Academic Integrity: tutoring, explanations, and feedback — we don’t complete graded work or submit on a student’s behalf.

We are running a Portal application for our client with Payment Gateway integrat

ID: 661159 • Letter: W

Question

We are running a Portal application for our client with Payment Gateway integrated. Payment gateway uses SSL as it is suppose to be .

The concern for me is that our Portal application does not use HTTPS leaving it susceptible to MITM attacks but since the payment gateway uses SSL , are we still open to MITM attacks? What are the other risks involved ?

Based on the suggestions here , I will try to convince our client to buy a digital certificate from a registering certifying authority if it is needed .

Explanation / Answer

It's often not only the case that "payment information" is the only sensitive information. If your portal requires some sort of "login" (which it undoubtedly does), you allow many parties in between (Internet Cafe owners, ISP's, "hackers", employers, govermenments, ...) to see these credentials and take over the account.

If your portal has anything in terms of recurring payment what they can setup from your unsecured side, or any requests that would affect the subjects account, you offer no protection towards that.

SSL certificates and the benefits they offer (even if it's just a professional and trusted image) far outweigh the cheap price.

Hire Me For All Your Tutoring Needs
Integrity-first tutoring: clear explanations, guidance, and feedback.
Drop an Email at
drjack9650@gmail.com
Chat Now And Get Quote