No indication of whether credit card page is using an encrypted HTTPS connection

Bug #656419 reported by Thomas Horsten
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
software-center (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: software-center

When I purchase the test wallpaper, the (presumably web-based) purchase interface is shown in a standard window, without any browser indicators. So there is no way to know if the connection to the payment server is secure, which is a serious concern when I have to enter my credit card details.

It makes me fear that someone spoofing the payment server could steal my credit card details (and my launchpad login details) unnoticed.

ProblemType: Bug
DistroRelease: Ubuntu 10.10
Package: software-center 3.0.4
ProcVersionSignature: Ubuntu 2.6.35-22.33-generic 2.6.35.4
Uname: Linux 2.6.35-22-generic x86_64
NonfreeKernelModules: nvidia
Architecture: amd64
Date: Thu Oct 7 18:12:58 2010
InstallationMedia: Ubuntu 10.04 "Lucid Lynx" - Release Candidate amd64 (20100419.1)
PackageArchitecture: all
ProcEnviron:
 PATH=(custom, user)
 LANG=en_GB.utf8
 SHELL=/bin/bash
SourcePackage: software-center

Revision history for this message
Thomas Horsten (thomas-horsten) wrote :
Revision history for this message
Thomas Horsten (thomas-horsten) wrote :

How can I mark this as a security issue? I missed the checkbox before hitting submit.

Revision history for this message
Thomas Horsten (thomas-horsten) wrote :

I would suggest to address this issue adding a status bar with a green icon and "You are connected to http://xxx.com using a secure connection, click here to verify certificate" (or a red icon and "This connection is not secure, click for details", as the case might be)

security vulnerability: no → yes
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.