Ok I need to clear this up so please advise.
If you have a online store and you don't use SSL but all credit card details and processing is handled via lets say paygate or whatever, is this is completely crazy and unsafe model?
So the customer picks his / her items, click checkout, selects credit card, puts their CC details in, clicks on continue to confirm order, and then once clicking confirm it goes directly to the payment gateway, so essentially nothing is happening on your site with regards to the CC processing. It leaves your site completely and gets done on the gateways side.
Please can someone explain how this model should work and if the above method is truly insecure.
If you have a online store and you don't use SSL but all credit card details and processing is handled via lets say paygate or whatever, is this is completely crazy and unsafe model?
So the customer picks his / her items, click checkout, selects credit card, puts their CC details in, clicks on continue to confirm order, and then once clicking confirm it goes directly to the payment gateway, so essentially nothing is happening on your site with regards to the CC processing. It leaves your site completely and gets done on the gateways side.
Please can someone explain how this model should work and if the above method is truly insecure.