Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why is there no way around this? This is surprising to me and I'm super curious.


The exchange of payment or authentication information is undoubtedly done over TLS so it's probably just not a priority. That said there seems to be some obvious security issues with it since a bad actor could, as far as I know, inject malicious javascript in the vanilla http page to do all kinds of fun stuff.


Yeah but the checkout button on the insecure cart page could be changed so that it instead points to http://www.apple-payment.com/... or any random malicious "checkout" page which then steals your CC. They've compromised the security of credit card details users will at some point enter by doing this. It's insane if that isn't a priority.


It also exposes all of your cookies for apple.com since not a single cookie is marked secure/HTTPS only.


If I had to give them the benefit of the doubt, I'd guess that they feel that SSL has failed at fulfilling its intended purpose, and that they're working on a "superior" alternative which they plan to use for themselves and force all developers for their platforms to also use, in an attempt to encourage it to spread and supersede SSL.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: