Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

HTTPS URLs are encrypted along with the rest of the request.


If a web designer adds this script to a non-HTTPS page, is that still the case?


Yes, the request is still encrypted. However, the original page will be subject to man in the middle attacks, which is why Stripe requires that payment pages using the Stripe Button or Stripe.js are served with SSL.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: