I wanted to donate to a well established and reputable charity using a
credit card. I'll not mention the name of the organisation for obvious
reasons.
The problem seems to be that although there is a VeriSign logo on the pages,
the connection in both IE6 and FireFox 1.5 seems to be a pure HTTP
connection and not an HTTPS one. This is reflected in the address bar and
there is no padlock.
This is true on the page where you enter the amount and also on the page
where you enter the actual card details.
As far as I can tell, this means that the card details would be routed
across the internet in an unencrypted format.
I've raised this with the organisation who passed it onto the hosting
company. This is what they had to say :
"There are multiple ways to donate as instructed on the page. You can send
him an email back saying your web hosting company, XXXXXXXXX, does not host
Verisign's online forms. That first page is on our servers (he mentions
http://www.xxxxxxxxx.org/donate.html ), after that it goes to VeriSign. If
he would place an amount in and continue, he would know. We can add some
text that says something along these lines. Please let me know."
If you enter an amount and click the Donate button it takes you to the
payment page - which is not showing as HTTPS. Clicking on the VeriSign logo
shows the following text :
"Encrypted Data Transmission This Web site can secure your private
information using a VeriSign SSL Certificate. Information exchanged with any
address beginning with https is encrypted using SSL before transmission.
Identity Verified VERISIGN, INC. has been verified as the owner or
operator of the Web site located at payments.verisign.com. Official records
confirm VERISIGN, INC. as a valid business."
What does anyone think about this ? You reasoning would be good to see as I
intend to pass the comments back to the organisation.
Thanks