Jump to content
Sign in to follow this  
qnh

Unencrypted Shopping Cart

Recommended Posts

I was about to purchase the B1900 and checked the security on the page. It would appear that my credit card details would be transmitted in the clear rather than being encrypted. What's happening here?ScottYBTL


Scott
Boeing777_Banner_Pilot.jpg

Share this post


Link to post
Guest rog74

Scott,Head on over to PMDG's site, click on the "sales" tab. Scroll down until you find the red paragraph, it contains the answer to your question.In short, it is encrypted.Cheers,Roger

Share this post


Link to post
Guest rcarlson123

The reason it appears to be unencrypted is due to the fact that the shopping cart system is contained within a frameset that is not encrypted. The shopping cart pages themselves ARE encrypted though.When in doubt, right-click the page where you enter your CC information, and choose "properties." You can then see the details about the page's encryption where it says "Connection:". As Scott points out, this is noted on the PMDG Sales page, just before you click to the page where you choose the product you wish to buy.

Share this post


Link to post

I have checked the properties and come up with the message in the attached file.Not overly reassuringScottYBTL


Scott
Boeing777_Banner_Pilot.jpg

Share this post


Link to post
Guest rellehenk

rightclick inside the frame, then propertiesYou should see this message (this is dutch :()SSL 3.0, RC4 met 128-bits codering (Hoog); RSA met 1024-bits overdracht

Share this post


Link to post
Guest rog74

Scott,Make sure you are at the "order checkout" page. Click near the entry fields. It should read something like this: SSL 3.0, RC4 with 128 bit encryption (High); RSA with 1024 bit exchange .Cheers,Roger

Share this post


Link to post

I clicked in the card number field and got the same properties. ScottYBTL


Scott
Boeing777_Banner_Pilot.jpg

Share this post


Link to post
Guest rcarlson123

Must be a netscape thing ... it probably always gives the properties for the outer frame.To open the shopping cart system in it's own window, and not in a frame, click the "Buy Now" link on the 1900 page while holding the shift key. (At least that's how you do it in IE, not sure how in Netscape. You might have to right click the "Buy Now" button then choose "open in new window" or something similar.) Then you will be proceeding through the checkout process in a separate window, which will not be framed. Once you get to the credit card entry page, you won't even be on the PMDG site anymore, since their secure checkout form is hosted by "secure.dalmoworks.net", probably a third-party secure transaction provider.

Share this post


Link to post

One wonders why PMDG can't do purchasing the same way as most other sites?ScottYBTL


Scott
Boeing777_Banner_Pilot.jpg

Share this post


Link to post
Guest rcarlson123

I dunno, it's actually pretty common to use a third-party secure transactions provider, which are a dime-a-dozen these days. Even some of the largest companies use that method ... one less thing to have to maintain internally.

Share this post


Link to post
Guest Buck Bolduc

Generally if you look at your URL, you will see.Http:// = unsecureHttps:// = secure cocket layer.Notice the S in https://If you have a padlock icon on your status bar it will be locked when using a secure socket layer. If you do online banking you will notice the same thing.I will not enter credit card numbers or other personal info unless the connection is thru a secure socket layer which is incripted.Regards

Share this post


Link to post

The URL is http, no s. It's a shame really I was looking forward to the B1900.ScottYBTL


Scott
Boeing777_Banner_Pilot.jpg

Share this post


Link to post
Guest Pterodactyl

You don't go on to the secure server until you click the "Proceed To Checkout" button. The product selection and shopping basket screens are not secure (they don't need to be as no data needs to be transmitted from these screens) but the payment details screen is, as shown below. This payment screen is contained in a PMDG frame, however, which is why the padlock icon won't appear in your browser.http://forums.avsim.net/user_files/61850.jpgRegards,Tom Williams

Share this post


Link to post
Guest Buck Bolduc

Tom,WinXp may be different?If you notice your attachment says: SSL 3.0, this tells me it is indeed using a secure socket layer, SSL=Secure Socket Layer.RC4 is the encryption algorithm used, 1024 bit.I would have no problems whatsoever downloading from PMDG's site!!To be honest I never noticed one way or the other when I DLoaded 737NG, broke my own rules, ha!PMDG is a fine company, as is Avsim, that you can take to the bank.Regards

Share this post


Link to post
Guest rcarlson123

Scott, the URL certainly is https ... you aren't looking at the right one. If you follow my instructions for opening the shopping cart in a new window, you will see it. The URL for the page where you enter your CC number is:https://secure.dalmoworks.net/PDM1/ordercheckout.aspI'd hate to see you miss out on this fantastic plane because of a minor misconception such as this.

Share this post


Link to post

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  
  • Tom Allensworth,
    Founder of AVSIM Online


  • Flight Simulation's Premier Resource!

    AVSIM is a free service to the flight simulation community. AVSIM is staffed completely by volunteers and all funds donated to AVSIM go directly back to supporting the community. Your donation here helps to pay our bandwidth costs, emergency funding, and other general costs that crop up from time to time. Thank you for your support!

    Click here for more information and to see all donations year to date.
×
×
  • Create New...