04-28-2021, 05:53 PM
(04-28-2021, 04:24 PM)Shannon Wrote: I have had Andrew explain this to me 3 times within the last 10 years as to why we don't have that, and every time he tells me it doesn't matter and why it doesn't matter, but I never remember it when the time comes to explain it to customers. Every time he does, it makes perfect sense, and there is a good reason it's not https. Unfortunately, he's not available to explain it. However, I don't think that's going to be an issue for much longer regardless.
Oh, you've had https available for years, although the secure certificate hasn't always been renewed promptly when it expires. It usually works fine, but given this post here, it seems like the SSL certificate was probably renewed last April and probably just expired recently, after that year was up.
I'd guess that Andrew's point about not really needing it would be that 1) most customers are worried about billing info security, 2) Paypal's site is where customers provide billing info, and 3) Paypal has https. And, yeah, if secure billing info were my only concern, I'd have already preordered OF v3 by now.
But, no, it's the Subliminal Shop logins that we perform in order to purchase or download that still needs the https around. With only http, we're sending plaintext usernames and passwords, which, if sniffed by a middle man (I could describe in more detail, but I'd rather not), might allow that middle man access to download the compromised user's files, redistribute them, and activate the anti-piracy scripting that we've all spent years listening to. That's what I'm concerned about, not billing security.