Capt C
Getting Settled In
Posts: 42
Joined: Thu Feb 18, 2010 9:31 pm

Security

#1 Post by Capt C » Thu Feb 18, 2010 9:40 pm

Hi,
I'd be happy to sign up for club membership - in fact I'd got as far as the checkout.
BUT - I saw no evidence of a secure (ie SSL) server, so quit at that point.

Capt C.

User avatar
xanadu
Enthusiast
Posts: 179
Joined: Fri Oct 09, 2009 3:47 pm
Location: West Yorkshire
Contact:

Re: Security

#2 Post by xanadu » Fri Feb 19, 2010 9:02 am

Once you get passed the checkout you are re-directed to a secure server before you add any payment information
See Beyond the Light............. Find Your Darker Side

User avatar
Smithy
Club Member
Posts: 2994
Joined: Mon Oct 09, 2006 9:14 pm
Car Ownership: Rover 200 Mk2 (R8) Hatchback
Location: Lincolnshire

Re: Security

#3 Post by Smithy » Fri Feb 19, 2010 9:59 am

Hi,

The payment facilities are provided via an external company, it is a secure SSL server.

As Xanadu says once you get to the checkout you are redirected to a secure server.

If it makes you any happier the direct link for the shop is here:
http://isubs.securewebservices.co.uk/sw ... 1035&gid=3


Also the online help give you some information on the security:

http://isubs.securewebservices.co.uk/sw ... curity.php

Look forward to seeing you as a member.

Lindsey
Rover 220 GTi Turbo.
Maestro Police Car.

Follow us on facebook. http://www.facebook.com/pages/Rover-200 ... 9239975702

Capt C
Getting Settled In
Posts: 42
Joined: Thu Feb 18, 2010 9:31 pm

Re: Security

#4 Post by Capt C » Fri Feb 19, 2010 8:24 pm

Thanks,

Well, you guys ought to know - but unless my beer was extra-strong that night, I was being asked for CC number and CVC over an unencrypted connection at that time. I'll try again, perhaps submitting fake data and capturing what's going on.

My day job is secure computing - but not the webby stuff
Capt C. 214SLi, 216GSi owner

E_T_V
Club Staff
Posts: 3009
Joined: Tue Nov 07, 2006 8:25 pm
Car Ownership: Rover 200 Mk2 (R8) Hatchback
Location: Scunthorpe
Contact:

Re: Security

#5 Post by E_T_V » Sat Feb 20, 2010 9:59 pm

Hi there,

I've done a bit of investigating. The site that handles the subscriptions is definatly encrypted. The issue is that following the link on the site opens it within a wrapper within this site. This means that the padlock icon doesn't appear on the screen (as this parent site isn't using encryption.

If you prefer you can go direct to the site where the padlock should appear, (same link but not in a frame)

http://isubs.securewebservices.co.uk/sw ... 1035&gid=3

Capt C
Getting Settled In
Posts: 42
Joined: Thu Feb 18, 2010 9:31 pm

Re: Security

#6 Post by Capt C » Sun Feb 21, 2010 4:38 pm

Absolutely right, E_T_V !

:oops I apologise.

Yes, it's a secure *frame* within an insecure page, with no visible cues unless 'view frame info' or suchlike is used.
I went to the trouble of squirting the connection through a logging proxy too.
Just too slick by half! I'm impressed.
Capt C. 214SLi, 216GSi owner

E_T_V
Club Staff
Posts: 3009
Joined: Tue Nov 07, 2006 8:25 pm
Car Ownership: Rover 200 Mk2 (R8) Hatchback
Location: Scunthorpe
Contact:

Re: Security

#7 Post by E_T_V » Sun Feb 21, 2010 8:05 pm

No need to apologise, I'm glad people are on the ball about such things, and we have nothing to hide! :D

Post Reply