Web site suggestions

Status
Not open for further replies.

HedonismBot

Full Member
Mar 24, 2011
13
0
Southwest FL
Hi iVapers,

Based on some of the recommendations around the forum I visited your site the other day and placed my first order. During the process I noticed a couple of things that you really need to take a look at as an online business.

1) When I finished my shopping and proceeded to checkout, I was not automatically directed to a secure (https://) link. As a matter of habit, whenever I'm about to enter payment info, I double-check that the page is secure - and yours was not. I was able to simply change the address in the browser to https://[blah] and pick up where I left off, but all of your "Checkout" links should do that for me - otherwise you're placing your less security-conscious customers at risk (their credit card info - name, card no., exp. and CVE - would be sent across the internet completely unencoded).

2) Your site shows "members online" and shows their username. Most people now use their full e-mail address as their username, and so you are inadvertently sharing your customer list on your webpage by listing the online user's names. To fix that, you should (a) disallow '@' characters in your new-customer username field, (b) only display the part of the username up to the '@' character in the "who's online" widget, or (c) remove the "who's online" widget altogether.

Other than that, a pleasant shopping experience - but please understand these two issues are more than a peeve. In fact one of them is in direct violation of the PCI (Payment Card Industry) web security standards. And they both have the potential to expose your customers in ways I'm sure you'd rather avoid.

If you lack the technical savvy to implement these suggestions, feel free to PM me and I'd be happy to help you out. The changes are pretty simple and I'd gladly do it for an extra bottle of juice or something.
 

kno

Unregistered Supplier
ECF Veteran
Oct 8, 2009
1,711
317
Myrtle Beach, SC, USA
This is the second report this week of a bug not displaying HTTPS:// - it should be doing it automatically at the checkout. I've been looking into it for the past 3 days and trying to recreate it since the last report, and have since implemented a force SSL to the entire site. I'm glad you've informed me, if you could please e-mail me if you know of what can be causing this - as we're still trying to find and fix what might be causing this. Also please check again to see if the site is loading via https:// at checkout, or if it's still displaying http:// - it seems like this is occurring randomly and not something that is just generally viewable. We had a few people test it, but weren't able to find it. and are hoping all the changes we've made can stop this from occurring again.

Your help would be fully appreciated, as we haven't been able to replicate the error where a SSL connection is not displayed.
 
Last edited:
Status
Not open for further replies.

Users who are viewing this thread