love your valentine special :)

Status
Not open for further replies.

labgramma

Senior Member
ECF Veteran
Jan 31, 2011
142
26
Denver, CO
www.ccrengines.com
I am pretty sure that this sale is for 30% off juice only. David was only saying that we could order hardware on the same order. In the past we had to place 2 seperate orders when there was a juice sale.

Ah. I guess I misunderstood the intent. No prob: it was a good price anyway.
 

Free2BMe

Vaping Master
ECF Veteran
Verified Member
Jul 21, 2010
3,360
4,754
IL
Filled up my cart and went to check out only to find that the page where you enter your credit card is not secure. It says https: but the lock in my security in firefox is red (should be green if it is a secure connection) and says "contains unauthenticated content" ... I just can't risk entering my credit card number on pages that are not 100% secure. I realize that my credit card will not be charged until I submit the final order but I will not risk transmitting it over an insecure page to the secure page.

Sorry. You might want to change this to only ask for the credit card on the 100% secure page.

cleo


This has popped up a time or two in the past during sales but I can't remember the resolve. I know FSUSA is a totally secure site but not sure why this happens. Hang tight, Cleo...I think this has already been forwarded to David's attention.
 

PastaMonster

Senior Member
ECF Veteran
Jan 3, 2011
100
23
Arizona
Filled up my cart and went to check out only to find that the page where you enter your credit card is not secure. It says https: but the lock in my security in firefox is red (should be green if it is a secure connection) and says "contains unauthenticated content" ... I just can't risk entering my credit card number on pages that are not 100% secure. I realize that my credit card will not be charged until I submit the final order but I will not risk transmitting it over an insecure page to the secure page.

Sorry. You might want to change this to only ask for the credit card on the 100% secure page.

cleo

I understand your concern for privacy, but it sounds like you don't know really what makes a payment process secure or not. The reason why the lock on firefox is not green is because the checkout screen contains links to unsecure pages (like the products you have in your cart for example). Now they may eventually want to add a way to add a payment option to our accounts on a totally secure page, but the only way to make you happy would require them to entirely recode their site.

I checked the code on the checkout screen and all of the sensitive information goes through their secure credit card payment processor, which goes through a 256bit encryption key.

Those little icons in Firefox and other browsers aren't 100% black and white. The credit card info on FreedomSmokeUSA is secure, it's just that the algorithm used to detect the security of a page is just not smart enough know the difference between the non-encrypted links to the encrypted ones, as far as security goes. I could code a page that tricked Firefox into thinking it was 100% secure, but it would be 0% secure.


EDIT: It also triggers some stuff in Chrome due to the javascript on the page and that it is an "unknown" site. However, all of the stuff that needs to go through encryption seems to be done properly. The problem isn't the security of the website, it's just that the payment page isn't coded in a way to make the security algorithms in modern browsers happy.
 
Last edited:

salemgold

ECF Guru
Supporting Member
ECF Veteran
Verified Member
Jul 5, 2010
28,155
63,784
South Carolina
I understand your concern for privacy, but it sounds like you don't know really what makes a payment process secure or not. The reason why the lock on firefox is not green is because the checkout screen contains links to unsecure pages (like the products you have in your cart for example). Now they may eventually want to add a way to add a payment option to our accounts on a totally secure page, but the only way to make you happy would require them to entirely recode their site.

I checked the code on the checkout screen and all of the sensitive information goes through their secure credit card payment processor, which goes through a 256bit encryption key.

Those little icons in Firefox and other browsers aren't 100% black and white. The credit card info on FreedomSmokeUSA is secure, it's just that the algorithm used to detect the security of a page is just not smart enough know the difference between the non-encrypted links to the encrypted ones, as far as security goes. I could code a page that tricked Firefox into thinking it was 100% secure, but it would be 0% secure.


EDIT: It also triggers some stuff in Chrome due to the javascript on the page and that it is an "unknown" site. However, all of the stuff that needs to go through encryption seems to be done properly. The problem isn't the security of the website, it's just that the payment page isn't coded in a way to make the security algorithms in modern browsers happy.

This is exactly the info that I was hoping to get across. My husband explained that to me also but I could not remember the exact details. Thanks for helping!
 

cleolove

Ultra Member
ECF Veteran
Verified Member
Feb 9, 2011
2,804
2,361
62
♥ Minnesota ♥
I realize that now, I just talked it over with some geek friends on irc, who managed to explain it without insulting my intelligence or lack of knowledge about security issues. We are taught in our beginner computer classes at the home for exceptional ...... to always check in 2 places to make sure the site you are on is secure before you enter your credit card number -- The https bar and the little lock icon.

FYI, In the the last two weeks, I have made about 14 orders from suppliers who have coded their payment pages to be totally secure and give me a green icon. I suggested that you might want to change this because how many others have gone and checked those two places and not bothered to ask, just left and didn't purchase because they heard on the nightly news special report on online shopping to check the two places for secure sites?

In the time that I posted my concern and the time I got a response, two other good coupon codes came out and I spent $70 on new juices at other suppliers. I'm all out of money now. Is it worth losing business over?

I hold no ill will against the site. I am not telling others to not order from them, I was simply trying to help in my odd cleo kind of way.

Peace, Love, and Clouds of Vapor,
cleo
 

Stifle

Super Member
ECF Veteran
Jan 15, 2011
345
96
San Diego, CA
So FSUSA launched their lounge..

They are putting out a great product...

They gave us a great 30% off juice sale...

I must ask...when will the FSUSA teleportation system be put in place so my juice magically materializes the second it is ordered? This is the only improvement I am still waiting on from FSUSA!

(Oh, and a vape lounge in San Diego, CA. I've already got the spot picked out and I know someone who would be an excellent General Manager. **cough cough**)


Edit*** Cleo, while you do have a valid concern and I understand not wanting to put your CC information out on unsecured sites, this is a relatively common coding issue in e-commerce sites.

It is not so much a problem with their website as it is a problem with our browsers. The payment information is secured but by trying to allow us easier access to more content in the form of links it fools Firefox into thinking it is not secure. In fact it is only the links to products/reviews/ other sections of the site are not secure.

While I understand that this is not ideal, given that David and crew at FSUSA are trying to balance a lot of big steps right now and this may not be of the highest priority. They are in the process of opening the first ever vape lounge in the US, continuously adding flavors to their catalog, constantly providing us with sales to make our vaping more enjoyable and cheaper, monitoring and helping their community through this site...etc etc etc.

Ultimately, this is something I am sure they will look to fix in the future. However, given that the information you are concerned with is actually secure and the problems you were seeing were for all intents and purposes cosmetic..I do not think it is high on the list of priorities right now. If it was actually the case that their customer's information was not secured I have no doubt it would be priority number 1 regardless of all the other things FSUSA is trying to do to make the customer experience better.

Just my 2 cents, but I wouldn't miss out on FSUSA juice just because the website has a minor cosmetic deficiency that makes it appear to be a problem. Jusy FYI - I just checked the code and it is correct.

Thanks for the previous code-monkey poster for digging through that too!
 
Last edited:

Misha707

Super Member
ECF Veteran
Oct 9, 2010
384
8
57
Leawood, KS
Still waiting for those student loans to come through for my big order, but ordered 60 ml of Cap Smooth anyway!!! :) Thanks for the sale, David, at least now I'll have one of my favorites to get me through til that happens! And some of it can steep too. :)

Are you expecting more Ego-T stock in about a week or week & 1/2? Really wanting to try them, and need lots of backup parts too. Almost like Christmas, only I get to buy what I want for my presents. Yay! lol
 

SPaZ

Full Member
Aug 14, 2010
36
0
WI
I am about to score some more hypnotic mist, hope I don't get scared when I see what color it is when it arrives...

Also as for the site security issue; most every site now only encrypts the private data that needs to be kept private. That was semester 1 of my Information Security degree.
There is no reason to overburden any of the servers out there that don't need it. Keeping that mindset would turn the "series of tubes" into a "series of tubes with tricycles riding in them". If anything the admins should keep the OScommerce site (along with any machines on the network patched frequently.
 
Status
Not open for further replies.

Users who are viewing this thread