Jake Williams@MalwareJake·Jun 21, 2019Hey @Expedia, we need to talk. You're sending HTTP links requesting credit card information...26119328
matches42@matches42·Jun 21, 2019Replying to @MalwareJake and @Expediaalmost universally when I complain about this they say the post/submit is secure which makes me think that’s the PCI requirement.311
Jake Williams@MalwareJake·Jun 21, 2019Replying to @matches42 and @ExpediaAs I'm sure you're aware, that's not how security works...213
Jake Williams@MalwareJake·Jun 22, 2019Replying to @rx13 @matches42 and @ExpediaThe POST is encrypted. Not sure I care though, it's 2019 - this is a 2005 problem.313
Wes @weskerfoot·Jun 22, 2019Replying to @MalwareJake @rx13 and 2 othersIt's effectively NOT encrypted if the page containing the form is unencrypted
Wes @weskerfoot·Jun 22, 2019Replying to @rx13 @MalwareJake and 2 othersIt can be trivially replaced with a form that uses http. If everything isn't encrypted, nothing is.
Wes @weskerfootReplying to @rx13 @MalwareJake and 2 othershttps://troyhunt.com/your-login-form-posts-to-https-but-you/…6:13 PM · Jun 22, 2019·Twitter for Android